Method and apparatus for resource management
Abstract
Some embodiments are implemented in a communication system. The communication system includes a first wireless communication system and a second wireless communication system. The second wireless communication system includes a Femto cell access point (FAP) and a network controller. The network controller can communicate Ground the FAP to the first wireless communication system. In some embodiments, the network controller can communicatively couple the first wireless communication system through the UTRANIu interface. Some embodiments provide a resource management method that determines whether a user equipment (UE) roams into an area served by a FAP. FAP includes the General Access Resource Control (GA-RC) protocol sublayer. This method creates a separate UE-specific GA-RC state in the GA-RC protocol sublayer. The method also sets the UE-specific GA-RC state to a deregistration state to indicate that the UE is not registered to use the service of the second wireless communication system.

Term
Projected expiry 22 September 2027.
- Priority
- Filed
- Published
- Today
- Projected expiry
18 claims: 7 independent, 11 dependent
- 1第 1. 一种在通信系统中进行资源管理方法,其中通信系统包括第一无线通 信系统和第二无线通信系统,该第二无线通信系统包括Femto小区接入点 (FAP )和网络控制器,网络控制器将所述FAP可通信地耦合到所述第一无 线通信系统,该方法包括: a) 确定用户装置(UE)是否已经在由所述FAP服务的区域中漫游, 其中所述FAP包括通用接入资源控制(GA-RC)协议子层; b) 创建在所述GA-RC协议子层中所述UE专用的单独的GA-RC状态; 以及 c )将所述UE专用的所述GA-RC状态设置成注销登记状态,所述注 销登记状态指示所述UE未被登记使用所述第二无线通信系统的服务。
- 2如权利要求1所述的方法,进一步包括,当由所述FAP将所述UE 成功登记到所述网络控制器时,将所述UE专用的所述GA-RC状态设置成 已登记状态。
- 3一种确定用户装置(UE)是否已经漫游到第一无线通信系统之外的 方法,该第一无线通信系统包括Femto小区接入点(FAP )和网络控制器, 该网络控制器将所述FAP可通信地耦合到第二无线通信系统,该方法包括: a) 在所述FAP处从所述UE接收周期性消息;以及 b) 当在所述FAP处未能接收到预定数目的所述周期性消息时: i) 在所述FAP和所述网络控制器之间的所述UE专用的唯一的连 接上向所述网络控制器发送注销登记消息;以及 ii) 释放所述UE专用的连接。
- 4如权利要求3所述的方法,其中,通过从所述FAP向所述UE发出 系统信息广播,来控制所述周期性消息的启用和周期。
- 5一种在通信系统中失去连接性之后释放资源的方法,该通信系统包括 第一无线通信系统和第二无线通信系统,该第二无线通信系统包括Femto小 200780043341.5 第 区接入点(FAP)和网络控制器,所述网络控制器将所述FAP可通信地耦合 到所述第一无线通信系统,所述方法包括: a) 在所述FAP和所述网络控制器之间的连接上从所述FAP向所述网 络控制器发送周期性消息,所述周期性消息用于确定是否失去所述连接,以 及 b) 当在所述FAP处确定失去所述连接时: i) 将可通信地耦合到所述FAP的用户装置(UE )注销登记;以及 ii) 迫使所述UE执行小区重选。
- 6如权利要求5所述的方法,其中,所述失去的连接是所述FAP专用 的第一唯一的连接,其中在所述FAP和所述网络控制器之间存在所述UE专 用的第二唯一的连接,所述方法进一步包括:在由所述FAP确定失去了所述 FAP专用的连接之后,并且在将所述UE注销登记之前:i)尝试重新建立在 所述FAP和所述网络控制器之间的第一连接;以及 ii)仅当重新建立所述第一连接的所述尝试失败时,由所述FAP执行将 所述UE注销登记。
- 7一种在通信系统中登记Femto小区接入点(FAP )的方法,该通信 系统包括第一无线通信系统和第二无线通信系统,该第二无线通信系统包括 所述FAP和网络控制器,该网络控制器将所述FAP可通信地耦合到所述第 一无线通信系统,该方法包括: a) 从所述FAP向所述网络控制器发送包括登记类型的登记请求消息, 其中所述登记类型将所述FAP标识为将要登记到所述网络控制器的设备;以 及 b) 当所述网络控制器确定所述网络控制器能够接受来自所述FAP的登 记请求时,在所述FAP处接收登记接受消息。 如权利要求7所述的方法,进一步包括,从所述FAP向所述网络控 制器发送包括登记类型的登记请求消息,其中所述登记类型将被可通信地耦 合到所述FAP的用户装置标识为将要登记到所述网络控制器的设备。 200780043341.5 第
- 89. 一种在通信系统中执行发现的方法,该通信系统包括第一无线通信系 统和第二无线通信系统,该第二无线通信系统包括Femto小区接入点(FAP ) 和供应网络控制器,该供应网络控制器用于将所述FAP可通信地耦合到所述 第一无线通信系统,该方法包括: a)从所述FAP向所述供应网络控制器发送发现请求消息,该发现请求 消息包括经许可的无线小区信息;以及 b )当所述供应网络控制器确定所述供应网络控制器能够接受所述发现 请求消息时,在所述FAP处接收发现接受消息,该发现接受消息包括基于所 述小区信息确定的默认网络控制器的标识,所述发现接受消息由所述供应网 络控制器发送。
- 910. 一种在通信系统中执行用户装置(UE)登记的方法,该通信系统 包括第一无线通信系统和第二无线通信系统,该第二无线通信系统包括 Femto小区接入点(FAP)和网络控制器,该网络控制器用于将所述FAP 可通信地耦合到所述第一无线通信系统,该方法包括: a) 在所述FAP和所述网络控制器之间建立所述UE专用的唯一的连接; 以及 b) 通过该专用的连接,在所述网络控制器处从所述FAP接收登记请求 消息。
- 1011. 如权利要求10所述的方法,其中,所述登记请求消息包括所述FAP 的标识和所述UE的标识。
- 1112. 如权利要求10所述的方法,其中,所述UE是第一 UE并且所述连 接是第一连接,该方法进一步包括: a)确定第二UE需要登记到所述网络控制器;以及 b )在所述FAP和所述网络控制器之间建立所述第二UE专用的第二唯 —的连接,所述FAP和所述网络控制器通过该连接交换一组信令消息;其中 所述第二连接不同于所述第一连接。
- 1213. 一种在通信系统中保护Femto小区接入点(FAP)和网络控制器之 200780043341. 5 第 间的通信安全的方法,该通信系统包括第一无线通信系统和第二网络,该第 二网络包括网络控制器和被可通信地耦合到所述网络控制器的FAP,该方法 包括: a)在所述FAP和所述网络控制器之间建立安全隧道;以及 b )使用所述安全隧道将所述FAP和多个用户装置(UE )可通信地耦 合到所述网络控制器; 其中所述UE被通过空中接口可通信地耦合到所述FAP。
- 1314. 如权利要求13所述的方法,其中所述安全隧道是IPSec隧道。
- 1415. 一种在通信系统中防止盗用服务的方法,该通信系统包括第一无线 通信系统和第二无线通信系统,第二无线通信系统包括Femto小区接入点 (FAP )和网络控制器,该网络控制器将所述FAP可通信地耦合到所述第一 无线通信系统,该方法包括: a) 创建包括第一用户装置(UE)的会话身份的经授权的会话,该会 话用于通过所述FAP将所述第一 UE与所述第一无线通信系统可通信地耦 合,所述第一无线通信系统将所述第一 UE识别为经授权使用所述FAP的 UE,所述第一 UE是通过一组身份来进行识别的;以及 b) 当第二UE的身份与所述一组第一 UE身份之中的任意身份都不匹 配时,拒绝所述FAP的对该第二UE进行登记的请求, 其中,被扌巨绝的请求包括所述经授权的会话的会话身份和所述第二UE 的身份,所述第一无线通信系统不将所述第二UE识别为经授权使用所述 FAP 的 UEo
- 1516. 如权利要求15所述的方法,进一步包括,将所述第一 UE的经授权 的会话注销登记。
- 1617. 如权利要求15所述的方法,其中所述经授权的会话是第一会话,该 方法进一步包括,使用来自所述第一 UE的所述一组身份之中的第一 UE的 身份,创建第二经授权的会话。 200780043341.5 第 1 如权利要求1所述的方法,其中,使用短距离的经许可的无线频率, 将所述UE可通信地耦合到所述FAP。
- 1719. 如权利要求1所述的方法,其中所述第二无线通信系统是通用接入 网络(GAN),其中所述网络控制器是通用接入网控制器(GANC)。
- 1820. 如权利要求1所述的方法,其中,通过通.用移动电信系统(UMTS) 陆地无线接入网络(UTRAN) Iu接口,将所述网络控制器可通信地耦合到 所述第一无线通信系统。 200780043341. 5
Independent claims18
970 paragraphs in 23 sections, as filed
Method and Equipment for Resource Management Cross Reference to Related Applications This application claims priority to the following U.S. provisional application: U.S. Provisional Application 60/826, 700, titled Radio Access Network-Generic Access to the Iu Interface for Femtocells, submitted On September 22, 2006; US provisional application 60/869, 900, titled Generic Access to the Iu Interface for Femtocells, filed on December 13, 2006; US provisional application 60/911, 862, titled Generic Access to the Iu Interface for Femtocells, filed on April 13, 2007; U.S. Provisional Application 60/949, 826, titled Generic Access to the Iu Interface, filed on July 13, 2007; U.S. Provisional Application 60/884, 889, titled Methods to Provide Protection against service Theft for Femtocells, filed on January 14, 2007; U.S. Provisional Application 60/893, 361, titled Methods to Prevent Theft of Service for Femtocells Operating in Open Access Mode, filed on March 6, 2007; US provisional application 60/884, 017, titled Generic Access to the Iu Interface for Femtocell-Stage 3, filed on January 8, 2007; US provisional application 60/911, 864, titled Generic Access to the Iu Interface for Femtocell-Stage 3, submitted on April 13, 2007; U.S. provisional application 60/862, 564, titled E-UMA-Generic Access to the Iu Interface, filed on October 23, 2006; U.S. Provisional Application 60/949, 853, titled Generic Access to the Iu Interface, filed on July 14, 2007 Ε); and, US provisional application 60/954, 549, titled Generic Access to the Iu Interfaces-Stage 2 Specification, filed on August 7, 2007. The content of each of the above provisional applications is hereby incorporated by reference.
Technical Field The present invention relates to the field of telecommunications. More specifically, the present invention relates to a technology for seamlessly integrating voice and data telecommunication services through a licensed wireless system and a short-term licensed wireless system.
BACKGROUND Licensed wireless systems provide mobile wireless communications to individuals who use wireless transceivers. With permission
200780043341.5 The first wireless system refers to the public cellular telephone system and/or the personal communication service (PCS) telephone system. Wireless transceivers include cellular phones, PCS phones, personal digital assistants with wireless functions, and wireless modems.
Licensed wireless systems utilize wireless signal frequencies licensed by the government. In order to access these frequencies, a lot of fees need to be paid. Use expensive base station (BS) devices to support communications on licensed frequencies. Typically, base stations are installed at a distance of about one mile between each base station (for example, a cell tower in a cellular network). The wireless transmission mechanism and frequency used by a typical licensed wireless system limit both the data transmission rate and the transmission range. Therefore, the quality of service (voice quality and data transmission speed) in a licensed wireless system is much lower than that provided by landline (wired) connections. In this way, users of licensed wireless systems pay higher fees but receive lower-quality services.
Landline (wired) connections are widely adopted and are usually implemented at a lower cost, while having higher-quality language and higher-speed data services. The problem with land line connection is that it restricts the mobility of users. Traditionally, a physical connection to the land line is required.
In the past few years, the use of unlicensed wireless communication systems to facilitate mobile access to land line-based networks has grown rapidly. For example, such an unlicensed wireless system may support wireless communication based on the IEEE 802.11a, b, or g standard (WiFi) or the Bluetooth® standard. The range of movement associated with such systems is usually on the order of 100 meters or less. A typical unlicensed wireless communication system includes a base station, which includes a wireless access A (AP) with a physical connection to a land-based network (for example, coaxial cable, twisted pair, or fiber optic cable). The AP has an RF transceiver to facilitate communication with wireless handsets working within a moderate distance of the AP. The data transmission rate supported by the WiFi and Bluetooth® standards is higher than the data transmission supported by the aforementioned licensed wireless system The rate is much higher. In this way, this option provides higher-quality service at a lower cost, but the service only extends to a moderate distance from the base station.
Currently, technologies are being developed to integrate the use of licensed and unlicensed wireless systems in a seamless manner, so that users can access unlicensed wireless systems via a single handset while in the range of such systems. Wireless system, and users can access a licensed wireless system when they are outside the range of an unlicensed wireless system. However, unlicensed wireless communication systems require the use of dual-mode wireless transceivers to communicate with licensed systems on licensed radio frequencies and to communicate with unlicensed systems on unlicensed radio frequencies . The use of this dual-mode transceiver requires the service provider to upgrade the transceivers of existing users who only work on licensed radio frequencies to dual-mode
200780043341.5 No. Transceiver. Therefore, in the prior art, it is necessary to develop a system that provides the beneficial effects of the above-mentioned system without the need for a dual-mode transceiver.
SUMMARY OF THE INVENTION Some embodiments implemented in a communication system include a first wireless communication system and a second wireless communication system. The second wireless communication system includes a Femto cell (Femtocell), an access point (FAP), and a network controller , The network controller communicatively couples the FAP to the first wireless communication system.
In some embodiments, the network controller is communicatively coupled to the first wireless communication system through the UTRAN Iu interface. In some embodiments, the FAP uses a short-range licensed wireless frequency to be communicatively coupled to the user device.
Some embodiments provide a resource management method for determining that a user equipment (UE) has roamed in the area served by the FAP. FAP includes the General Access Resource Control (GA-RC) protocol sublayer. This method creates a separate GA-RC state dedicated to the UE in the GA-RC protocol sublayer. The method also sets the UE-specific GA-RC state to a deregistered state to indicate that the UE is not registered to use the service of the second wireless communication system.
Some embodiments provide a method for judging whether the UE has roamed outside the second communication system. This method receives periodic messages from the UE at the FAP. When the FAP cannot receive a predetermined number of periodic messages, the method sends a deregistration message to the network controller through the only connection dedicated to the UE between the FAP and the network controller, and also releases the dedicated connection.
Some embodiments provide methods to release resources after losing the connection. This method sends periodic messages from the FAP to the network controller through the connection between the FAP and the network controller to determine whether the connection is lost. When the FAP determines that the connection is lost, the FAP deregisters the user equipment (UE) communicably coupled with the FAP, and forces the UE to perform cell reselection.
Some embodiments provide a Femto cell access point (FAP) method. The method sends a registration request message, the registration request message including the type of registration from the FAP to the network controller. This registration type identifies the FAP as a device to be registered with the network controller. If the registration request message is acceptable to the network controller, the FAP receives the registration acceptance message.
Some embodiments provide methods for performing discovery. The method sends a discovery request message, and the discovery request message includes the licensed wireless cell information sent to the provisioning network controller. This method receives the discovery acceptance message at the FAP. Discovery acceptance message includes default network control based on cell information
200780043341.5 The identification of the device. When the provisioning network controller determines that the provisioning network controller can accept the discovery request message, the provisioning network controller sends a discovery acceptance message.
Some embodiments provide methods for performing user equipment (UE) registration. This method establishes a unique connection dedicated to the UE between the FAP and the network controller. The method receives a registration request message from the FAP at the network controller through the dedicated connection.
Some embodiments provide a security control method. The method receives a security mode command. The security mode command includes a set of security keys and a set of security algorithms from the network controller at the FAP. The set of security keys and the set of security algorithms are from the network controller. Received by the wireless communication system. The method judges the integrity of a set of messages exchanged between the FAP and the user equipment (UE), wherein the user equipment (UE) is communicatively coupled to the FAP via the air interface by using the set of security keys and the set of security algorithms .
Some embodiments provide methods to provide security. This method establishes a secure tunnel between the FAP and the network controller. This method communicatively couples the FAP and several user devices (UEs) to the network controller by using a secure tunnel. The UE is communicatively coupled to the FAP via an air interface.
Some embodiments provide a method to prevent theft of services. The method creates an authorized session, and the authorized session includes the session identity of the first user equipment (UE). The session is used to communicatively couple the first UE and the first wireless communication system through the FAP. The first UE is recognized by the first wireless communication system as a UE authorized to use FAP» When the identity of the second UE does not match any of the identities of the first UE in the group, the method rejects the FAP from registering the second UE. request. The rejected request includes the session identity of the authorized session and the identity of the second UE. The first wireless communication system will not recognize the second UE as a UE authorized to use FAP.
BRIEF DESCRIPTION OF THE DRAWINGS The appended claims set forth the novel features of the present invention. However, for illustrative purposes, several embodiments of the present invention are described in the following drawings.
Figure 1 shows an integrated communication system (ICS) of some embodiments;
Figure 2 shows several applications of ICS in some embodiments; Figure 3 shows the overall A/Gb mode GAN functional structure of some embodiments; Figure 4 shows the overall Iu mode GAN functional structure of some embodiments; 5 shows the Femto cell functional structure of some embodiments; FIG. 6 shows some embodiments with an asynchronous transfer mode (ATM) connection towards the core network
200780043341.5 Femto cell network structure; Figure 7 shows a Femto cell network structure with an IP interface facing the core network of some embodiments; Figure 8 shows a CS domain control plane structure of some embodiments; Figure 9 shows The CS domain user plane protocol structure of some embodiments is shown; FIG. 10 shows the PS domain control plane structure of some embodiments; FIG. 11 shows the PS domain user plane protocol structure of some embodiments; FIG. 12 shows some implementations. Figure 13 shows the state diagram of the GA-CSR in the FAP of each UE in some embodiments; Figure 14 shows the state diagram of the GA-CSR in the FAP of each UE in some embodiments; The state diagram of GA-PSR in FAP; Figure 15. shows the GA-CSR connection initiated by FAP established in some embodiments; Figure 16 shows the GA-CSR connection release of some embodiments; Figure 17 shows The GA-PSR connection initiated by the FAP established in some embodiments; Figure 18 shows the GA-PSR connection release in some embodiments; Figure 19 shows the FAP power-on discovery processing of some embodiments; Figure 20 shows some FAP power-on registration processing in an embodiment; FIG. 21 shows messages related to synchronization processing initiated by FAP in some embodiments; FIG. 22 shows UE registration in some embodiments; Figure 23 shows a UE roaming outside the service area in some embodiments; Figure 24 shows a situation where the UE powers off and performs IMSI separation in some embodiments; Figure 25 shows a loss of the Up interface in some embodiments Connectivity situation; Figure 26 shows the registration update situation initiated by FAP in some embodiments; Figure 27 shows the registration update situation initiated by INC in some embodiments; Figure 28 shows the FAP initiated registration update situation in some embodiments Figure 29 shows the voice carrier establishment processing in some embodiments (for MO/MT calls using Iu-UP on AAL2); Figure 30 shows the mobile station-originated in some embodiments Mobile-to-PSIN call; Figure 31 shows a PSTN-to-mobile call terminating at a mobile station in some embodiments; Figure 32 shows a call release performed by a Femto cell user in some embodiments; Figure 33 An example of relaying DTAP auxiliary service messages in some embodiments is shown;
200780043341.5 Figure 34 shows the activation of the GA-PSR transmission channel initiated by the FAP in some embodiments; Figure 35 shows the deactivation of the transmission channel initiated by the FAP in some embodiments; Figure 36 shows the activation of the transmission channel in some embodiments Network-initiated transmission channel activation for user data services; Fig. 37 shows network-initiated transmission channel deactivation in some embodiments; Fig. 38 shows Femto cell user plane data transmission processing in some embodiments; 39 shows the uplink control plane data transmission of some embodiments; FIG. 40 shows the downlink control plane data transmission of some embodiments; FIG. 41 shows the protocol structure of the CS mode SMS in some embodiments; Figure 42 shows the GAN protocol structure of the packet mode SMS in some embodiments; Figure 43 shows the SMS delivery via the GAN circuit mode originating from the mobile station in some embodiments; Figure 44 shows the GAN protocol structure in some embodiments The CS mode of the Femto cell terminates in the SMS delivery of the mobile station; Figure 45 shows the service area-based routing situation of some embodiments; Figure 46 shows the GAN Femto cell security mechanism in some embodiments; Figure 47 Shows the EAP-SIM authentication processing in some embodiments; FIG. 48 shows the EAP-AKA authentication processing in some embodiments; FIG. 49 shows the message flow for security mode control in some embodiments; Figure 50 shows AKA processing for mutual authentication in some embodiments; Figure 51 shows advanced processing that can lead to fraudulent FAP service embezzlement; Figure 52 shows Femto cell service embezzlement prevention in some embodiments Solution; Figure 53 shows the prevention of Femto cell service misappropriation in some embodiments; Figure 54 shows the service access control of a new FAP connected to the Femto cell network in some embodiments; Figure 55 shows Service access control for FAPs redirected in Femto cell network in some embodiments; Figure 56 shows service access control for FAPs registered in restricted UMTS coverage areas in some embodiments; Figure 57 shows service access control for unauthorized UEs accessing authorized FAPs in some embodiments;
200780043341.5 Figure 58 conceptually shows the computer system used in the implementation of some embodiments.
DETAILED DESCRIPTION In the following detailed description of the present invention, many details, examples, and embodiments of the present invention are described. However, it will be clear to those skilled in the art that the present invention is not limited to the described embodiments, and the present invention can be implemented without using some of the specific details and examples discussed.
Throughout this article, common abbreviations for wireless services in the telecommunications industry are used, as well as special abbreviations for the present invention. A list of abbreviations used in this application is provided in Section XV.
Some embodiments are implemented in a communication system. The communication system includes a first wireless communication system and a second wireless communication system. The second wireless communication system includes a Femto cell access point (FAP) and a network controller. The network controller can communicate with each other. The FAP is coupled to the first wireless communication system.
In some embodiments, the network controller can be communicatively coupled to the first wireless communication system through a UTRAN Iu interface. In some embodiments, the FAP can use a short-range licensed wireless frequency to communicatively couple to the user device.
Some embodiments provide a resource management method that determines that a user equipment (UE) has roamed in an area served by a FAP. FAP includes the General Access Resource Control (GA-RC) protocol sublayer. This method creates a separate GA-RC state dedicated to the UE in the GA-RC protocol sublayer. The method also sets the UE-specific GA-RC state to a deregistration state to indicate that the UE is not registered to use the service of the second wireless communication system.
Some embodiments provide methods for determining whether the UE has roamed outside the second communication system. This method receives periodic messages from the UE at the FAP. When the FAP cannot receive a predetermined number of periodic messages, the method sends a deregistration message to the network controller on the only connection dedicated to the UE between the FAP and the network controller, and also releases the dedicated connection.
Some embodiments provide a method of releasing resources after a connection is lost. This method sends periodic messages from the FAP to the network controller on the connection between the FAP and the network controller to determine whether the connection is lost. When the FAP determines that the connection is lost, the FAP deregisters the user equipment (UE) communicably coupled with the FAP, and forces the UE to perform cell reselection.
Some embodiments provide a method of registering a Femto cell access point (FAP). The method sends a registration request message from the FAP to the network controller, and the registration request message includes the registration type. The registration type identifies the FAP as a device to be registered to the network controller. When the registration request message is acceptable to the network controller, the FAP receives the registration acceptance message.
200780043341.5 The first embodiment provides a method for performing discovery processing. The method sends a discovery request message to the provisioning network controller, the message including the licensed wireless cell information. This method receives the discovery acceptance message at the FAP. The discovery acceptance message includes the identity of the default network controller determined based on the cell information. When the provisioning network controller determines that it can accept the discovery request message, the provisioning network controller sends a discovery acceptance message.
Some embodiments provide a method of performing user equipment (UE) registration. This method establishes a unique connection dedicated to the UE between the FAP and the network controller. The method receives a registration request message from the FAP through the dedicated connection at the network controller.
Some embodiments provide a security control method. The method receives a security mode command from a network controller at the FAP. The security mode command includes a set of security keys and a set of security algorithms. The set of security keys and the set of security algorithms are from the first wireless communication at the network controller. Received by the system. The method uses the set of security keys and the set of security algorithms to determine the integrity of a set of messages exchanged between the FAP and a user equipment (UE) communicatively coupled to the FAP through an air interface.
Some embodiments provide a method of providing security. This method establishes a secure tunnel between the FAP and the network controller. The method communicatively couples the FAP and several user equipment (UE) to the network controller by using a secure tunnel. The UE is communicatively coupled to the FAP through the air interface.
Some embodiments provide a method to prevent theft of services. The method creates an authorized session that includes the session identity of the first user equipment (UE). The session is used to communicatively couple the first UE and the first wireless communication system through the FAP. The first wireless communication system recognizes the first UE as a UE authorized to use FAP. When the identity of the second UE does not match any identity in the group of identities of the first UE, the method rejects the request issued by the FAP to register the second UE. The rejected request includes the session identity of the authorized session and the identity of the second UE. The first wireless communication system does not recognize the second UE as a UE authorized to use FAP.
Several more detailed embodiments of the invention are described in the following sections. Specifically, Section I describes an overall integrated communication system incorporating some embodiments. After the discussion in Section I, Section II discusses the system structure of the Femto cell system. Next, Section III describes the protocol structure of the Femto cell system. Then, Section IV describes the resource management processing of the Femto cell system in some embodiments. Next, Section V shows the mobility management functions of the Femto cell system in some embodiments.
Next, Section VI describes the call management process of the Femto cell system. After this section,
200780043341.5 Section VII describes the packet services of the Femto cell system in some embodiments. The error handling process is described in Section VIII. Section IX provides a list of messages and information elements used in different embodiments. Section X describes the short message service support of the Femto cell system, and then describes emergency services in Section XI.
The Femto cell system security functions are described in Section XII. After this description, Femto cell system service access control is discussed in Section XIII. Next, Section XIV describes the computer system used in the implementation of some embodiments of the present invention. Finally, Section XV lists the abbreviations used in this article.
I. Overall system
A. Integrated communication system (ICS) FIG. 1 shows an integrated communication system (ICS) structure 100 according to some embodiments of the present invention. The ICS structure 100 enables user equipment (UE) 102 to pass through a licensed air interface 106 or The ICS access interface 110 is used to access the voice and data network 165. Alternatively, each component of the licensed wireless core network 165 can be accessed through the licensed air interface 106 or the ICS access interface 110. In some embodiments, the communication session conducted through any of the above interfaces includes voice service, data service, or both.
The mobile core network 165 includes one or more home location registers (HLR) 150 and a database 145 for user authentication and authorization. Once authorized, the UE 102 can access the voice and data services of the mobile core network 165. To provide such services, the mobile core network 165 includes a mobile switching center (MSC) 160 to provide access to circuit-switched services (eg, voice and data). The packet-switched service is provided through a service GPRS (General Packet Radio Service) support node (SGSN) 155 in cooperation with a gateway, such as a gateway GPRS support node (GGSN) 157.
SGSN 155 is typically responsible for transferring data packets from user devices in the geographic service areas of GGSN 157 and SGSN 155, and to transfer data packets to user devices in the geographic service areas of GGSN 157 and SGSN 155. In addition, the SGSN 155 can perform functions such as mobility management, storing user configuration files, and storing location information. However, the actual interface from the mobile core network 165 to various external data packet service networks (for example, the public Internet) is facilitated by the GGSN 157. Since data packets originating from user devices are typically not structured in a format used to access external data networks, the GGSN 157 acts as a gateway in such a packet service network. In this way, the GGSN 157 provides communication to and from the UE 102 and an external packet service network (not shown)
200780043341.5 The addressing of the data packet. In addition, when a user device of a licensed wireless network passes through multiple service areas and thus multiple SGSNs, the role of the GGSN 157 is to provide a static gateway in the external data network.
In the illustrated embodiment, the common components of the cellular network based on the UMTS Terrestrial Radio Access Network (UTRAN) include multiple base stations (referred to as Node B) 180 (For simplicity, only one Node E is shown) The base station 180 facilitates providing wireless communication services for each user device 102 via a corresponding licensed wireless link 106 (for example, a wireless link using a wireless frequency within a licensed bandwidth). However, those skilled in the art will recognize that in some embodiments, the licensed wireless network may include other components, such as a GSM/EDGE radio access network (GERAN). Figure 3 shows an example of a system that uses A and Gb interfaces to access GERAN, which will be described in more detail below.
The licensed wireless channel 106 may include a voice/data network with a defined UTRAN or GERAN interface protocol (for example, Iu-cs and Iu-ps interfaces for UTRAN, or A and Gb interfaces for GERAN) Of any licensed wireless service. The UTRAN 185 typically includes at least one Node B 180 and a radio network controller (RNC) 175 for managing the group of Node Bs 180. Typically, the plurality of Node Bs 180 are configured in a cellular configuration covering a wide service area ( One node per cell B). Licensed radio cells are sometimes called macro cells, which is a logical term used to refer to, for example, UMTS radio cells under Node-B/RNC (ie, 3G cells), which are used to Provides coverage typically within a range of tens of kilometers. Similarly, UTRAN or GERAN is sometimes referred to as a macro network.
Each RNC 175 communicates with various components of the core network 165 through standard radio network controller interfaces, such as the Iu-cs and Iu-ps interfaces shown in FIG. 1. For example, the RNC 175 communicates with the MSC 160 via the UTRAN Iu-cs interface for circuit-switched services. In addition, the RNC 175 communicates with the SGSN 155 through the GGSN 157 via the UTRAN Iu-ps interface for packet switching services. In addition, those skilled in the art will realize that in some embodiments, other networks with other standard interfaces may also be used. For example, the RNC 175 in the GERAN network can be replaced with a base station controller (BSC) that communicates with the MSC 160 via the A interface of circuit-switched services and a BSC that communicates with the SGSN via the Gb interface of the GERAN network for packet-switched services.
In some embodiments of the ICS structure, the user device 102 is facilitated by the ICS access interface 110 and the universal access network controller (GANC) 120 (also known as the universal network controller or UNC)
200780043341.5 The second communication network to use the services of the mobile core network (CN) 165.
In some embodiments, voice and data services are advanced through the ICS access interface 110, which is communicatively coupled to the broadband IP network 116 via the access point 114. In some embodiments, the access point 114 is An ordinary wireless access point. The access point 114 connects the user device 102 to the ICS network through an unlicensed wireless network 118 created by the access point 114. In some other embodiments, the access point 114 is a Femto cell access point (FAP) 114 that is communicatively coupled to the broadband IP network 116. FAP facilitates a short-range licensed wireless communication session 118, which operates independently of the licensed communication session 106. In some embodiments, the area covered by GANC, FAP, UE, and FAP is collectively referred to as a Femto cell system. The area spanned by a Femto cell (typically tens of meters) is smaller than that of a macro cell. In other words, a Femto cell is a micro cell whose range is 100, 1000, or more times smaller than that of a macro cell. In the case of the Femto cell system, the user device 102 is connected to the ICS network through a short-distance licensed wireless network created by the FAP 114. Then, the signal from the FAP is transmitted on the broadband IP network 116.
The signaling from the UE 102 is transferred to the GANC 120 through the ICS access interface 110. After the GANC 120 performs user authentication and authorization, the GANC 120 uses the same or similar radio network controller interface as the UTRAN described above and includes the UTRAN Iu-cs interface for circuit-switched services and the interface for packet switching. The radio network controller interface of the UTRAN Iu-ps interface of the service (for example, GPRS) communicates with the components of the mobile core network 165. In this way, the GANC 120 uses the same or similar interface to connect to the mobile core network as the UTRAN radio access network subsystem (for example, nodes E180 and RNC 175).
In some embodiments, GANC 120 passes through one or more of several other interfaces (ie, (1) Up, (2) Wm'\ (3) D7Gr\ (4) Gn, and (5) SI), Communicate with other system components of the ICS system. The Up interface is a standard interface used for session management between UE 102 and GANC 120. The Wm interface is a standardized interface between the GANC 120 and the authorization, authentication, and accounting (AAA) server 170, and is used for the authentication and authorization of the UE 102 to the ICS. The D7Gr'# port is a standard interface between the AAA server 170 and the HLR 160. Optionally, some embodiments use a GN interface, which is a modified interface for direct communication with a data service gateway (eg, GGSN) of the mobile core network. Some embodiments optionally include an S1 interface. In these embodiments, the S1 interface provides an authorization and authentication interface from the GANC 120 to the AAA server 140. In some embodiments, the AAA server 140 supporting the S1 interface and the AAA server 170 supporting the Wm interface may be the same. U.S. application 11/349,025 describes
200780043341.5 No.
More details of the S1 interface, titled Service Access Control Interface for Unlicensed Wireless Communication Systems, were submitted on February 6, 2006.
In some embodiments, the UE 102 must register with the GANC 120 before accessing the ICS service. The registration information of some embodiments includes the user's international mobile subscriber identity (IMSI), medium access control (MAC) address, and service setting identifier (SSID) of the service access point, as well as the cell identity from the GSM or UTRAN cell, UE102 The cell has been camped on (when the UE has completed the cell selection/reselection process and the cell has been selected, the UE camps on the cell; the UE monitors system information, and in most cases, the system information is paging information). In some embodiments, the GANC 120 may pass this information to the AAA server 140 to authenticate the user and determine that the service (eg, voice and data) is available to the user. If the AAA server 140 approves the access, the GANC 120 will allow the UE 102 to access the voice and data services of the ICS system.
These circuit-switched and packet-switched services are seamlessly provided to the UE 102 by the ICS through the various interfaces described above. In some embodiments, when the UE 102 requests data services, the ICS uses the optional Gri interface to directly communicate with the GGSN 157 Communication. The Gn, interface allows the GANC 120 to avoid the overhead and delay time associated with communication with the SGSN 155 through the Iu-ps interface of UTRAN or the Gb interface of the GSM core network before reaching the GGSN 157.
B. Application of ICS
ICS provides a scalable and secure interface to the core service network of the mobile communication system. Figure 2 shows several applications of ICS in some embodiments. As shown in the figure, homes, offices, hotspots, hotels, and other public and private places 205 are connected to one or more network controllers 210 (such as the GANC 120 shown in FIG. 1) through the Internet 215. The network controller is thus connected to the mobile core network 220 (such as the core network 165 shown in FIG. 1).
Figure 2 also shows several user devices. These user devices are just some examples of user devices that can be used for each application. Although in most examples, only one of each type of user device is shown, those skilled in the art will understand that other types of user devices can also be used in these examples without departing from the technology of the present invention. Program. Similarly, although only one of each type among access points, user devices, or network controllers is shown, many such access points, user devices, or network controllers can also be used in FIG. 2. For example, an access point can be connected to several user devices, a network controller can be connected to several access points, and several network controllers can be connected to a core network. The following subsections provide several examples of services that ICS can provide.
1. Wi-Fi
200780043341.5 No.
The Wi-Fi access point 230 enables the dual-mode cellular/Wi-Fi UE 260-265 to receive high-performance and low-cost mobile services when in the range of a home, office, or public Wi-Fi network. With dual-mode UEs, users can roam and switch between licensed wireless communication systems and Wi-Fi access, and can receive a consistent set of services when they switch between networks.
2. Femto community
The Femto cell enables user devices, such as the illustrated standard mobile station 270 and the wireless-capable computer 275, to receive low-cost services through the FAP 235 using a short-range licensed wireless communication session.
3. Terminal Adapter The terminal adapter 240 allows the combination of fixed terminal equipment, such as a telephone 245, a facsimile machine 250, and other devices in the ICS that have no wireless function. As long as the user is interested, the service can function as a standard analog fixed telephone line. This service is delivered in a manner similar to other fixed line V0IP services, where the UE is connected to the user's existing broadband (eg, Internet) service.
4. WiMAX Some licensed wireless communication system operators are studying the deployment of WiMAX networks in parallel with their existing cellular networks. Dual-mode cellular/WiMAX UE 255 enables users to seamlessly switch between cellular networks and such WiMAX networks through WiMax access point 290.
5. SoftMobile It has become common to connect laptops 280 to broadband access and Wi-Fi hotspots in hotels, especially for international business travelers. In addition, many travelers are beginning to use their laptops and broadband connections for voice communications. When making long-distance calls, they use software mobile stations (or softphones (SoftPhone)) and V6IP services instead of using mobile phones to make calls and pay a lot of roaming fees.
The user can put the USB memory stick 285 with the embedded SIM into the USB port of his laptop 280 to use the software mobile station service. Software mobile station customers can automatically initiate and connect to the mobile service provider via IP. From this point on, the user will be able to make calls and receive mobile calls as if he were in his own home calling zone.
Several examples of integrated communication systems (ICS) are given in the following subsections. Those of ordinary skill in the art will understand that the technical solutions in these examples can be easily combined. For example, an ICS may be an IP-based system with an A/Gb interface to the core network, while another ICS may have a similar IP-based system with an Iu interface to the core network.
200780043341.5 No.
C. Integrated system with A/Gb and/or Iu interfaces to the core network FIG. 3 shows the functional structure of the A/Gb-mode General Access Network (GAN) of some embodiments. The GAN includes one or more general access network controllers (GANC) 310 and one or more general IP access networks 315. One or more UEs 305 (for brevity, only one is shown in the figure) can be connected to the GANC310 through the universal IP access network 315» GANC310 has the core network 325 behaves as a GSM/EDGE radio access network (GERAN) base station controller (BSC) ability. GANC 310 includes a security gateway (SeGW) 320, which terminates the secure remote access tunnel from UE 305, and the security gateway 320 provides mutual authentication, encryption, and data for signaling, voice, and data traffic. Completeness.
The general IP access network 315 provides the connection between the UE 305 and the GANC 310. The IP transport connection extends from GANC 310 to UE 305. Between the GANC 310 and the UE 305, a single interface is defined, that is, the Up interface.
GAN and GERAN co-exist and maintain interconnection with the core network (CN) 325 via standardized interfaces defined for GERAN. These standardized interfaces include the A interface for circuit-switched services to the Mobile Switching Center (MSC) 330, the Gb interface for packet-switched services to the Serving GPRS Support Node (SGSN) 335, and the Serving Mobile Location Center (SMLC) 350. The Lb interface used to support location services, and the interface to the Cell Broadcast Center (CBC) 355 to support cell broadcast services. Transaction control (for example, connection management, CC and session management, SM) and user services are provided by the core network (for example, MSC/VLR and SGSN/GGSN).
As shown in the figure, the SeGW 320 is connected to the AAA server 340 through the Wm interface. The AAA server 340 is used to authenticate the UE 305 when the UE 305 establishes a secure tunnel. Some embodiments require only a subset of Wm functions when used in GAN applications. In these embodiments, at least the GANC-SeGW should support Wm authentication processing.
Figure 4 shows the Iu-mode General Access Network (GAN) functional structure of some embodiments. The GAN includes one or more general access network controllers (GANC) 410 and one or more general IP access networks 415. One or more UE 405 (for brevity, only one is shown in the figure) can be connected to the GANC 410 through the universal IP access network 415. Compared with the GANC 310, the GANC 410 has a core network 425 that appears as a UMTS terrestrial radio access network. (UTRAN) The capabilities of the Radio Network Controller (RNC). In some embodiments, the GANC has the extension capability of UEs that support both the Iu interface and the A/Gb interface to support both the Iu mode and the A/Gb mode. Similar to GANC 310, GANC 410 includes a secure gateway (SeGW) 420, which terminates secure remote access from UE 405.
200780043341.5 The first entry tunnel, and the security gateway (SeGW) 420 provides mutual authentication, encryption and data integration for signaling, voice and data communications.
The universal IP access network 415 provides the connection between the UE 405 and the GANC 410. The IP transport connection extends from the GANC 410 to the UE 405. Between GANC 410 and UE 405, a single interface, the Up interface, is defined. Compared with the UP interface shown in Figure 3, the interface has been added functions to support GAN services in Iu mode.
GAN coexists with UTRAN and maintains interconnection with the core network (CN) 425 via standardized interfaces defined for UTRAN. These standardized interfaces include the Iu-cs interface for circuit-switched services to the mobile switching center (MSC) 430, the Iu-ps interface for packet-switched services to the serving GPRS support node (SGSN) 435, and the serving mobile positioning center. (SMLC) 450 Iu-pc interface for supporting location services, and Iu-bc interface to cell broadcast center (CBC) 455 for supporting cell broadcast services. Transaction control (for example, connection management, CC and session management, SM) and user services are provided by the core network (for example, MSC/VLR and SGSN/GGSN).
As shown in the figure, the SeGW 420 is connected to the AAA server 440 through the Wm interface. The AAA server 440 is used to authenticate the UE 405 when the UE 405 establishes a secure tunnel. Some embodiments only require a subset of Wm functions when used in GAN applications in Iu mode. In these embodiments, at least the GANC-SeGW should support Wm authentication processing.
II. FEMTO cell system structure FIG. 5 shows the functional structure of the Femto cell system of some embodiments. As shown, many of the components of the system shown in FIG. 5 are similar to those in FIG. 4. In addition, the Femto cell system includes a Femto cell access point (FAP) 560, and the Femto cell access point (FAP) 560 communicatively couples the UE 505 to the GANC 510 through a general IP access network 515. In this disclosure, the interface between UE 505 and FAP 560 is called Uu interface. The UE 505 and the FAP 560 communicate through a short-range wireless air interface using a licensed wireless frequency. GANC510 is an enhanced version of GANC 410 shown in Figure 4. The security gateway (SeGW) 520 component of the GANC 510 terminates the secure remote access tunnel from the FAP 560, and the security gateway (SeGW) 520 component provides mutual authentication, encryption, and data integration for signaling, voice, and data services.
Femto cell access point (AP) management system (AMS) 570 is used to manage a large number of FAPs. AMS 570 functions include configuration, fault management, diagnosis, monitoring and software upgrades. The interface between AMS 570 and FAP 560 is called the S3 interface. S3 interface enables FAP to safely access Femto
200780043341.5 The access point management service of the cell. All communications between the FAP and the AMS are exchanged via the Femto cell security tunnel, which is established between the FAP and the SeGW 520. As shown in the figure, AMS 570 accesses an AP/user database (Femt cell DB) 575, which provides a centralized data storage facility for Femto cell AP (ie, FAP) and user information. Multiple Femto cell system elements can access the Femto cell DB via the AAA server.
The IP network controller (INC) 565 component of GANC 510 is connected to the AAA/proxy server 540 through the S1 interface to provide FAP-related information and service access control. As shown in FIG. 5, the AAA/proxy server 540 is also connected to the AP/user database 575 through an interface.
A. ATM and IP-based architecture In some embodiments, the Femto cell system uses asynchronous transfer mode (ATM) based on the Iu (Iu-cs and Iu-ps) interface to the CN. In some embodiments, the Femto cell system structure may also support IP-based Iu (Iu-cs and Iu-ps) interfaces to the CN.
Those skilled in the art will understand that the same example can be easily applied to other types of ICSo. For example, when the ICS access interface 110 (as shown in Figure 1) uses an unlicensed frequency (instead of the Femto cell's These examples can be used when the access point 114 is a universal WiFi access point (rather than a FAP), etc., when licensed frequency). Likewise, those skilled in the art will understand that the A/Gb interface (as described above) can be easily used instead of the Iu interface to implement these examples.
Figure 6 shows the basic elements of the Femto cell system structure with Iu (Iu-cs and Iu-ps) interfaces to the CN based on asynchronous transfer mode (ATM) in some embodiments. These elements include User Equipment (UE) 605, FAP610 and General Access Network Controller (GANC) 615, and AMS 670.
For brevity, only one UE and one FAP are shown in the figure. However, each GANC can support multiple FAPs, and each FAP can support multiple UEs. As shown in the figure, the GANC 615 includes an IP network controller (INC) 625, a GANC security gateway (SeGW) 630, a GANC signaling gateway 635, a GANC media gateway (MGW) 640, and an ATM gateway (645). The elements of Femto cell are further described below.
Figure 7 shows the basic elements of a Femto cell system structure with an IP-based Iu (Iu-cs and Iu-ps) interface to the CN in some embodiments. For brevity, only one UE and one FAP are shown in the figure. However, each GANC can support multiple FAPs, and each FAP can support multiple UEs. This optional solution eliminates the need for GANC signaling gateway 635 and ATM gateway 645
200780043341.5 Article needs. Optionally, for the IP-based Iu interface, if the R4 MGW 705 in the CN can support the termination of voice data, that is, an RTP frame as defined in the following text: Real-Time Transport Protocol (RTP) Payload Format and File Storage Format for The Adaptive Multi-Rate (AMR) and Adaptive Multi-Rate Wideband (AMR-WB) Audio Codecs, IETF RFC 3267, hereinafter referred to as RFC 3267, GANG Media Gateway 640 can also be eliminated.
Figures 6 and 7 also show the components of the licensed wireless communication system. These components are 3G MSC650, 3G SGSN 655 and other core network systems (shown together in the figure) 665. 3G MSC 650 provides a standard Iu-cs interface leading to GANC. Figure 7 shows another alternative embodiment of the MSC. As shown in the figure, MSC 750 is divided into MSS (MSC Server) 775 for Iu-cs-based signaling and MGW 780 for carrier path »R4 MSC 750 is the release 4 version of 3G MSC with different structures, namely , R4 MSC is divided into MSS used to control services and MGW used to handle carriers. For the ATM structure of Figure 6, a similar MSC can be used. The two structures shown in Figures 6 and 7 can also be adapted to use any future version of MSC.
3G SGSN 655 provides packet service (PS) via a standard Iu-ps interface. The SGSN is connected to INC 625 for signaling and SeGW 630 for PS data. The AAA server 660 communicates with the SeGW630 via the Wm interface and supports EAP-AKA and EAP-SIM processing used in IKEv2, and includes a MAP interface connected to the HLR/AuC. The system also supports enhanced service access control functions through the S1 interface.
For the sake of brevity, in some illustrations in this application, only the INC component of GANC is shown. Similarly, whenever INC is a component of GANC, references to INC and GANC are interchangeable.
B. Functional entity
1. User Equipment (UE)
The UE includes functions required to access the Iu-mode GAN. In some embodiments, the UE additionally includes functions required to access A/Gb-mode GAN. In some embodiments, the user equipment (UE) is a dual-mode (eg, GSM and unlicensed radio) handheld device with the ability to switch between the two modes. The user device can support Bluetooth® or IEEE 802.11 protocols. In some embodiments, the UE supports an IP interface connected to an access point. In these embodiments, the IP connection from the GANC extends all the way to the UE. In some other embodiments, the user equipment (UE) is a standard 3G handheld device operating on the provider's licensed spectrum.
200780043341. 5 In some embodiments, the user device includes a cell phone, smart phone, personal digital assistant, or computer equipped with a Subscriber Identity Mobile (SIM) card for communicating on a licensed or unlicensed wireless network. In addition, in some embodiments, a computer equipped with a SIM card communicates through a wired communication network.
Alternatively, in some embodiments, the user device includes a fixed wireless device that provides a set of terminal adapter functions to integrate Integrated Services Digital Network (ISDN), Session Initiation Protocol (SIP) or Plain Old Telephone Service (POTS) ) The terminal is connected to the ICS. Applying the present invention to this type of equipment enables wireless service providers to provide users with so-called landline alternative services, even for those users whose locations are not sufficiently covered by licensed wireless networks. In addition, some embodiments of terminal adapters are fixed wired devices used to connect ISDN, SIP, or POTS terminals to different communication networks (for example, IP networks), but alternative embodiments of terminal adapters provide unlicensed or licensed The wireless equivalent function of connecting to the wireless network.
2. Femto cell access point (FAP)
FAP is a licensed access point that provides a standard wireless interface (Uu) for UE connection. FAP uses a revised version of the standard GAN interface (Up) to provide wireless access to the network for the UE. In some embodiments, the FAP is equipped with a standard 3G USIM or 2G SIM.
According to some embodiments, the FAP 610 will be located in a fixed structure, such as a home or office building. In some embodiments, the service area of the FAP includes an indoor part of a building, although it is understood that the service area may include an outdoor part of a building or a venue.
3. General Access Network Controller (GANC)
GANC 510 is an enhanced version of GANC defined in the following standards: Generic access to the A/Gb interface; Stage 2, 3GPP TS 43.318 standard, hereinafter referred to as TS 43.318 standard. GANC acts as the UTRAN Radio Network Controller (RNC) for the core network. GANC includes a security gateway (SeGW) 520 and an IP network controller (INC) 565. In some embodiments (not shown in FIG. 5), the GANC further includes a GANC signaling gateway 635, a GANC media gateway (MGW) 640, and/or an ATM gateway (645).
SeGW 520 provides functions defined in the following standards: TS 43.318 standard and Generic access to the A/Gb interface; Stage 3, 3GPP TS 44.318 standard. SeGW terminates the secure access tunnel from FAP and provides mutual authentication, encryption, and data integration for signaling, voice, and data services. The SeGW 520 needs to support the EPA-SIM and EAP-AKA authentication of the FAP 560.
200780043341.5 No.
INC 565 is the main GANC component. In some embodiments, a load balancing router/switching subsystem is connected to the front end of the INC, which connects the INC to other GAN systems; for example, a GANC security gateway, a local or remote management system, etc.
GANC MGW640 provides interactive functions between the Up interface and the Iu-CS user plane. GANC MGW will provide the interaction between RFC 3267-based frames received on the Up interface and Iu-UP frames sent to the CN. The GANC signaling GW 635 provides protocol conversion between the SIGTRAN interface leading to the INC and the ATM-based Iu-cs interface leading to the CN. ATM GW 645 provides ATM/IP gateway function, mainly routing Iu-ps user plane packets between SeGW (IP interface) and CN (AAL5 based ATM interface).
4. Broadband IP network Broadband IP network 515 represents all elements that collectively support the IP connection between the GANC SeGW 520 function and the FAP 560. This includes: (1) Other Customer premise equipment (for example, DSL/cable modem, WLAN switch, residential gateway/router, switch, hub, WLAN access point), (2) dedicated broadband access technology Network system (for example, DSLAM or CMTS), (3) ISP IP network system (edge router, core router, firewall), (4) wireless service provider (WSP) IP network system (edge router, core router, firewall) , And, (5) Network address translation (NAΓ) function, independent or integrated into one or more of the above systems.
5. AP Management System (AMS)
AMS 570 is used to manage a large number of FAP560, including configuration, fault management, diagnosis, monitoring and software upgrades. Access to AMS functions is provided via GANC SeGW 520 through a secure interface.
Some embodiments of the above-mentioned equipment, such as user equipment, FAP or GANC, include electronic components, such as a microprocessor and memory (not shown), and store computer program instructions in a machine-readable or computer-readable medium (such as for executing Wireless protocols to manage voice and data services instructions), which will be further described in the section on computer systems noted below. Examples of machine-readable media or computer-readable media include, but are not limited to, magnetic media such as hard disks, storage modules, magnetic tapes, optical media such as CD-ROMs and holographic devices, magneto-optical media such as optical disks, and special integrations such as Circuits (ASIC), programmable logic devices (PLD), ROM and RAM devices are specifically configured to store and execute program codes as hardware devices. Examples of computer programs or computer codes include machine codes such as those generated by a compiler and those generated by computers, electronic components, or micro-processing
200780043341.5 The first device uses annotators to execute high-level code files.
III. FEMTO cell protocol structure
A. CS Domain-Control Plane Structure FIG. 8 shows a GAN Femto cell structure supporting the CS domain control plane in some embodiments. The figure shows the different protocol layers used for UE805. FAP810. Universal IP network 815, SeGW820, INC 825 and MSC 830. Figure 8 also shows three interfaces-Uu840, Up 845 and Iu-cs 850ο
1. The Up interface used for the CS domain control plane The main features of the Up interface 845 used for the CS domain control plane are as follows. The underlying access layer (underlying Access Layer) 846 and the transport IP layer 848 provide a common connection between FAP 810 and GANC (which includes SeGW 820 and INC 825). The IPSec Encapsulating Security Payload (ESP) layer 850 provides encryption and data integration.
TCP 852 provides GA-RC 854 with reliable transmission between FAP 810 and GANC, and uses remote IP layer 856 for transmission. GA-RC 854 manages IP connections, including Femto cell registration processing.
The GA-CSR 858 protocol performs functions equivalent to the UTRAN RRC protocol and uses the underlying connection managed by GA-RC 854. Protocols such as MM 860 and above are carried transparently between UE 805 and MSC 830. GANC uses the messaging of the Radio Access Network Application Part (RANAP) 862 to terminate the GA-CSR 858 protocol and interact with the Iu-cs 850 interface.
The remote IP layer 856 is the IP layer of the IPSec tunnel mode, and is used by the FAP810 for addressing through INC 825. During the establishment of the IPSec connection, the remote IP layer 856 is configured. In some embodiments, the Iu-cs signaling transmission layer 870 is based on the UTRAN Iu interface signaling transmission, 3GPP TS 25.412 standard, hereinafter referred to as Ding S 25.412.
B. CS Domain-User Plane Structure FIG. 9 shows the GAN Femto cell protocol structure supporting the CS domain user plane in some embodiments. The figure shows different protocol layers for UE 905, FAP 910, general IP network 915, SeGW 920, media GW 925 and MSC 930. Figure 9 also shows three interfaces-Uu935, Up 940 and Iu-cs 945.
The main features of the CS domain user plane are as follows. The bottom access layer 950 and the transport IP layer 952 provide a universal connection between the FAP 910 and the GANC. The IPSec layer 954 provides encryption and data integration.
FAP 910 converts CS user data 956 (received through the air interface) into RFC 3267
200780043341.5 The defined frame. The RFC 3267 user data 958 is transmitted to the GANC media GW 925 on the Up interface. The GANC media GW 925 will provide an interaction function 960 with Iu-UP (for example, Support Mode) leading to the CN. In some embodiments, Iu-UP uses ATM as a transmission mechanism between CN and GANC media GW 925. In some embodiments, Iu-Up uses IP as the transmission mechanism between CN and GANC media GW925. In some embodiments, the CS domain user plane structure supports the AMR codec, as specified in the following: AMR speech codec; General description, 3GPP TS 26.071 standard, optionally supporting other codecs. In some embodiments, the Iu-cs data transmission layer 970 is based on TS 25.414.
C. PS Domain-Control Plane Structure FIG. 10 shows a GAN Femto cell structure supporting PS domain control plane in some embodiments. The figure shows the different protocol layers used for UE 1005, FAP 1010, general IP network 1015, SeGW 1020, INC 1025, and SGSN 1030. Figure 10 also shows three interfaces-Uul040, Up 1045 and Iu-psl050o. The main features of the Up interface 1045 for the PS domain control plane are as follows. The bottom access layer 1052 and the transport IP layer 1054 provide a common connection between FAP1010 and GANC. The IPSec layer 1056 provides encryption and data integration.
TCP 1058 provides reliable transmission of GA-PSR 1060 signaling messages between FAP 1010 and GANC. GA-RC 1062 manages IP connections, including Femto cell registration processing. The GA-PSR 1060 protocol performs functions equivalent to the UTRAN RRC protocol.
Upper layer protocols 1064 such as those used for GMM, SM, and SMS are transparently transported between UE 1005 and CN. GANC terminates the GA-PSR 1060 protocol and uses RANAP 1070 to interact with the Iu-ps interface 1050. In some embodiments, the Iu-ps signaling transport layer 1080 is in accordance with TS 25.412.
D. PS Domain-User Plane Structure FIG. 11 shows a GAN Femto cell structure for the PS domain user plane of some embodiments. The figure shows the different protocol layers used for UE1105, FAP1110. General IP network 1115, SeGW1120, packet gateway (packet GW) 1125 and SGSN1130. Figure 11 also shows three interfaces-Uu 1135, Up 1140 and Iu-ps 1145.
The main features of the Up interface 1140 for the PS domain user plane are as follows. The bottom access layer 1150 and the transport IP layer 1155 provide a universal connection between FAP 1110 and GANC. The IPSec layer 1160 provides encryption and data integration. The GTP-U 1170 protocol works between FAP 1110 and SGSN 1130
200780043341.5 The first work is to transmit the upper layer payload (ie, user plane data) via Up 1140 and Iu-ps interface 1145.
The packet GW1125 provides an ATM GW function for ATM transmission or an IPGW function for IP transmission. In some embodiments, the functionality of the packet GW1125 is incorporated into the SeGW1120. In addition, in some embodiments, the packet GW also provides a GTP-U proxy function, where the GTP-U can optionally terminate on either side of the packet GW 1125. In an embodiment in which the packet GW 1125 provides the ATM GW function, the packet GW 1125 provides transport layer conversion between IP (to FAP 1110) and ATM (to CN). The user data 1180 is transparently transported between the UE 1105 and the CN. In some embodiments, the Iu-ps data transmission layer 1180 is in accordance with TS 25.414.
E. Alternative Embodiments In some embodiments, independent CSR and PSR protocols are not used for the communication between FAP and GANC. As described in this article, a single protocol is used, that is, universal access Radio Resource Control (GA-RRC)» In these embodiments, the GA-CSR 858 (shown in Figure 8) and GA-PSR 1060 (shown in Figure 10) protocol layers are replaced with one protocol layer GA- The details of the RRCo GA-RRC protocol structure and messaging are further described in the following patent application: US Patent Application 11/778,040> titled Generic Access to the Iu Interface, filed on July 14, 2007. This application is incorporated herein by reference. Those skilled in the art will be able to apply the disclosure of the GA-CSR and GA-PSR protocols in this application to the GA-RRC protocol.
IV. Resource Management
A. GA-RC (General Access Resource Control)
The GA-RC agreement provides a resource management layer with the following functions. (1) Discover and register to GANC, (2) Register updates to GANC, (3) Keep-alive at the application level (keep-alive), and (4) Support FAP used for Femto cell access Recognition.
1. State of the GA-RC sublayer FIG. 12 shows different states of the GA-RC sublayer in the FAP in some embodiments. As shown in the figure, the GA-RC sublayer in FAP can be in one of the following two states: GA-RC-registered 1205 or GA-RC-registered 1210.
FAP creates and maintains an independent GA-RC sub-layer status for each device it registers. For example, if FAP registers three UEs, FAP creates and maintains three independent GA-RC sublayers for these three UEs. Likewise, FAP supports registration of two types of devices, namely, FAP and UE. Based on the type of device, the function of the GA-RC sub-layer can be changed.
200780043341.5 a) GA-RC sublayer with device type FAP For FAP device types, when the FAP is powered on, the GA-RC sublayer is in the GA-RC-deregistration state 1205» In this state, the FAP is not successfully registered to the GANC . When in the GA-RC-deregistration state 1205, the FAP can start the registration process. In the case of losing the TCP or IPSec connection or executing the deregistration process, the FAP returns to the GA-RC-deregistration state 1205. When transitioning to the GA-RC-deregistration state 1205, the FAP must trigger the implicit deregistration of all UEs currently camping on the FAP.
In GA-RC-registered state 1210, FAP is registered to the service GANC (Serving GANC). The FAP has an established IPSec tunnel and TCP connection to the service GANC. Through the IPSec tunnel and TCP connection, the FAP can exchange GA-RC, GA-CSR, and GA-PSR signaling messages with the GANC. When the FAP remains in the GA-RC-registered state 1210, it performs application-level maintenance and GANC continues to function.
b) The GA-RC sublayer with the device type of UE. For the UE device type, when the UE roams in and establishes a subsequent TCP connection between FAP and GANC, the GA-RC (for each UE) in the FAP The sub-layer is in the GA-RC deregistration state 1205. In this state, the UE has not successfully registered with the GANC (by FAP). When the UE-specific GA-RC sublayer is in the GA-RC-deregistration state 1205, the FAP can start the registration process. In the case of losing the TCP or IPSec connection or executing the deregistration process, the GA-RC sublayer returns to the GA-RC-deregistration state 1205. When the TCP connection is lost, the FAP can try to re-establish the corresponding TCP session and perform synchronization processing. A failure in successfully re-establishing the TCP session will cause a transition to the GA-RC-deregistration state 1205 in the GA-RC layer. If the corresponding GA-RC sublayer for the FAP is in the GA-RC-deregistered state 1205, the GA-RC sublayer for the UE can also be converted to the GA-RC-deregistered state 1205.
In the GA-RC-registered state 1210, the UE has successfully registered (by the FAP) to the serving GANC. FAP has an established shared IPSec tunnel and a new TCP connection to the service GANC. Through the IPSec tunnel and the new TCP connection, FAP can exchange GA-RC.GA-CSR and GA-PSR signaling messages with GANC (for Each registered UE). For each UE device type, regarding the corresponding TCP session, FAP will perform application-level retention and GANC will continue to function.
In the GA-RC-registered state, the UE camps on the Femto cell. The UE may be idle or active in the Femto cell (for example, the RRC connection may have been established). In some embodiments, an idle UE is a UE that is not currently engaged in voice or data communication.
200780043341.5 No.
B. GA-CSR (Common Access Circuit Switching Resources)
The GA-CSR protocol provides a circuit-switched service resource management layer, which supports the following functions: (1) Establish a transmission channel for CS services between FAP and GANC, (2) In UE (or FAP, if FAP supports local services ) And the core network directly transfer NAS messages, and, (3) other functions such as CS paging and security configuration.
1. State of the GA-CSR sublayer FIG. 13 shows a state diagram of the GA-CSR in the FAP for each UE in some embodiments. As shown in the figure, the GA-CSR sublayer (for each UE) in the FAP can be in two states: GA-CSR-idle 1305 or GA-CSR-connected 1310.
When each UE roams into the coverage of the FAP and the FAP successfully registers the UE to the serving GANC, the GA-CSR state of the UE enters the GA-CSR-idle state 1305. This switching occurs only when the GA-RC state of the UE is in the GA-RC-registered state 1210.
When the GA-CSR connection is established, the UE GA-CSR changes from the GA-CSR-idle state 1305 to the GA-CSR-connected state 1310, and returns to the GA-CSR idle state 1305 when the GA-CSR connection is released. When the GA-CSR connection is released, an indication that there is no dedicated CS resource is passed to the upper layer.
The GA-CSR connection for each UE is typically established by the FAP when the upper layer message (NAS layer) of a specific UE needs to be exchanged with the network. GA-CSR connection release can be triggered by GANC or FAP. If FAP supports the local service (terminal adapter function) using FAP SIM, FAP will have a similar GA-CSR status.
C. GA-PSR (General Access Packet Switching Resource)
The GA-PSR protocol provides a packet switching service resource management layer, which supports the following functions: (1) Establish a transmission channel for PS services between the FAP (for each UE) and the network, (2) between the UE and the PS core Directly transfer NAS messages between networks, (3) transfer GPRS user plane data, and (4) other functions such as PS paging and security configuration.
1. State of GA-PSR sublayer FIG. 14 shows a state diagram of GA-PSR in FAP for each UE in some embodiments. As shown in the figure, the GA-PSR sublayer for each UE can be in two states: GA-PSR-idle 1405 or GA-PSR-connected 1410 »When each UE roams within the coverage of FAP and FAP When the UE is successfully registered to the serving GANC, the GA-PSR state of the UE enters the GA-PSR-idle state 1405. The switch is only
200780043341.5 The first GA-RC status of the UE occurs when the GA-RC-registered status is 1210.
When the GA-PSR connection is established, the UE GA-PSR changes from the GA-PSR-idle state to the GA-PSR-connected state 1410, and returns to the GA-PSR idle state 1405 when the GA-PSR connection is released. When the GA-PSR connection is released, an indication that there is no dedicated PS resource is passed to the upper layer. The GA-PSR connection for each UE is typically established by the FAP when the upper layer message (NAS layer) of a specific UE needs to be exchanged with the network. GA-PSR connection release can be triggered by GANC or FAP.
The GA-PSR transmission channel (GA-PSR TC) provides the connection between FAP (for each UE) and GANC for transmitting PS user data on the Up interface. This will be further described in the section GA-PSR Transmission Channel Management Steps below. If FAP supports the local service (terminal adapter function) using FAPSIM, there will be similar GA-PSR status and
GA-PSR TC.
D. GA-CSR and GA-PSR connection processing
GA-CSR and GA-PSR connections are logical connections between FAP and GANC used in the CS domain and PS domain, respectively. When the upper layer in the FAP requests the establishment of a CS (or PS) domain signaling connection and the corresponding GA-CSR (or GA-PSR) is in the GA-CSR-idle (or GA-PSR-idle) state, that is, in the FAP and When there is no GA-CSR (or GA-PSR) connection for a specific UE between GANC, a GA-CSR (or GA-PSR) connection is established. In some embodiments, when the FAP receives a corresponding higher layer (ie, NAS layer) message for a specific UE through the air interface (ie, through an RRC connection), the upper layer in the FAP requests the establishment of a GA-CSR ( Or GA-PSR) connection. In some embodiments, a single RRC connection is used between the UE and the FAP for the CS and PS domains.
When a successful response is received from the network, GA-CSR (or GA-PSR) responds to the upper layer, indicating that CS (or PS) domain signaling has been established and entered the corresponding connected mode (ie, GA-CSR-connected or GA -PSR-Connected state). The upper layer may request to transmit a NAS message for CS (or PS) service to the network through the corresponding GA-CSR (or GA-PSR) connection.
1. FAP-initiated GA-CSR connection establishment FIG. 15 illustrates the successful establishment of a GA-CSR connection when initiated by FAP 1505 in some embodiments. As shown in the figure, FAP 1505 initiates GA-CSR connection establishment by sending a GA-CSR request message to INC 1510 (in step 1). The message includes the establishment cause (Establishment Cause) to indicate the reason for establishing the GA-CSR connection.
200780043341.5 No.
INC 1510 sends a successful response to FAP 1505 by sending GA-CSR request acceptance (in step 2), and FAP 1505 enters the GA-CSR-connected state. Alternatively, INC 1510 may return the GA-CSR request rejection (in step 3) to indicate the reason for the rejection. As shown in the figure, the MSC 1515 does not play a role in the establishment of the GA-CSR connection initiated by the FAP.
2. GA-CSR Connection Release Figure 16 shows the release of the logical GA-CSR connection between FAP 1605 and INC 1610 in some embodiments. As shown in the figure, the MSC 1615 instructs the INC 1610 (in step 1) to release the CS resources (both control and user plane resources) allocated to the FAP 1605 via the Iu release command message. INC 1610 uses the Iu release complete message to confirm (at step 2) the resource release to MSC 1615.
INC 1610 uses the GA-CSR release message command (in step 3). FAP 1605 releases the resources used for the specific UE connection. FAP 1605 uses the GA-CSR release complete message to confirm (in step 4) the resource release to INC 1610, and the GA-CSR status in FAP 1605 becomes GA-CSR idle.
3. FAP initiated GA-PSR connection establishment FIG. 17 illustrates the successful establishment of a GA-PSR connection when initiated by FAP 1705 in some embodiments. As shown in the figure, FAP 1705 initiates GA-PSR connection establishment by sending (in step 1) a GA-PSR request message to INC 1710. The message includes the establishment reason to indicate the reason for establishing the GA-PSR connection.
INC 1710 sends a successful response to FAP 1705 by sending GA-PSR request acceptance, and FAP 1705 enters the GA-PSR-connected state. Alternatively, INC 1710 may return (in step 3) the GA-PSR request rejection to indicate the reason for the rejection. As shown in the figure, SGSN1715 does not play a role in the establishment of the GA-CSR connection initiated by the FAP.
4. GA-PSR Connection Release Figure 18 shows the release of the logical GA-PSR connection between FAP 1805 and GANC in some embodiments. As shown in the figure, the SGSN 1815 instructs the INC 1810 (in step 1) to release the PS resources (both control and user plane resources) allocated to the FAP via the Iu release command message.
INC 1810 uses the Iu release complete message to confirm (in step 2) the resource release to SGSN 1815. INC 1810 uses the GA-PSR release message command (in step 3) FAP 1805 releases the resources used for specific UE connections °FAP 1805 uses the GA-PSR release complete message to confirm (in step 4) the resource release to the GANC, and the FAP 1805 The GA-PSR status changes to GA-PSR-idle.
200780043341.5 No.
V mobility management
A. UE Addressing When the FAP registers a specific UE trying to occupy the FAP, the FAP provides the IMSI related to the SIM or USIM in the UE to the INC. INC keeps a record of each registered UE. For example, when INC receives a RANAP paging message, INC uses IMSI to find the appropriate UE record.
B. Femto cell addressing When the FAP registers, the FAP provides the IMSI related to the SIM or USIM in the FAP to the INC. INC keeps a record of each registered FAP.
When the FAP establishes an IPSec tunnel to the GANC security gateway, the public IP address of the FAP is used by the FAP. The identifier is provided by the GANC security gateway to the AAA server. In some embodiments, the identifier is used by the GANC network system to support location services (including E911) and fraud detection. In some embodiments, the identifier is used by the service provider to support the QoS of IP flows in the managed IP network.
The FAP's private IP address (also known as the remote IP address) is used by the FAP in the IPSec tunnel. When the FAP registers the Femto cell service, the identifier is provided by the INC to the AAA server via the S1 interface. This identifier can be used by the Femto cell network system in the future to support location services (including E911) and fraud detection.
In some embodiments, the access point, ID (AP-ID) is the MAC address of the Femto cell access point, through which the UE is accessing the Femto cell service. When the FAP registers for the Femto cell service, the identifier is provided by the FAP to the INC via the Up interface, and is provided by the INC to the AAA server via the S1 interface. AP-ID can be used by Femto cell network systems to support location services (including E911, described in the location-based routing section below), and can also be used by service providers to restrict Femto cells to only authorized FAPs Service access (described in the Femto cell service access control section below) »
C. Femto cell identification The following points describe the Femto cell identification strategy.
1. Identification of location area, routing area, and service area In order to promote the mobility management function in UMTS, the coverage is divided into logical registration areas called location area (used in CS domain) and routing area (used in PS domain). The UE needs to register to the network every time the service location area (or routing area) changes. One or more location area identification codes (LAI) can be associated with each MSC/VLR in the carrier network. Similarly, a single SGSN can be used to control
200780043341.5 The first one or more routing area identifiers (RAI).
In particular, when the UE is in idle mode and the UE does not have any active RRC connection, LA and RA are used. When the active wireless connection is not available, the CN will use the last known LA (for the CS domain) and RA (for the PS domain) for paging the mobile station.
The Service Area Identifier (SAI) identifies an area composed of one or more cells belonging to the same location area. SAI is a subset of the location area and can be used to indicate the location of the UE to the CN. SAI can also be used for emergency call routing and billing purposes.
The service area code (SAC) is 16 bits in some embodiments, and together with the PLMN-Id and the location area code (LAC) constitute the service area identifier.
SAI = PLMN-Id || LAC || SAC In some embodiments, it is necessary to assign a unique LAI to each FAP in order to detect the movement of the UE from the macro network to the FAP or from one FAP to another FAP. When the UE moves from the macro network to the FAP, the UE can camp on the FAP via its internal cell selection logic. However, if the UE is in idle mode, no messages will be exchanged between the UE and the FAP, so it is difficult for the FAP to detect the presence of the UE. In order to trigger the initial message from the UE, when the UE camps on a specific FAP, the FAP will need to be assigned a unique location area, which is different from the adjacent macro cell. This will cause the MM layer of the UE to trigger a location update message sent to the CN via the pre-occupied cell, that is, the FAP.
The movement of the UE from one FAP to another FAP must also be detected. The UE's cell selection can select a neighboring FAP, and it will camp on the neighboring FAP without any obvious messaging. But if there is no obvious messaging started, the service access control (SAC) of the neighboring FAP may not allow the specific UE to preempt, and the neighboring FAP will not be able to detect and subsequently reject the UE. Assuming LAI for each operator If the MCC and MNC components of the FAP remain fixed, the uniqueness of the LAI can be ensured by assigning a unique LAC to each FAP, so that the LAC assigned to the FAP is different from the neighboring macro network cell and other neighboring FAPs.
However, the LAC space is limited, the maximum is 64K (due to the limitation of the 16-bit LAC attribute specified in numbering, addressing and identification), 3GPP TS 23.003, hereinafter referred to as TS23.003". Therefore, the LAC allocation plan must be provided The mechanism for reusing LAC for scalable solutions, while minimizing the operational conflicts of existing CN components (MSC/SGSN).
In some embodiments, the following solutions are used to meet the above requirements. LAC allocation is divided into two independent categories: (1) LAC pool managed by FAP/AMS, and (2) managed by INC
200780043341.5 The LAC of the first group (one for each Iu interface).
FAP/AMS uses the first group of LACs to allocate a unique LAC to each FAP, so that the allocation result (at least) meets the following requirements: (1) The uniqueness of neighboring macro cells and other FAPs (this will ensure that it is from the UE The initial message is used for Femto cell selection and roaming into the coverage area), and (2) to resolve conflicts between shared LACs, where multiple FAPs sharing the same LAC are not adjacent but are accessed by the same UE (this will allow Use the rejection code where LA is not allowed for UE rejection).
The second group of LAC (a much smaller group) is managed within each INC as follows, with the following key requirements: (1) minimize the conflicts of existing CN components (such as minimum configuration and operation conflicts), (2) The existing functions for the routing of emergency calls are seamlessly integrated into the appropriate PSAP, and (3) the existing functions for generating the appropriate call detail record (CDR) for billing purposes are seamlessly integrated.
In order to meet the above requirements for the second group of LACs, each INC represents the super LA (SuperLA) used for a given Iu interface (ie, MSC + SGSN interface)." This implies that the MSC/SGSN can configure a single for the INC. It should be noted that this does not limit the operator to configure multiple super LAI/super RAI if necessary (for example, in order to further subdivide the area served by a single INC into multiple geographic areas).
In addition, INC should use the following mapping functions to allocate super LA: (1) When reporting macro coverage by FAP, INC should support the mapping of the reported macro coverage to Super LAC, Super RAC, and Service Area Code (SAC). The number of SACs used will depend on the interval size of the regional distribution selected by the operator (for example, for emergency call routing, billing, etc.), and (2) When the FAP report has no macro coverage, INC should have the following Super LAC/RAC/SAC distribution logic: (a) Via S1 interface, for a given FAPIMSI, query AAA for information about the supplied macro coverage. If S1 reports macro coverage (based on the information stored in the user DB), INC uses S1 macro information to map Super LAC/RAC/SAC as described above, and (b) if there is no information about macro coverage according to S1 query, INC Map FAP to the default super LAC/RAC/SAC;
(This may cause INC to route business to CN under a sub-optimal mechanism)<sub>O</sub>In order to prevent the sub-optimal route from routing UE traffic to the default MSC/SGSN, the following additional enhancements can be applied to the FAP: (i) When the UE roams into the uncovered FAP, the FAP can request an initial location update (LU) from the UE Collect information (because the UE will report the LAI that it has recently reserved), (ii) FAP can collect information from multiple UEs and construct the exported macro coverage information (the number of UEs used for the exported macro coverage can be related to the algorithm), (Iii) Using the exported macro coverage information, FAP will send GA-RC registration
200780043341.5 Update the uplink message to INC, and (iv) INC will use the macro coverage information reported by the GA-RC registration update uplink message, and map the FAP to the appropriate super LAC/RAC/SAC as described above »The unique LAI of each FAP also implies a unique RAI, because RAI is composed of LAI and routing area code (RAC). After the FAP is successfully registered, the LAI and RAI are sent to the FAP via the "System Information" attribute. On the other hand, the SAI is relayed to the CN in the initial UE message (used to deliver the initial L3 message from the UE to the CN).
FAP is expected to provide super LAC/RAC replacement (for example, LU acceptance or RAU acceptance) from the network to the UE in the NAS message. The FAP must replace the super LAC/RAC included in the related NAS message from the network with the appropriate logically allocated LAC/RAC information sent to the message of the UE camping on the FAP.
2. 3G cell identification
The 3G cell Id identifies a cell that is clearly in the PLMN. The 3G cell identifier consists of the following parts.
3G Cell Id = RNC-Id (12 bits) + Cell Id (16 bits) In some embodiments, the RNC-Id is 12 bits and the cell Id is 16 bits, so that the 3G cell Id is a 28-bit value. The 3G cell Id in UMTS is managed in UTRAN and is not exposed to the CN. Therefore, the cell allocation logic can be limited to UTRAN, as long as it can ensure uniqueness within a given PLMN.
Initially, the 3G cell Id assigned to each FAP must be different from its neighboring Femto cell, so as to avoid the system information broadcasts sent by two neighboring FAPs from including the announcement of the same area Id (advertisement), taking into account the FAP's The physical deployment is ad-hoc rather than the actual situation controlled by the operator. In some embodiments, each INC will be statically supplied with a unique RNC-Id, and the RNC-id will be passed to the FAP via system information during registration. FAP will be responsible for the local allocation of 16-bit cell Id, and use the combination of the RNC-id provided by INC and the locally allocated cell Id to construct a 3G cell.
D. Femto cell operation configuration There are two possible Femto cell operation configurations: common core configuration and independent core configuration. In the common core configuration, the Femto cell LAI and the umbrella UTRAN (Umbrella UTRAN) (for example, the UTRAN serving the user's neighbor) have different LAIs, and the network is designed so that the same core network entity (ie, MSC and SGSN) both serve the Femto cell and serve
200780043341.5 The first umbrella-shaped UMTS cell.
The main advantage of this configuration is that user movement between the Femto cell coverage area and the UMTS coverage area will not cause inter-system (ie, MAP) signaling (for example, location update and handover are in the MSC). The main advantage of this configuration is that it requires the coordination of Femto cell and UMTS service engineering design (tra Wuc engineering); for example, for the purpose of MSC & SGSN capacity planning.
In a separate core configuration, the Femto cell LAI and the umbrella UTRAN LAI are different, and the network is designed so that different core network entities serve the Femto cell and the umbrella UMTS cell.
The advantage of this configuration is that the engineering design of the Femo cell and the UMTS network can be more independent than the common core configuration. The disadvantage of this configuration is that user movement between the Femto cell coverage area and the UMTS coverage area will cause inter-system (ie, MAP) signaling.
E. Femto community registration
The Femto cell registration process does not involve any signaling sent to the PLMN infrastructure, and is included in the Femto cell system as a whole (ie, between FAP, INC, and AAA). There are two types of Femto cell registration: FAP registration and UE registration.
In FAP registration, FAP registers with INC when power is on. FAP registration serves the following purposes: (1) It informs INC that FAP is currently connected and available at a specific IP address. In some embodiments, the FAP creates a TCP connection to the INC before registration. A TCP connection is identified using one or more of the following information: source IP address, destination IP address, source TCP port, destination TCP port. INC can extract the FAP IP address from the TCP connection, (2) it provides the FAP with the operating parameters associated with the Femto cell service at the current location (such as LAL·Cell Id, etc.). During the registration process, the system information content applicable to the GANFemto cell service is delivered to the FAP as part of the GA-RC registration acceptance message sent from the INC to the FAP. FAP uses this information to transmit system parameters to the UE through the broadcast control channel, and (3) it enables the Femto cell system to provide service access control (CSAC) and charging functions (for example, AP restriction and redirection). In some embodiments, SAC and charging are done through the S1 interface.
In UE registration, after Femto cell selection and cell reservation, the UE initiates an LU message to the CN via FAP. The FAP uses this message to detect the presence of the UE on the specific FAP. Then, the FAP initiates a registration message to the INC for the reserved UE. The UE registration performed by the FAP serves the following purposes: (1) It informs the INC that the UE is currently connected through a specific FAP and is available at a specific IP address. INC (for example) for the purpose of terminating the call to the mobile station, this information is kept
200780043341.5 No. Tracking, and (2) It enables INC to provide SAC functions (for example, using S1 interface, if a specific UE should be allowed to receive Femto cell services from a specific FAP, then approve).
F. Mobility Management Scenarios The following scenarios show the message flows involved in various mobility management scenarios via the Femto cell system.
1. FAP is powered on. In some embodiments, the FAP is initially supplied with information about the supply INC (ie, IP address or FQDN), and the corresponding supply SeGW related to the INC. The information can take the format of FQDN, or the format of IP address, or any combination of the two. In the case that the FAP is not supplied with information about the provision of SeGW, the FAP can derive the FQDN of the provisioning SeGW from the IMSI (as described in TS 23.003). If the FAP does not have any information about the default INC or the service INC and the stored associated SeGW, the FAP completes the discovery process (Discovery procedure) to the supply INC via the associated SeGW. If the FAP has stored information about the default/monthly service INC that it successfully registered last time, the FAP skips the discovery process and attempts to register to the default/service INC, as described below.
a) FAP Discovery Process FIG. 19 shows a situation when the FAP 1905 is powered on and no information about the default/service INC is stored, and then the provisioning GANC 1910 is used to perform the discovery process in some embodiments. The supply of GANC 1910 includes the supply of INC 1915, DNS 1920 and SeGW 1925.
As shown in the figure, if FAP 1905 has the supplied FQDN or derived FQDN that supplies SeGW (as described in the FAP power-on section above), FAP 1905 (via the universal IP access network interface) performs a DNS query (in step 1) to resolve FQDN to IP address. If the FAP 1905 has an IP address for provisioning SeGW 1925, the steps of DNS (steps 1 and 2) are omitted. In some embodiments, DNS server 1935 is a public DNS server accessible from FAP. The DNS server 1935 returns (at step 2) a response including the IP address of the SeGW 1925 that is provided.
Next, the FAP 1905 establishes a secure tunnel (for example, an IPSec tunnel) to the provisioning SeGW 1925 (in step 3). If FAP 1905 has a supplied or derived FQDN that supplies INC 1915, FAP 1905 (via a secure tunnel) performs (at step 4) a DNS query to resolve the FQDN to an IP address. If the FAP has an IP address for supplying INC 1915, omit the steps of DNS (steps 4 and 5). The DNS server 1920 that supplies the GANC 1910 returns
200780043341.5 Section includes the response to supply the IP address of INC 1915 (in step 5).
Next, FAP 1905 establishes a TCP connection to a well-defined port on the supply INC. Then, it uses the GA-RC discovery request to query the default INC supply INC 1915 (in step 6). The message includes: (1) Cell information: If FAP detects macro network coverage, FAP provides the detected UTRAN cell ID and UTRAN LAI (for GSM, FAP provides GSM cell identification and GSM LAI λ If FAP does not detect macro network coverage, FAP provides the last LAI successfully registered by the FAP, and an indicator that identifies the last GERAN/UTRAN cell (for example, by including GERAN/UTRAN coverage indication Character information element (IE), which identifies the cell coverage of GERAN or UTRAN). The cell information is information of a neighboring macro cell, and the neighboring macro cell can be a GSM cell or a UTRAN cell. There are many ways for FAP to obtain information about neighboring cells. For example, it uses pre-configuration of FAP, obtains macro neighboring cell configuration via AMS, or makes FAP perform wireless scanning of neighboring cells. If the macro coverage is GSM, for the scanning scheme, the FAP must have the ability and mechanism to scan GSM cells, (2) FAP identity: IMSI, and (3) FAP physical MAC address: AP-ID. Optionally, if INC 1915 has been configured for service access control (SAC) through the S1 interface, INC 1915 will use the information provided in the GA-RC discovery request to authorize FAP 1905 via the AAA server 1930 (step 6a-6c).
The supply INC 1915 uses the information provided by the FAP (for example, cell ID) and returns the GA-RC discovery acceptance message (in step 7) to provide the FQDN or IP address of the default INC and its associated default SeGW. This makes FAP 1905 be directed to the local default INC in HPLMN to optimize network performance. The discovery acceptance message also indicates whether the provided INC and SeGW addresses should be stored by the FAP 1905.
If the provisioning INC 1915 cannot accept the GA-RC discovery request message, it returns a GA-RC discovery rejection message (in step 8), indicating the reason for the rejection. The secure IPSec tunnel to the supply SeGW is released (step 9).
You can also reuse the same IPSec tunnel for FAP registration processing. This situation is: the result of the discovery process makes the FAP successfully discover the default INC and the default SeGW. If the default SeGW is the same as the SeGW used by discovery (that is, SeGW is supplied), the same IPSEC tunnel can be reused. In this case, the IPSec tunnel is not released.
b) FAP registration process After the discovery process, FAP uses the default provided by the supplier GANC in the discovery process
200780043341.5 No.
GANC's security gateway establishes a secure tunnel and tries to register to the default GANC. Figure 20 illustrates the FAP power-on registration process of some embodiments. The default GANC can become the connected service GANC by accepting registration, or the default GANC can make FAP point to a different service GANC. The GANC can be redirected based on information provided by the FAP during the registration process, operator-selected policies, or network load balancing.
As shown in Figure 20, if FAP 2005 is only provided with the default or serving FQDN of SeGW 2015, FAP2005 (via the universal IP access network interface) performs a DNS query (in step 1) to resolve the FQDN into an IP address. If FAP 2005 is supplied with an IP address for SeGW, omit each DNS step (steps 1 and 2). The DNS server 2010 returns a response including the IP address of the default service SeGW 2015 (at step 2).
Next, FAP 2005 establishes a secure IPSec tunnel to SeGW 2015 (in step 3). If you reuse an IPSec tunnel from an earlier discovery or registration, you can omit this step. If FAP 2005 is provided with a default or serving INC FQDN, the FAP (via the secure tunnel) performs a DNS query (in step 4) to resolve the FQDN into an IP address. If FAP 2005 has an IP address for INC, omit the DNS steps (steps 4 and 5). The DNS server 2020 returns a response including the IP address of the default/service INC 2025 (at step 5).
Then, FAP establishes a TCP connection to INC 2025. The TCP port can be well-known, or it can be received from the network earlier during discovery or registration. FAP attempts to register (in step 6) INC2025 by transmitting a GA-RC registration request. In some embodiments, the message includes one or more of the following information: registration type, cell information, neighboring FAP information, physical MAC address of the FAP, FAP identity, and location information.
The registration type indicates that the device being registered is a Femto cell AP. This is indicated using the GAN classification mark, IE (the definition of IE is described further below). The cell information is the neighboring UTRAN/GERAN cell ID obtained as a result of the system scanning of the neighboring information. FAP must determine (using scan results or pre-configuration), the single suitable macro cell information that will be sent during the registration process.
The neighboring FAP information is information about neighboring FAPs operating in the same PLMN and carrier frequency. This will help provide INC with information such as the LAI and cell id being used by neighboring FAPs. In some embodiments, neighbor FAP information will not be provided. The physical MAC address of the FAP is the AP-ID (in some embodiments, the AP-ID is the MAC address of the Ethernet port associated with the FAP). The FAP identity is the IMSI of the FAP» If GPS services are provided, location information is also supported.
200780043341.5 Optionally, if INC 2025 has been configured for service access control (SAC) through the S1 interface, GANC will use the information provided in the registration request to authorize FAP via the AAA server 2030 (steps 6a-6c) If INC 2025 accepts the registration attempt, it responds with GA-RC registration acceptance (in step 7). The message includes: (1) GAN Femto cell specific system information (for example) (i) location area identification, including mobile country code, mobile network code and location area code corresponding to the Femto cell, and (ii) 3G cell identity , Which identifies the cell in the location area corresponding to the Femto cell. The message also includes GAN Femto cell capability information, which is indicated by using the GAN control channel IE. In some embodiments, the GAN Femto cell capability information includes instructions on whether to allow early Classmark sending> GAN mode of operation, whether GPRS is available, and whether GAN supports dual transmission mode.
In the case that INC 2025 accepts the registration attempt, as long as the FAP is registered to the GANC, the TCP connection and the secure IPSec tunnel will not be released but will be maintained. INC does not provide FAP with operating parameters for radio management (such as carrier frequency, scrambling code, etc.). It is expected that FAP will obtain this information through AMS or other pre-provisioning mechanisms.
Alternatively, INC 2025 may deny the request. In this case, it responds with GA-RC registration rejection (in step 8), indicating the reason for the rejection. The TCP connection and the secure IPSec tunnel are released, and FAP2005 operates as defined in the exception section below. Alternatively, if GANC has to redirect FAP 2005 to (another) service GANC, it responds with a GA-RC registration redirect (in step 9), providing the target service INC and its associated SeGW FQDN Or IP address. In this case, the TCP connection is released (in step 10), and the secure IPSec tunnel is optionally released depending on whether the network indicates that the same IPSec tunnel can be reused in the next registration. The GA-RC registration redirect message includes a single serving SeGW and GANC address or a list of PLMN identities, associated serving SeGW and GANC addresses, and an indication about whether the GANC address can be stored in the FAP for future use.
c) Abnormal situation If the service INC rejects the registration request and does not provide a redirection to another service INC, FAP will retry to register with the default INC, including the reason for the failed registration attempt and the service on which the registration request failed to register INC and SeGW. FAP should also delete all stored information about the service GANC.
If the default INC rejects the registration request and cannot provide the re-assignment of the INC to the appropriate service
200780043341.5 First, FAP can retry the discovery process to the supply INC (including indicating the reason for the failed registration attempt and the default INC provided in the last discovery process). FAP should also delete all stored information about the default GANC. The possible reasons for registration rejection for FAP registration attempts are: network congestion, location not allowed, unknown geographic location, IMSI not allowed, AP not allowed, and unspecified.
2. FAP synchronization after TCP connection reestablishment initiated by FAP In some embodiments, after a TCP connection failure, when the FAP receives a TCP reset (TCP RST), the FAP uses GA-RC synchronization processing to try to reestablish the signaling connection. Figure 21 shows messages associated with synchronization initiated by the FAP in some embodiments.
a) FAP synchronization is initiated by the FAP. In some embodiments, after a TCP connection failure, when the FAP receives a TCP reset, the FAP attempts to rebuild the TCP connection once. After successfully re-establishing the TCP connection, FAP 2105 sends (in step 1) GA-RC synchronization information to GANC 2110 to synchronize the status information. When the FAP fails to successfully re-establish the TCP connection, the FAP releases the relevant local GA-CSR or GA-PSR resources, and continues to operate as described in the lower fault handling section below.
b) The GANC processes the FAP synchronization information message. When the GA-RC synchronization information message is received from the FAP, the GANC updates the FAP status information as specified in the request. GANC also verifies that the binding (IMSI, internal IP address) received in the GA-RC synchronization message is the same as that used by FAP as an identity to authenticate to GANC-SeGW.
3. System Selection In some embodiments, in a combined 3G network, both the standard UMTS RNS and UMA Femto cell network coexist in the same or different PLMN. Standard UMTS UEs utilize these two access options, no matter which one is better in a particular situation. In these embodiments, there is no need to change the PLMN selection process in the NAS layer (MM and above) in the UE, as described in the following standard: Non-Access-Stratum functions related to Mobile Station (MS) in idle mode , 3GPP TS 23.122» Similarly, in these embodiments, there is no need to change the standard cell selection mechanism, as described in the following standards: User Equipment (UE) procedures in idle mode and procedures for cell reselection in connected mode, 3GPP TS 25.304. The following paragraphs describe the necessary configuration and system behavior for roaming into Femto cell coverage and roaming out of macro network coverage.
200780043341.5 During service activation or provisioning update, the UMA Femto cell network provides FAP with radio parameters, such as working UARFCN and a list of primary scrambling codes for Femto cells. The provisioning parameters will also include a list of UARFCN/scrambling codes associated with neighboring macro cells.
Then, FAP uses the macro UARFCN information to perform a neighborhood scan to find the existence of macro coverage. If multiple macro network cells are detected in the FAP scan, FAP selects the most suitable macro cell to report the macro cell to the serving INC during FAP registration. FAP also stores a list of macro cells, which will be used as The neighbor list is provided to the UE that is camping on.
FAP also scans the neighborhood to find the existence of other FAPs in the same PLMN. Then it selects the unused {UARFCN, SC} pair from the list of available pairs that are supplied, so that the selected {UARFCN, SC} does not conflict with any adjacent FAP {UARFCN, SC} combination.
The FAP attempts to register with the service INC (obtained via the discovery/registration mechanism as described in the FAP discovery process and FAP registration process above), and includes information about the selected macro cell and a list of neighboring FAPs. The service INC uses the information provided during registration to assign network operation parameters, such as LAL·3G cell-id, service area, etc., to the FAP that is being registered.
The service INC uses the registration acceptance message to return network operation parameters to the FAP that is registering. FAP uses a combination of information obtained through initial provisioning and registration to broadcast appropriate system information to the UE so that it can select Femto cell services and preempt the FAPo list of {UARFCN, SC} associated with Femto cell neighbors to be provisioned To the macro network RNC. Since the Femto cell network must be able to adjust to millions of FAPs, and the deployment location cannot be controlled, the macro network RNC is supplied with a list of 5-10 {UARFCN, SC} combinations corresponding to neighboring FAPs. Due to the restrictions associated with the supply of neighbor list on the macro RNC, the FAP will need to select one of the 5-10 supplied {UARFC, SC} pairs for its operation, so that there are no two neighboring FAPs (via FAP). Scan OK) will reuse the same pair for its operation.
The macro RNC should provide the FAP neighbor list information to the UE that camps on the macro network and uses the specific RNC. This will allow the UE to periodically measure the FAP neighbor list.
When the UE comes to the coverage area of the FAP and its signal level becomes stronger, the UE will choose Femto cell. UE cell-reselection, that is, roaming into the FAP cell can be enhanced by two possible mechanisms: (1) The FAP cell can be in a different HPLMN (equivalent PLMN list) and will be selected by the preferred equivalent PLMN be chosen. This assumes that the macro cell currently camped by the UE is not in the equivalent PLMN list, and (2) FAP will broadcast system information (such as Qqualmin and
200780043341.5 No.
Qrxlevmin), so that in the presence of other macro cell coverage, the UE will prefer the FAP cell.
When the cell is reselected and the UE camps on the FAP cell, the UE will initiate location registration because the FAP LAI is different from the LAL of the previously camped macro cell
4. UE registration
When the UE camps on the FAP (through its internal cell selection mechanism), it will initiate the NAS layer location update process to the CN via the FAP (the LU is triggered because the FAP broadcasts a unique LAI, which is different from its neighboring macro cell and Other neighboring Femto districts). As shown in Figure 22, the FAP will intercept the location update message and try to register the UE to the INC. Those skilled in the art will understand that the UE always initiates location update processing to the core network, that is, the UE uses an upper protocol layer that directly exchanges with the core network. As described in this section and the following sections, the public FAP has the ability to intercept the message and try to register the UE to the INC.
As shown in the figure, the UE 2205 establishes (at step 1a) a radio resource control (RRC) connection with the FAP 2210 pre-occupied by the UE. The UE 2205 starts (at step lb) the location update process to the CN. In some embodiments, the network supports network mode 1. In this mode, there is a Gs interface between the MSC and the SGSG, and the UE triggers a combined routing area (RA)/location area (LA) update when roaming into the FAP Instead of the initial LA update<sub>o</sub>FAP2210 will intercept the location update request (or combined RA/LA update request), and try to register the UE to the associated service INC through the existing IPSec tunnel. Optionally, if the location update is completed using TMSI (in step Id), since the initial registration of the UE must use a permanent identity, that is, the IMSI of the UE to complete, the FAP can request (in step lc) the IMSL of the UE. Next, FAP2210 ( For each UE) Establish (in step 2) a separate TCP connection to the destination TCP port on INC2215. The INC destination TCP port is the same as the port used for FAP registration. FAP2210 attempts to use the UE dedicated TCP connection to register UE 2205 to INC 2215 by transmitting (in step 3) a GA-RC registration request. The message includes the registration type (it indicates that the device being registered is UE. This is indicated by using the GAN classification mark TE), general IP access network attachment point information (ie AP-ID), UE identity (ie UE- IMSI), and FAP identity (ie, FAP-IMSI). In some embodiments, the AP-ID is the MAC address of the FAP.
Optionally, if INC2215 has been configured for service access control (SAC) through the S1 interface, INC 2215 will use the information provided in the registration request via the AAA server
200780043341.5 No.
2220 authorizes the UE (steps 3a-3c). The authorization logic on the AAA server 2220 will also check to see whether the UE 2205 is allowed to use a specific FAP for Femto cell access.
If INC2215 accepts the registration attempt, it responds with GA-RC registration acceptance (in step 4). Next, FAP 2210 is established (connection with INC 2215's GA-CSR in step 5). FAP 2210 encapsulates the location update NAS PDU (in step 6) in the GA-CSR UL direct delivery message, which is forwarded to INC 2215 via the existing TCP connection.
Next, INC2215 establishes the SCCP connection to CN 2225, and uses RANAP initial UE message to forward the location update request (or combined RA/LA update request) NAS PDU to (in step 7) CN2225. The RANAP direct delivery message will be used to send subsequent NAS messages between UE2205 and core network 2225 between INC 2215 and CN 2225.
Next, CN 2225 uses standard UTRAN authentication processing to authenticate UE 2205 (at step 8). CN 2225 also initiates a security mode control process, which is further described in the security mode control subsection in the Femto cell security section below. CN 2225 uses the location update accept message to indicate to INC 2215 (at step 9) that it has received the location update and that it will accept the location update.
INC 2215 forwards the message to (at step 10) FAP 2210 in the GA-CSRDL direct delivery<sub>o</sub>FAP2210 will relay location update acceptance to UE2205 via the air interface (in step 11). Once the UE 2205 has successfully registered (via FAP) to INC 2215 and performed a successful location update, FAP 2210 will expect the periodic LU for the UE (the activation and periodicity of the LU is done by the FAP via the FAP from the FAP to the UE. System information broadcast to control). The exchange will be used as a keep-alive between the FAP 2210 and the UE 2205, and will help the FAP 2210 detect that the idle UE is removed from the pre-occupied FAP 2210, and does not mean disconnecting from the network.
a) Abnormal situation If the service INC rejects the UE-specific registration request, FAP will use the appropriate rejection mechanism (for example: RRC redirection to another cell, or reject the LU with the rejection reason location area is not allowed), and reject the UE The corresponding location update request. The FAP should disconnect the corresponding TCP session of the specific UE. Possible reasons for registration rejection for UE-specific registration attempts are (1) AP is not allowed (meaning that UE-specific registration is not allowed on FAP for UE), (2) IMSI is not allowed, (3) Location is not allowed It is allowed, (4) not specified, and (5) FAP is not registered.
5. The UE roaming out of Figure 23 shows the situation when the UE leaves the Femto cell coverage area when it is idle.
200780043341.5 The situation. As shown in the figure, when UE2305 succeeds in GAN registration and location update (LU), FAP2310 will monitor (in step 1) UE2305 via periodic location update. The activation and periodicity of the LU is controlled by the FAP2310 via the system information broadcast from the FAP to the UE. This exchange will be used as a keep-alive between FAP and UE.
Next, as a result of losing multiple periodic location updates from the UE, the FAP 2310 determines (at step 2) that the UE 2305 no longer camps on the FAP (roams out). Once the FAP determines that the UE has roamed out, the FAP sends (in step 3) a GA-RC deregistration message to INC 2315 by using the associated TCP connection to notify the GANC that the UE has been separated. Since the TCP connection from the FAP to the GANC is unique for each UE, sending the GA-RC deregistration message on the dedicated TCP connection means the deregistration of a specific UE. Next, upon receiving the deregistration message on the UE-specific TCP connection, the GANC removes (in step 4) any content associated with the UE. In some embodiments, the content associated with the UE includes the status and other information reserved by the GANC for each successfully registered UE. FAP 2310 also releases (in step 4) the UE-specific TCP connection to the INC.
6. UE power off in case of IMSI separation FIG. 24 shows a situation in some embodiments when the UE is powered off and IMSI separation is performed via the GAN network. As shown in the figure, UE2405 in idle mode initiates (in step 1) a power outage sequence. Next, UE2405 establishes (in step 2) an RRC connection with FAP2410. The UE sends (in step 3) the MM layer IMSI-separation message to the FAP through the air interface. FAP2410 establishes (in step 4) the GA-CSR connection with INC 2415.
FAP 2410 encapsulates the IMSI-separated NAS PDU in a GA-CSR UL direct delivery message, which is forwarded via the existing TCP connection to (in step 5) INC2415. INC 2415 establishes a SCCP connection to CN 2420 and uses RANAP to initiate The UE message forwards the IMSI-separated NAS PDU to (in step 6) CN 2420 «CN 2420 initiates (in step 7) normal resource cleaning to INC 2415 via the RANAPIu release command. The release of Iu from CN2420 causes INC 2415 to disconnect (at step 8) the corresponding GA-CSR connection.
Next, INC 2415 confirms to CN via the RANAPIu release completion message (in step 9) that the resource is cleared. FAP2410 uses the UE-specific TCP connection to deregister the UE (in step 10) In some embodiments, FAP uses the mechanism described in the UE roaming out section above to detect that the UE has roamed out and triggers the UE to deregister. As a kind of In a preferred manner, the FAP can also monitor the IMSI-detached NAS message from the UE and trigger the deregistration of the UE.
200780043341.5 Next, FAP2410 releases (at step 11) the UE-specific TCP connection. The FAP initiates (in step 12) the RRC connection release process to the UE. Finally, the UE is powered off (at step 13).
7. The UE power-off event sequence without IMSI separation is the same as the UE roaming out of the Femto cell described in the UE roaming out section above.
8. Loss of Up Interface Connectivity Figure 25 shows a situation where the Up interface connectivity is lost. As shown in the figure, UE2505 is in idle mode. FAP2510 periodically sends (in step 1) GA-RC keep-alive messages to INC2515 to check the existence of TCP connections. In step 2, TCP (or IP) connectivity between FAP 2510 and INC 2515 is lost (for example, due to broadband network issues).
If the INC detects (in step 3) loss of connectivity, it releases the resources allocated to the FAP (for example, TCP connection) and deletes the user record (ie, performs local deregistration of the FAP). Optionally, the execution of INC can also delete the UE-specific connection originated on the FAP.
If FAP 2510 detects (in step 4) the loss of TCP connectivity and if the loss is a FAP dedicated TCP connection, FAP 2510 tries (in step 5) to re-establish the TCP connection and re-register with INC. If the FAP re-establishes the connection and re-registers before the INC detects the problem, the INC must recognize that the FAP has been registered and make corresponding adjustments (for example, release the old TCP connection resources). In some embodiments, the FAP dedicated TCP is the only TCP connection dedicated to the FAP and is used for signaling to INC related to FAP IMSI, such as FAP registration and FAP calling when FAP uses FAP IMSI to provide local calls. Build etc.
For the FAP to detect the loss of the TCP connection, different embodiments use different methods. In some embodiments, the TCP sublayer (TCP stack) in the FAP indicates (upper layer) whether it loses connectivity with other endpoints (ie, INC). Or when the upper layer tries to transmit data through the TCP connection, or when the stack can detect the loss of connectivity via the TCP keep-alive mechanism, a notification from the TCP sublayer on the FAP may occur.
When the FAP fails to re-establish connectivity, the FAP will perform the following operations (not shown) to deregister all UEs currently camping on the FAP: (1) The FAP uses the TCP connection currently established for each UE to report to the INC. Send a GA-RC deregistration message, (2) release the TCP connection to the GANC, and (3) release all resources associated with the deregistered UE.
In addition, the FAP 2510 forces (at step 6) all UEs currently camping on the FAP to perform cell-reselection and roam outside the coverage area of the Femto cell. If a failure is detected for the UE dedicated connection
200780043341.5 If TCP connectivity is removed, FAP will immediately deregister the UE and trigger the UE's cell reselection without attempting to reestablish the UE-specific TCP connection. Finally, as a result of the cell reselection, the UE 2505 will handover (at step 7) to the UMTS macro cell 2520 (if UMTS macro network coverage is available).
9. INC-initiated deregistration In some embodiments, INC deregisters FAP under the following error conditions: (1) INC receives the GA-RC registration update uplink message, but the FAP is not registered, (2) INC Received the GA-RC registration update uplink message, but encountered a resource error and could not process the message, (3) INC received the GA-RC registration update uplink message with the new macro network cell information, and the The macro cell is a restricted Femto cell, and (4) INC receives the GA-RC registration update uplink message and sends a request for the registered FAP to the AAA server. One of the following will happen: ( a) INC received a user authentication failure from the AAA server, (b) INC did not receive 4 responses from the AAA server, and the transaction timer expired> or (c) S1 interface was enabled but not configured AAA server, therefore cannot authenticate users. In some embodiments, when the INC receives a GA-RC synchronization information message for an unregistered UE, the INC deregisters the UE.
10. FAP-Initiated Registration Update FIG. 26 shows a situation where FAP initiates a registration update in some embodiments. As shown in the figure, the registration update is triggered (in step 1) in FAP 2605 (for example, macro network coverage is detected). FAP sends (in step 2) GA-RC registration-update-uplink to INC 2610.
The INC 2610 exchanges (in steps 3a-3c) with the AAA server 2615 an SI RADIUS message for service access control (SAC). Based on the results of the SAC, this operation can be used to trigger (in step 4) additional processing (for example, deregistration or registration update downlink).
11. INC-Initiated Registration Update Figure 27 shows the situation where INC initiates a registration update. As shown in the figure, a registration update is triggered (in step 1) in INC 2715 (for example, due to a change in the SAC list for FAP, or a change in system information, etc.).
Next, INC2715 sends (in step 2) a GA-RC registration update downlink message to FAP2710. As shown in the figure, this operation can be used to trigger (in step 3) some other processing (for example, FAP 2710 rejects UE 2705 due to receiving an updated SAC list from INC).
12. UE synchronization initiated by the FAP after the TCP connection is reestablished. In some embodiments, when the FAP receives a TCP RST after the TCP connection fails, the FAP
200780043341.5 First tried to use GA-RC synchronization processing to reestablish the signaling connection. Figure 28 shows the synchronization process initiated by the FAP in some embodiments.
a) UE synchronization process initiated by the FAP In some embodiments, when the FAP receives a TCP RST after the TCP connection fails, the FAP tries to re-establish the TCP connection once. As shown in Figure 28, after successfully re-establishing the TCP connection, FAP 2805 sends (at step 1) GA-RC synchronization information to GANC 2810 to synchronize the status information of the UE. When unsuccessful, the FAP releases the UE's resources and forces the UE to roam outside the FAP and select an alternative cell (either a macro cell or another FAP) for camping.
b) The GANC processes the UE synchronization information message. When the GA-RC synchronization information message is received from the FAP on the UE's TCP connection, the GANC updates the UE status information as specified in the request. GANC also verifies that the associated FAP is in the registered state. When the FAP is not in the registered state, GANC deregisters the UE by sending a GA-RC-deregistration message (not shown) with a rejection reason code FAP is not registered to the FAP on the TCP connection of the UE. When the GA-RC layer in the GANC has submitted a GA-RC deregistration message to the TCP layer, it initiates the release of half of its two-way TCP connections. GANC also verifies that the binding (IMSI, TCP connection) received in the GA-RC synchronization message is valid.
VI. Call management
A. Voice carrier establishment (on AAL2, using Iu-UP) Figure 29 shows some embodiments for the purpose of mobile station (MO) or mobile station (MT) calls, and the UE The normal process of successfully establishing a voice carrier association with the MSC. As shown in the figure, the signaling for call origination or termination travels between UE2905, FAP2910, GANC MGW 2915, INC 2920 and MSC 2925 (in step 1) = MSC 2925 sends to INC 2920 (in step 2) RANAP allocation Request (RAB) message. The allocation request includes the address used for ALCAP signaling (ATM E.164 or NSAP address), as well as binding-id.
Next, INC 2920 requests (in step 3) GANC MGW 2915 to prepare a bearer connection between the endpoints (VoIP towards FAP and Iu-UP towards MSC on AAL2). The MGW 2915 uses the ATM address and binding-id to initiate (in step 4) ALCAP signaling to the MSC 2925.
Next, the MSC2925 uses the ALCAP establishment confirmation message to answer (in step 5) the AAL2 connection request. Here, (Step 6) AAL2 connection with appropriate QoS exists between GANC MGW and MSC. Then, the GANC MGW sends (in step 7) an Iu-UP control (Iu-INIT) message on the AAL2 connection to request Iu-UP initialization.
200780043341.5 No.
MSC 2925 responds with Iu-UP initial acknowledgement (Iu-INIT ACK) (in step 8). Next, MGW 2915 assigns the MGW IP address and port to the WIP side of the connection. The MGW sends (in step 9) the VblP information to the INC using the prepare carrier Ack message. Next, INC 2920 sends (at step 10) a GA-CSR activation channel message to FAP2910 and starts timing (for example, Tqueuing as described in UTRAN Iu interface Radio Access Network Application Part (RANAP) signaling, 3GPPTS 25.413) to ensure At or before the expiration of Tqueuing, the RANAP allocation response is sent to the MSC»GA-CSR activation channel message including the description of the VoIP connection created by the GANC MGW.
FAP2910 initiates (in step 11) an appropriate RRC layer radio bearer establishment message to UE2905. The UE confirms (at step 12) the establishment to the FAP via the radio bearer establishment completion message. The FAP sends (at step 13) a GA-CSR activation-channel-confirmation message to the INC, which includes the local IP address and port used for the VoIP connection.
INC requests (in step 14a) GANC MGW modifies the previously created connection and sends the voice stream to the IP address and port provided by FAP. GANC MGW confirms (in step 14b) the connection modification. INC 2920 confirms (at step 15) the completion of the establishment of the traffic channel to FAP 2910 via the GA-CSR activation-channel completion message.
INC 2920 sends (at step 16) MSC 2925 a signal regarding the completion of RAB allocation. Here, (steps 17a-17c), via FAP 2910 and GANC MGW 2915, there is a voice carrier between UE 2905 and MSC 2925. After the voice carrier is established, continue with the rest of the call establishment.
B. Call management scenarios The following scenarios show the message flows involved in various call management scenarios via Femto cells.
1. Call originating from a mobile station FIG. 30 shows a call originating from a mobile station in some embodiments. FIG case illustrated -PSTN call for a mobile station. As shown in the figure, the UE 3005 in GAN idle mode places (in step 1) a call. UE 3005 establishes (in step 2) an RRC connection with FAP 3010. When making a request at the upper layer, the UE sends (in step 3) a CM service request to the FAP.
FAP performs (in step 4) the GA-CSR connection establishment process with INC, as described in the previous sections. Then, FAP 3010 uses GA-CSR UL to directly deliver the message to INC3015 to forward (in step 5) the CM service request. Next, INC 3015 establishes an SCCP connection to MSC 3020 and uses RANAP initial UE message to forward to the MSC (in step 6) CM service
200780043341.5 request. The subsequent NAS messages between the UE and the MSC will be sent between the INC and the MSC using RANAP direct delivery messages.
Next, the MSC 3020 uses standard UTRAN authentication processing to authenticate the UE 3005 (at step 7). The MSC also initiates (at step 7) the security mode control process as described in the previous sections. The UE sends (in step 8) an establishment message to the FAP to provide the MSC with details about the call and its carrier capabilities and supported codecs.
FAP forwards the message within the GA-CSR UL direct transfer between FAP and INC (at step 9). INC uses RANAP to directly deliver the message and will establish a message relay (in step 10) to the MSC.
The MSC 3020 uses the call forward message to indicate to the INC (at step 11) that it has received the call setup and it will not accept other call-setup information. INC forwards the message (in step 12) to FAP in the GA-CSRDL direct delivery. Then, the FAP relays the call forward message (at step 13) to the UE through the air interface. Here (step 14), using one of the processes shown in the previous section, an end-to-end carrier path is established between the MSC and the UE.
The MSC 3020 uses (at step 15) the user address to construct the ISUP IAM and sends it to the destination switch 3025 of the called party. The destination switch responds with an ISUP ACM message (at step 16). Then, the MSC signals the UE with an alarm message to indicate that the called party is ringing. The message is passed (in step 17) to INC.
INC forwards the alert message (in step 18) to FAP in the direct delivery of GA-CSRDL. The FAP relays the alarm message (in step 19) to the UE, and if the UE has not connected the audio path to the user, it will generate a ring back to the calling party. Otherwise, the ringback generated by the network will be returned to the calling party.
The called party answers and the destination switch indicates this with an ISUPANM message (at step 20). The MSC signals via the connection message that the called party has responded. The message is delivered (in step 21) INC. INC. forwards the connection message (in step 22) to FAPo in the GA-CSR DL direct delivery
The FAP relays (at step 23) the connection message to the UE and the UE connects the user to the audio path. If the UE is generating ringback, the UE stops generating ringback and connects the user to the audio path. The UE sends (in step 24) a connection Ack in the response, and both parties are connected to make a voice call. FAP directly relays the message in the GA-CSR UL between FAP and INC (at step 25).
200780043341.5 No.
INC forwards the connection Ack message to (in step 26) MSC=Now, the end-to-end two-way path is ready (step 27) and the two-way voice service flows between UE and MSC through FAP and INC. FAP with local service can use FAP IMSI to support MO. The necessary message flow will be similar to the aforementioned FAP-UE message exchange without air interface.
2. Call terminated at the mobile station Figure 31 shows a call terminated at the mobile station. The situation shown in the figure is used for calls from PSTN to mobile stations. As shown in the figure, the MSC (ie, GMSC function) receives (in step 1) a call from party A who wants to call user 3105 in the Femto cell. The MSC 3120 sends (in step 2) a RANAP paging message to the INC 3115 identified by the latest location update it has received, and the MSC 3120 includes the TMSI, if available. The IMSI of the paged mobile station is always included in the request.
INC3115 uses the IMSI provided by the MSC to identify the UE registration context. Then, it uses the GA-CSR page request message to page (in step 3) the associated FAP3110. This message includes TMSI, if it is available in the request from the MSC, otherwise it only includes the IMSL of the mobile station
FAP 3110 relays the paging request to (in step 4) UE<sub>0</sub>Based on the RRC status of the UE, the FAP can use paging type 1 or 2, as described in the Radio Resource Control (RRC) protocol specification, 3GPP TS 25.331, which is hereinafter referred to as TS 25.331. If there is no such connection, UE3105 establishes (in step 4a) an RRC connection with FAP3110. If there is already an RRC connection, omit this step (for example, an RRC connection for the PS domain may have been established). Next, the UE3105 processes the paging request and sends (in step 5) a paging response to the FAP3110. Then, FAP performs (in step 5a) the GA-CSR connection establishment process with INC, as described in the previous sections. The FAP responds with the GA-CSR page response (in step 6).
INC 3115 establishes an SCCP connection to MSC 3120. Then, INC 3115 uses the RANAP initial UE message to forward (in step 7) the paging response to the MSC. The subsequent NAS message between the UE and the core network will be sent using RANAP to directly deliver the message. Then, the MSC uses standard UTRAN authentication processing to authenticate the UE (in step 8). The MSC also initiates (in step 8) the security mode control process, as described in the previous sections.
The MSC initiates (in step 9) call establishment using the establishment message sent to the FAP via the INC. Then, INC forwards the message to (in step 10) FAP in the GA-CSRDL direct delivery message.
200780043341.5 No.
The FAP relays the setup message (step 11) to the UE »After checking its compatibility with the carrier service requested in the setup and modifying the carrier service as needed, the UE 3105 responds with a call confirmation (at step 12). If the establishment includes a signal information element, the UE uses the indicated signal to warn the user, otherwise the UE warns the user after the successful configuration of the user plane.
FAP uses the GA-CSR UL direct delivery message to relay the call confirmation to (in step 13) INCo. Then, INC uses the RANAP direct delivery message to forward the call confirmation message to (in step 14) the MSC. Here (step 15), use the process for voice carrier establishment described in the previous sections to establish an end-to-end carrier path between MSC3120 and UE3105.
The UE signals the FAP via the alarm message (in step 16) that it is warning the user...FAP uses GA-CSR UL direct delivery to relay the alarm message to (in step 17) INC. INC (in step 18) to forward the alarm message To MSC.
The MSC 3120 returns (at step 19) an ISUPACM message to the initiating PSTN switch 3125. The UE signals (at step 20) via the connection message that the called party has answered. FAP relays the connection message to (in step 21) INC in the GA-CSRUL direct delivery message. Next, INC forwards the connection message to (in step 22) the MSC. Then, the MSC returns (at step 23) an ISUP ANM message to the initiating PSTN switch 3125. The MS confirms to the INC via the connection Ack message (at step 24). INC forwards the message to (at step 25) FAP in the GA-CSR DL direct delivery,
The FAP relays the connection Ack (in step 26) to the UE. Both parties of the call are connected on the audio path. Now, the end-to-end two-way path is ready (step 27) and the two-way voice service flows between the UE and the MSC through the FAP and INC. FAP with local service can use FAP IMSI to support MT. The necessary message flow will be similar to the aforementioned FAP-UE message exchange that does not pass through the air interface.
3. Call release performed by Femto cell users FIG. 32 shows a situation where Femto cell users release a Femto cell call in some embodiments. As shown in the figure, the Femto cell user 3205 requests (in step 1) the call to be released (for example, by pressing the END button). Upon receiving the request from the upper layer, the UE sends (in step 2) a disconnect message to the FAP 3210. FAP forwards the disconnect message to (in step 3) INC (embedded in the GA-CSR UL direct delivery message).
INC 3220 relays the disconnection message to (in step
200780043341.5 No.
4) MSC3225. The MSC 3225 sends (at step 5) an ISUP release message to the other party 3230. The MSC uses RANAP to directly deliver the message to the INC to send (in step 6) the release.
Next, INC uses GA-CSR DL to pass the message directly to forward the release message to (in step 7) FAP<sub>O</sub>Then, the FAP sends a release message to the UE through the air interface (in step 8)<sub>O </sub>The UE3205 confirms (at step 9) the release to the FAP via a release complete message. FAP uses GA-CSR UL to directly deliver the message to relay the release completion message to (in step 10) INCo
INC uses the RANAP direct delivery message to forward the message to (in step 11) the MSC. Here, the MSC considers the connection to be released. Sometimes, after step 5, the MSC receives (at step 12) the exchanged ISUPRLC message from the other party.
MSC 3225 sends (at step 13) an Iu release command to INC 3220, indicating that it requests the release of call resources. The SCCP connection identifier is used to determine the corresponding call. INC 3220 requests (at step 14) GANC MGW 3215 to release resources associated with the call. GANC MGW 3215 confirms (at step 15) the release of the associated resources.
INC initiates (in step 16) the GA-CSR connection release process to the FAP (as described in the previous sections). The FAP in turn releases (at step 17) any radio resources associated with that particular call. If there is an active PS session for the UE, the FAP may not release the RRC connection, but only release the corresponding CS radio bearer. Finally, the INC uses the Iu release complete message sent to the MSC to confirm (at step 18) the resource release to the MSC. The SCCP connection associated with the call between INC and MSC is also released.
4. Other call situations
Femto cell solution supports the following services: Calling line identification indication (CLIP) Calling line identification restriction (CLIR) Connected line identification indication (CoLP) Connected line identification restriction (CoLR) Unconditional call forwarding Call forwarding busy Call forwarding is not answered Call forwarding cannot be reached Call waiting (CW) Call held (CH)
200780043341.5 Multi-party (MPTY) Closed User Group (CUG) Advice of Charge (AoC) User-User Signaling (UUS) Call Barring (CB) Clear Call Transfer (ECT) Name Identification Complete Calls to Busy Users (CCBS) These ancillary services involve end-to-end processing between the UE and the MSC. In addition to the basic Direct Delivery Application Part (DTAP) messages that have been described for MO and MT calls, the following DTAP messages are used for the purpose of these additional auxiliary services: HOLD HOLD-ACKNOWLEDGE ) .HOLD-REJECT (HOLD-REJECT).Resume (RETRIEVE).Resume-Acknowledge (RETRIEVE-ACKNOWLEDGE).Resume-Reject (RETRIEVE-REJECT) .Facility (FACILITY)
-User-Information (USER-INFORMATION) Congestion-Control (CONGESTION-CONTROL) CM-Service-Prompt (CM-SERVICE-PROMPT) Start-CC (START-CC) CC-Establish (CC-ESTABLISHMENT) CC-Establishment-Confirm (CC-ESTABLISHMENT-CONFIRMED) .Recall (RECALL) In the same manner as described in this disclosure in other call control and mobility management scenarios, INC will transfer these DTAP messages between UE and MSC. Relay in between. A general example is shown in Figure 33. As shown in the figure (in step 1), an existing MM connection for the ongoing call is established between the UE and the MSC. The user requests (at step 2) a specific auxiliary service operation (for example, hold the call).
The UE 3305 transmits (at step 3a) a hold message to the FAP 3310 by radio. then,
200780043341.5 No.
FAP forwards the message to (in step 3b) INC 3315, which is embedded in the GA-CSR uplink direct delivery message. INC relays the DTAP hold message to (in step 3c) the MSC 3320 through the Iu-interface.
Next, through INC and FAP, the DTAP hold-ACK message is sent from the MSC 3320 (in steps 4a-4c) to UE3305. Later, during the call, the user requests (in step 5) another auxiliary service operation (for example To initiate a multi-party call).
The UE sends a facility message to the FAP by radio (in step 6a). Then, FAP forwards the message (in step 6b) to INCo INC and relays the DTAP facility message (in step 6c) to the MSC via the Iu-interface. Finally, through INC and FAP, the DTAP facility message including the response is sent from the MSC (in steps 7a-7c) to the UE.
VII. Packet business
A. GA-PSR transmission channel management processing
The GA-PSR transmission channel (GA-PSR TC) provides the association between FAP and INC for the transmission of user data through the Up interface. Assuming that the user data transmission of Femto cell is based on UDP, the GA-PSR transmission channel is associated with the corresponding FAP and INC IP address and the UDP port used for user data transmission. FAP and INC manage the GA-PSR transmission channel based on the request for data transmission and the configurable GA-PSR TC timer.
1. Status of the GA-PSR sublayer
The GA-PSR transmission channel (GA-PSR TC) management process is the basic process for the PS service, and the PS service is specified to facilitate the control of the GA-PSR connection for user data transmission. Suppose that in the GAN solution used for Femto cell support, GTP-U user data transmission is extended to FAP, and these processes are closely integrated with the RAB allocation process of user data. The GTP-U-based connection between the FAP and the SGSN used for user data transmission is called the GA-PSR transmission channel.
The GA-PSR transmission channel consists of the following parts: (1) the IP address and destination UDP port number to be used for user data transmission at both the SGSN and FAP, and (2) the GA-PSR TC timer. Only when needed, that is, when user data transmission is initiated, FAP or INC will activate the GA-PSR transmission channel.
GA-PSR maintains a separate PS entity for each PDP context established. Each single GA-PSRPS entity can be in two different states, GA-PSR-PS-standby or GA-PSR-PS active state. The state of the GA-PSRPS entity and the corresponding transmission channel are always synchronized.
In the GA-PSR-PS-standby state, the FAP cannot send to or receive data from the SGSN
200780043341.5 User data associated with the specific PDP context. INC or FAP needs to activate the GA-PSR transmission channel before sending any user data for the PDP context. In this state, there is no corresponding GA-PSR transmission channel. When the GA-PSR transmission channel is activated, the GA-PSR entity associated with the PDP context enters the GA-PSR-PS-active state.
In the GA-PSR-PS-active state, the FAP and UE can send and receive user data associated with a specific PDP context to and from the SGSN. Moreover, there is a corresponding GA-PSR transmission channel for the FAP/UE.
The GA-PSRTC timer is also defined below to control the transition from GA-PSR-PS-active state to GA-PSR-PS-standby state. The FAP GA-PSR layer implements a timer associated with each GA-PSR transmission channel. When the entity enters the GA-PSR-PS-active state, the timer starts timing, and whenever a data packet for the PDP context is transmitted to or received from the network, the timer restarts timing. When the timer expires, the FAP deactivates the GA-PSR transmission channel, and the corresponding PDP service entity enters the GA-PSR-PS-# machine state.
The value of the GA-PSR TC timer is provided to the FAP as part of the Femto cell registration process (ie, in the GA-RC registration acceptance message).
2. FAP-initiated GA-PSR transmission channel activation FIG. 34 shows the FAP-initiated GA-PSR transmission channel activation process of some embodiments. Initially, when the uplink data transmission for the PDP context is requested, the corresponding GA-PSR PS PDP entity is in the GA-PSR-PS-idle state. The FAP must establish the GA-PSR transmission channel before resuming the uplink data transmission.
As shown in the figure, if there is no RRC connection, the UE 3405 initiates (in step 1) RRC connection establishment processing according to standard 3GPP processing. When the RRC connection is successfully established, the UE3405 forwards (in step 2) a service request message indicating data transmission to the SGSN via the FAP3410. FAP performs (in step 2a) the GA-PSR connection establishment process with INC, as described in the GA-PSR connection establishment section initiated by FAP under the previous resource management section.
Then, FAP3410 encapsulates the request in a GA-PSR-uplink-direct-pass message, and forwards the request to (in step 3) INC 3415. INC forwards (in step 4) the service request encapsulated in the initial Iu message or in the direct delivery message to CN (SGSN) 3420 according to the PMM status. Optionally, the CN (SGSN) can start (in step 5) the security function, as specified in the security mode control section and the core network authentication section in the Femto cell security section described below. Optionally, when the request is received, and if the UE is in PMM-connected
200780043341. 5 In the connected state, the CN (SGSN) responds with a service acceptance message (in step 6).
Optionally, if a service acceptance message is received, INC3415 forwards the message to (in step 7) FAP3410<sub>o</sub>Then, FAP forwards the message to (in step 8) UE3405°CN (SGSN) 3420 to initiate (in step 9) RAB allocation processing, and CN (SGSN) 3420 includes RAB-ID. CN transport layer address (IP address) and CN Iu transmission association (GTP-U terminal endpoint identifier (TEID)), used for user data to be used by the GA-PSR transmission channel.
Next, INC forwards the GA-PSR activation TC REQ to (at step 10) FAP to activate the transmission channel for user data transmission. The message includes RAB-ID, and INCIP address and INC TEID. In order to make FAP directly send GA-PSR TC packets (ie, GTP-U messages) to SGSN, INC sets the INC IP address to CN IP address, and sets INC TEID to CN TEID. In an alternative embodiment, GANC can assume the role of GTP-U proxy gateway. In this case, for a given GA-PSRTC, there are two separate GTP-U tunnels, namely, one of FAP and GANC. The first GTP-U between and the corresponding GTP-U between GANC and SGSN. GANC is responsible for relaying the actual PS data packets between these two GTP-U tunnels. Next, establish (at step 11) the corresponding radio bearer between FAP3410 and UE3405.
Then, the FAP responds to the INC with a confirmation (in step 12). The message includes the RAB-ID and GTP-U TEID assigned by the FAP for the specific PS session. Upon receiving the confirmation, INC sends the RAB allocation Rsp message to (in step 13) CN (SGSN) to complete the RAB allocation process. In order to enable the SGSN to send GTP-U messages directly to the FAP, INC sets the RAN IP address to the IP address of the FAP, and sets the RAN TEID to the TEID allocated by the FAP for the UE-specific PS session.
INC informs FAP (at step 14) that the processing is complete and FAP changes the corresponding GA-PSR PS PDP entity state to GA-PSR-PS activity and starts the GA-PSRPS TC timer. The UE initiates (at step 15) uplink user data transmission via the established transmission channel, and the SGSN can use the same transmission channel to transmit downlink user data packets. When the transmission channel is active, both the FAP and the SGSN can use the transmission channel to continue to directly send user data associated with the same PDP context.
3. Deactivation of GA-PSR Transmission Channel Initiated by FAP FIG. 35 shows a situation in which the FAP deactivates the GA-PSR transmission channel after the GA-PSR TC timer expires in some embodiments. As shown in the figure, the GA-PSR TC timer associated with one of the active GA-PSR transmission channels expires (at step 1). FAP 3510 sends to INC 3515
200780043341.5 (in step 2) GA-PSR deactivation TC REQ message including RAB-ID to identify the GA-PSR transmission channel and indicate that the reason for deactivation is normal release.
INC 3515 forwards the RAB release Req message to (in step 3) CN (SGSN) 3520 to request the release of the associated RAB. CN (SGSN) responds with RAB allocation request (in step 4), indicating the release of the requested RAB.
Next, INC 3515 responds to the FAP with a GA-PSR deactivation TC ACK message (in step 5) to confirm the successful deactivation. Upon receiving the confirmation message, the FAP initiates (in step 6) the release of the associated radio bearer. Finally, INC sends (in step 7) the RAB allocation Rsp message to notify the SGSN that the RAB release process is complete.
4. Network initiated transmission channel activation for PS service FIG. 36 shows a situation where CN (SGSN) initiates activation of the PS transmission channel for user data service. This situation covers the case where the SGSN receives downlink user data packets from the GGSN and the case where the RAB for the PDP context is not established. At first, the CN (SGSN) received downlink user data to deliver to the UE, and no associated RAB was established. The UE was in the PMM idle state. UE 3605 is in the PMM-idle state, and CN (SGSN) 3610 sends (at step 1) a RANAP paging request via INC 3615 to UE 3605 to locate the user. The paging request indication is used for paging in the PS domain. INC3615 forwards the GA-PSR paging message to (in step 2) FAP 3610. Next, FAP forwards the PS page to (in step 3) UE 3605 in accordance with standard 3GPP processing. Based on the RRC status of the UE described in TS 25.331, the FAP can use paging type 1 or 2. Next, establish (at step 4) an RRC connection between UE 3605 and FAP3610. If an existing RRC connection already exists (for example, an RRC connection for the CS domain may have been established), this step is omitted.
Next, the UE responds to the SGSN with a service request indicating a PS paging response via the FAP (in step 5). The message is encapsulated in the RRC INITIAL direct delivery message. FAP performs (in step 5a) the GA-PSR connection establishment process with INC, as described in the GA-PSR connection establishment section initiated by FAP in the resource management section above. FAP uses the GA-PSR paging response message to forward the PS paging response to (in step 6) INC.
INC forwards (in step 7) the service request message encapsulated in the RANAP initial UE message to the SGSN. Perform security functions (in step 8), as specified in the security mode control section and core network authentication section in the FEMTO cell security section below. Steps 9 to
200780043341.5 No.
15 is the same as described in the GA-PSR transmission channel activation section initiated by FAP above.
5. Network-initiated transmission channel deactivation FIG. 37 shows a network-initiated GA-PSR transmission channel deactivation process in some embodiments, which includes the release of wireless access bearers. Initially, the active GA-PSR transport channel associated with the UE 3705 registered for Femto cell service is active.
As shown in the figure, optionally, INC3715 can initiate (in step 1) RAB release processing as a result of the error handling process. This will trigger CN (SGSN) 3720 to release the corresponding RAB. CN (SGSN) 3720 sends (in step 2) a RAB allocation request to request the release of the associated RAB» The release request may include one or more RABs.
INC 3715 requests (in step 3) to deactivate the associated GA-PSR transmission channel. Therefore, the corresponding radio carrier is released (at step 4). Then, FAP3710 updates the status of the corresponding GA-PSRPS PDP entity (in step 5) to standby, stops the GA-PSR TC timer and sends back confirmation to INC. Repeat steps 3, 4, and 5 for each additional RAB that needs to be released. Finally, INC 3715 informs (in step 6) CN (SGSN) 3720 that the release is successful.
B. User data and signaling transmission
1. User data transmission processing FIG. 38 shows the transmission of user data packets via Femto cells in some embodiments. As shown in the figure, if the corresponding GA-PSR transmission channel is inactive, initiate (in step 1) GAPSR TC activation processing, as specified in the GA-PSR transmission channel activation section initiated by FAP above. When the GA-PSR transmission channel is established, FAP3810 starts (in step 2) the GA-PSR TC timer.
UE 3805 initiates (in step 3) the delivery of uplink user data packets using PDCP data service. FAP 3810 uses the standard GTP-U protocol as specified in GPRS Tunnelling Protocol (GTP) across the Gn and Gp interface, 3GPP TS 29.060 to forward (in step 4) packets, and restart (in step 5) the GA-PSRTC timer .
CN (SGSN) 3820 uses the same GA-PSR transport channel associated with a specific PDP context to deliver (in step 6) downlink user data packets. Use the standard GTP-U protocol as specified in 3GPPTS 29.060 to transfer downlink user data packets. When a downlink data packet is received, the FAP restarts (in step 7) the GA-PSR TC timer associated with the corresponding GA-PSR transmission channel, and forwards the packet to (in step 8) the UE via PDCP.
Additional uplink and downlink user data packets via the same GA-PSR transmission channel
200780043341.5 is passed as described in steps 2 and 3 respectively (in step 9). After the GA-PSRTC timer expires (step 10), FAP initiates (at step 11) the GA-PSR transport channel deactivation process, as described in the above section Deactivation of GA-PSR transport channel initiated by FAP . FAPs with local services can use FAP IMSI to support #PS user plane activities. The necessary message flow will be similar to that described above without FAP-UE message exchange over the air interface.
2. The GA-PSR signaling process establishes a single TCP connection for each UE to transmit signaling messages in the Femto cell. This TCP connection is used to transmit all signaling and SMS messages related to CS and PS.
a) PS signaling processing initiated by the UE For the PS-related signaling initiated by the UE, the UE sends the PS signaling message to the CN via the INC, and the INC forwards the message to the CN through the Iu-ps interface in accordance with the standard UMTS; for example , The signaling message may include GMM attach (GMM attach) or SM PDP context activation message. INC encapsulates the received signaling message in a RANAP direct delivery message, which is forwarded to the SGSN through the Iu-ps interface. Figure 39 shows uplink control plane data transmission of some embodiments.
At first, the UE 3905 prepares to send an uplink signaling message for PS service to the CN (SGSN) 3920. This can be any of GMM or SM signaling messages. As shown in the figure, if the RRC connection does not exist, the UE 3905 initiates (in step 1) RRC connection establishment processing according to standard 3GPP processing.
When the RRC connection is successfully established, the UE forwards (in step 2) the service request message indicating the PS signaling message to the SGSN via FAP3910. FAP performs (in step 2a) the GA-PSR connection establishment process with INC, as described in the GA-PSR connection establishment section initiated by FAP in the resource management section above. FAP encapsulates the service request in the GA-PSR-uplink-direct-pass message and forwards the request to (in step 3) INC3910. Next, INC will encapsulate the service request in the initial Iu message or in the direct message according to the PMM status. The service request in the delivery message is forwarded (in step 4) to the SGSN. Optionally, the CN (SGSN) can initiate (in step 5) security functions, as specified in the security mode control and core network authentication sections below. UE 3805 uses RRC uplink direct delivery service to send PS signaling message to (at step 6) FAP3910,
FAP 3910 will encapsulate the PS signaling message in the GA-PSR-uplink-direct-pass message
200780043341. 5 Forward to (in step 7) INC. Finally, INC3915 uses RANAP direct transfer processing to forward the PS signaling message to (in step 8) CN (SGSN) 3920.
b) PS signaling processing initiated by the network For PS-related signaling initiated by the network, the core network sends PS signaling messages to INC via the IuPS interface in accordance with standard UMTS; for example, the signaling messages may include GMM attach accept messages or SM PDPs Context activation accept message. INC encapsulates the received signaling message in GA-PSR-downlink-direct-transfer message or GA-PSR paging message, which is forwarded to FAPo via the existing TCP signaling connection. Figure 40 shows Downlink control plane data transmission of some embodiments. At first, the CN (SGSN) 4020 is ready to send a downlink signaling message for the PS service to the UE 4005. This can be any of GMM or SM signaling messages. It is assumed that the signaling processing is initiated by the network, and if the UE is in the PMM-idle state, the SGSN will page the UE first. If the UE is in the PMM-connected state, the SGSN will use the RANAP direct delivery process started in step 9 to send the downlink PS signaling message.
As shown in the figure, optionally, if the UE 4005 is in the PMM-idle state, the CN (SGSN) 4020 sends (in step 1) a RANAP paging request to the UE via the INC 4015 to locate the user. The paging request indicates paging for the PS domain. Optionally, if a paging request is received, INC uses a GA-PSR paging message to forward the paging request to (in step 2) FAP 4010. Similarly, optionally, if a paging message is received, FAP processes according to standard 3GPP Forward the PS page to (in step 3) the UE. Optionally, if there is no RRC connection for the UE, the connection is established (in step 4) according to standard 3GPP processing. Optionally, if a paging for the PS service is received, the UE responds to the SGSN with a service request message indicating a PS paging response via the FAP (at step 5). The service request message is encapsulated in the RRC initial direct delivery message.
FAP 4010 executes (in step 5a) the GA-PSR connection establishment process with INC, as described in the GA-PSR connection establishment section initiated by FAP in the resource management section above. FAP forwards the response encapsulated in the GA-PSR paging response message to (in step 6) INC.
Next, INC 4015 forwards (at step 7) the service request message encapsulated in the RANAP initial UE message to SGSN 4020. Optionally, the CN (SGSN) initiates (in step 8) the security function.
CN (SGSN) uses RANAP direct transfer processing to forward PS signaling messages to (in step 9) INC» INC forwards the PS signaling messages encapsulated in GA-PSR-downlink-direct-transfer messages to (in step 9). 10) FAP...Finally, FAP uses RRC downlink to deliver services directly
200780043341.5 The signaling message is sent (in step 11) to the UE. FAPs with local services can use FAP IMSI to support PS signaling plane activities. The necessary message flow will be similar to the case of FAP-UE message exchange without air interface described above.
VIII. Error handling processing In some embodiments, the checks described in this section are applied to all messages exchanged in the Femto cell system. This section also specifies the handling of unknown, unforeseen, and erroneous protocol data handled by the receiving entity. These processes are called error handling processes, but, in addition to providing recovery mechanisms for error conditions, they also define compatibility mechanisms for future extensions of the protocol. In some embodiments, the following subsections A to F are applied in order of priority.
In this section, the following terms are used: (1) If the information element (IE) includes at least one value in the corresponding message that is defined as reserved, or if its value partly violates any message-related rules, then the information The element (IE) is defined as being syntactically incorrect in the message. However, IE specifies in its length indicator that it is not a grammatical error to be greater than the length defined for a particular message, and (2) If the message includes a resource that contradicts the receiver's resources and/or contradicts the specified procedural part The message, which may depend on the status of the receiver, is defined as having semantically incorrect content. The processing described in this subsection applies to both GA-CSR messages and GA-PSR messages, unless there are clear provisions to the contrary.
A. The message is too short. When the received message is too short to include the complete message header and all mandatory information elements, the message is ignored.
B. Invalid message header When FAP receives a message with an undefined or unimplemented message type via UDP, FAP ignores the message. When the FAP receives a message with an undefined or unimplemented protocol discriminator via TCP, the FAP ignores the message. When the FAP receives a message with a skip indicator IE that is not encoded as 0000 or a length IE greater than 2048, the FAP ignores the message.
When FAP receives a message with a message type that is not defined for a specific PD (GA-CSR or GA-PSR) or is not implemented via TCP, FAP returns GA with a reason that the message type does not exist or is not implemented, respectively -CSR status or GA-PSR status. When FAP receives a message that is incompatible with the protocol state, FAP ignores the message and should return a status message (GA-CSR or GA-PSR) with the reason that the message type is incompatible with the protocol state.
C. Invalid information element
200780043341.5 When FAP receives a GA-RC or GA-CSR or GA-PSR message with a missing or grammatically incorrect mandatory IE, FAP ignores the message and returns the mandatory information with invalid reason ( GA-RC or GA-PSR) status message. FAP also ignores all unknown IEs in the received message. FAP further treats all optional IEs that are syntactically incorrect in the message as if they do not exist in the message.
When FAP diagnoses a missing or unexpected conditional IE or when it receives at least one grammatically incorrect conditional IE, FAP ignores the message and returns the conditional IE error with the reason value (GA- RC or GA-PSR) status message. When FAP receives a message with semantically incorrect content, FAP ignores the message and returns a status message (GA-RC or GA-PSR) with a message whose reason value is semantically incorrect.
D. Handling of lower-level errors The handling of lower-level faults in the FAP in the GA-RC-deregistration state is as follows. If a TCP connection has been established to the supply GANC, FAP releases the connection. If a secure connection has been established to the SeGW supplying GANC, the FAP will release the secure connection (as defined in the Internet Key Exchange (IKEv2) Protocol, IETF RFC 4306). In addition, when a lower layer failure occurs during the discovery process, FAP doubles the timer value currently used for TU3903, but does not exceed the maximum value (32 minutes). FAP also starts the timer TU3903.
When a lower-layer failure occurs during the registration process, and if after the number of attempts defined by the FAP parameter Up Connect Attempt Count (maximum 3), the registration is still unsuccessful, and if the FAP has If the default GANC attempts to register, the FAP deletes the stored information about the default GANC, increases the redirection counter, and initiates the discovery process. When a lower-layer failure occurs during the registration process, after trying the number of attempts defined by the connection attempt count (maximum value of 3) on the FAP parameter, the registration is still unsuccessful, and the FAP has tried to register with the service GANC, the FAP makes a re The directional counter is increased and the registration process is initiated to the default GANC.
When a lower layer failure occurs during the registration process, and the registration is successful before the number of attempts defined by the FAP parameter on the connection attempt count (the maximum value is 3), the FAP starts the timer TU3905 and waits for it to expire.
When not in the GA-RC-deregistration state, the lower fault handling in FAP is as follows. For all lower layer faults in FAP (for example, DNS, IPSec, or TCP faults, not RST), except for the FAP synchronization initiated by the above FAP after the TCP connection is rebuilt
In addition to the TCP connection failures described in section 200780043341.5, FAP (1) releases the TCP connection to the current GANC, if the connection is established, (2) releases the secure connection to the SeGW of the current GANC, if If the connection is established, (3) start the timer TU3905 (for FAPTCP connection) or TU3955 (for UE specific TCP connection), and (4) enter the GA-RC-deregistration state.
E. IE outside the sequence
FAP ignores all out-of-sequence IEs in the message. In some embodiments, GANC also uses the same method and ignores all IEOs outside the sequence in the message.
F. Unexpected news
FAP silently discards all unexpected messages (unless a specific behavior is defined for some messages). These messages are either inconsistent with the current state of the device or out of sequence. The network should take the same approach.
IX. Messages and Information Elements Used This section provides a list of messages and information elements (IE) used in some embodiments. IE is similar to attributes or parameters, and is used in messages to exchange information through interfaces.
Table IX-1 summarizes the messages used for general resource management.
Table IX-1: Messages used for unlicensed radio resource management
<td>Found message:</td>
<td>GA-RC discovery request</td>
<td>GA-RC found acceptance</td>
<td>GA-RC found rejection</td>
<td>Registration message:</td>
<td>GA-RC registration request</td>
<td>GA-RC registration accepted</td>
<td>GA-RC registration redirect</td>
<td>GA-RC registration rejected</td>
<td>GA-RC deregistration</td>
<td>GA-RC registration update uplink</td>
<td>GA-RC registration update downlink</td>
<td>Miscellaneous news:</td>
<td>GA-RC keep alive</td>
200780043341.5 No.
GA-RC Synchronization Information Table IX-2 summarizes the messages used for the management of General Access Circuit Switching Resources (GA-CSR)
Table IX-2: Messages used for GA-CSR management
<td>GA-CSR connection establishment message:</td>
<td>GA-CSR request</td>
<td>GA-CSR request acceptance</td>
<td>GA-CSR request denied</td>
<td>Service channel establishment message:</td>
<td>GA-CSR activation channel</td>
<td>GA-CSR activate channel ACK</td>
<td>GA-CSR activation channel failure</td>
<td>GA-CSR activation channel completed</td>
<td>Channel release message:</td>
<td>GA-CSRfreed</td>
<td>GA-CSRRelease complete</td>
<td>GA-CSRClear (CLEAR)ask</td>
<td>Paging message:</td>
<td>GA-CSRPage request</td>
<td>GA-CSRPaging response</td>
<td>Safe mode message:</td>
<td>GA-CSRSafe Mode Command</td>
<td>GA-CSRSafe mode complete</td>
<td>GA-CSRSafe Mode Deny</td>
<td>Miscellaneous news:</td>
<td>GA-CSRUplink direct delivery</td>
<td>GA-CSRDownlink direct delivery</td>
<td>GA-CSRsituation</td>
surfaceIX-3Summarizes the resources used for general access packet services (GA-PSR) Managed messages.
Table IX-3:Message for general access radio link control management
200780043341.5 NS
<td>GA-PSRConnection management message:</td><td>Transport layer used</td>
<td>GA-PSR-ask</td><td>TCP</td>
<td>GA-PSRRequest acceptance</td><td>TCP</td>
<td>GA-PSRRequest denied</td><td>TCP</td>
<td>GA-PSR-freed</td><td>TCP</td>
<td>GA-PSRRelease complete</td><td>TCP</td>
<td>GA-PSR TCManagement message:</td><td>Transport layer used</td>
<td>GA-PSR-activation-TC-REQ</td><td>TCP</td>
<td>GA-PSR-activation-TC-ACK</td><td>TCP</td>
<td>GA-PSR-activation-TC-CMP</td><td>TCP</td>
<td>GA-PSR-go activate-TC-REQ</td><td>TCP</td>
<td>GA-PSR-go activate-TC-ACK</td><td>TCP</td>
<td>GPRSTunnel message:</td><td></td>
<td>GA-PSR-Uplink-direct-transfer</td><td>TCP</td>
<td>GA-PSR-Downlink-direct-transfer</td><td>TCP</td>
<td>GANDedicated signaling message:</td><td></td>
<td>GA-PSR-Paging</td><td>TCP</td>
<td>GA-PSR-Paging response</td><td>TCP</td>
<td>GA-PSR-situation</td><td>TCP</td>
<td>Security message:</td><td></td>
<td>GA-PSRSafe Mode Command</td><td>TCP</td>
<td>GA-PSRSafe mode complete</td><td>TCP</td>
<td>GA-PSRSafe Mode Deny</td><td>TCP</td>
<td>GA-PSRClear request</td><td>TCP</td>
Table 9.2.1:Used for unlicensed radio resource managementIEType and identifier
<td>IE</td><td>Identifier</td>
<td>Mobile station identity (FAP)</td><td>1</td>
<td>GANRelease finger</td><td>2</td>
<td>Access identity</td><td>3</td>
200780043341.5 NS
<td>GERANCommunity identity</td><td>4</td>
<td>Location area recognition</td><td>5</td>
<td>GERAN/UTRANCoverage indicator</td><td>6</td>
<td>GANClassification mark</td><td>7</td>
<td>Geographic location</td><td>8</td>
<td>GANC-SeGWIP address</td><td>9</td>
<td>GANC-SeGWFully qualified domain name/CPU name</td><td>10</td>
<td>Redirect counter</td><td>11</td>
<td>Found the reason for rejection</td><td>12</td>
<td>GANCell description</td><td>13</td>
<td>GANControl channel description</td><td>14</td>
<td>List of cell identifiers</td><td>15</td>
<td>TU3907Timer</td><td>16</td>
<td>GSM RR/UTRAN RRC state</td><td>17</td>
<td>Routing area identification</td><td>18</td>
<td>GANBand</td><td>19</td>
<td>GA-RC/GA-CSR state</td><td>20</td>
<td>Reason for registration rejection</td><td>21</td>
<td>TU3906Timer</td><td>22</td>
<td>TU3910Timer</td><td>23</td>
<td>TU3902Timer</td><td>24</td>
<td>L3information</td><td>26</td>
<td>Channel mode</td><td>27</td>
<td>Mobile station classification mark2</td><td>28</td>
<td>RRreason</td><td>29</td>
<td>Password mode setting</td><td>30</td>
<td>GPRSContinue</td><td>31</td>
<td>according toGANHandover of orders (handover)</td><td>32</td>
<td>ULQuality indicator</td><td>33</td>
<td>TLL1</td><td>34</td>
200780043341. 5 NS
<td>Packet stream identifier</td><td>35</td>
<td>Reason for suspension</td><td>36</td>
<td>TU3920Timer</td><td>37</td>
<td>QoS</td><td>38</td>
<td>GA-PSRreason</td><td>39</td>
<td>User data rate</td><td>40</td>
<td>Routing area code</td><td>41</td>
<td>APLocation</td><td>42</td>
<td>TU4001Timer</td><td>43</td>
<td>Location status</td><td>44</td>
<td>Password response</td><td>45</td>
<td>Decode commandRAND</td><td>46</td>
<td>Decode commandMAC</td><td>47</td>
<td>Decoding key serial number</td><td>48</td>
<td>SAPI ID</td><td>49</td>
<td>Reason for establishment</td><td>50</td>
<td>Required channel</td><td>51</td>
<td>WrongPDU</td><td>52</td>
<td>Sample size</td><td>53</td>
<td>Payload type</td><td>54</td>
<td>Multi-rate configuration</td><td>55</td>
<td>Mobile station classification mark3</td><td>56</td>
<td>LLC-PDU</td><td>57</td>
<td>Location blacklist indicator</td><td>58</td>
<td>Reset indicator</td><td>59</td>
<td>TU4003Timer</td><td>60</td>
<td>APService Name</td><td>61</td>
<td>GANService zone information</td><td>62</td>
<td>RTPRedundant configuration</td><td>63</td>
<td>UTRANClassification mark</td><td>64</td>
200780043341.5 NS
<td>Classification mark query mask</td><td>65</td>
<td>UTRANList of cell identifiers</td><td>66</td>
<td>serviceGANCTable indicator</td><td>67</td>
<td>Registration indicator</td><td>68</td>
<td>GANPLMN List</td><td>69</td>
<td>requiredGANservice</td><td>71</td>
<td>Broadcast container</td><td>72</td>
<td>3GCommunity identity</td><td>73</td>
<td>FAPRadio identity</td><td>96</td>
<td>GANC IPaddress</td><td>97</td>
<td>GANCFully qualified domain name/CPU name</td><td>98</td>
<td>Used forGPRSUser data transmissionIPaddress</td><td>99</td>
<td>Used forGPRSUser data transmissionUDPport</td><td>100</td>
<td>GANC TCP port</td><td>103</td>
<td>RTP UDP port</td><td>104</td>
<td>RTCP UDP port</td><td>105</td>
<td>GERANList of received signal levels</td><td>106</td>
<td>UTRANList of received signal levels</td><td>107</td>
<td></td><td></td>
<td></td><td></td>
<td>Integrity protection information</td><td>75</td>
<td>Encrypted information</td><td>76</td>
<td>Key status</td><td>77</td>
<td>Selected integrity algorithm</td><td>78</td>
<td>Selected encryption algorithm</td><td>79</td>
<td>Reasons for Safe Mode Rejection</td><td>80</td>
<td>RABID</td><td>81</td>
<td>RABparameter</td><td>82</td>
<td>GTP TEID</td><td>83</td>
<td>Service handover</td><td>84</td>
200780043341.5 NS
<td>PDPType information</td><td>85</td>
<td>Data volume report indicator</td><td>86</td>
<td>DLGTP-PDU Serial number</td><td>86</td>
<td>UL GTP-PD U Serial number</td><td>88</td>
<td>DLN-PD U Serial number</td><td>89</td>
<td>ULN-PDU Serial number</td><td>90</td>
<td>CandidateRABParameter value</td><td>91</td>
<td>distributedRABParameter value</td><td>92</td>
<td>Data volume list</td><td>93</td>
<td>DRXCycle length factor</td><td>94</td>
<td>Paging reason</td><td>95</td>
<td>oraidentity</td><td>110</td>
<td>GA-PSRstate</td><td>111</td>
<td>Mobile station identity (UE)</td><td>112</td>
<td>RABSData volume report list</td><td>113</td>
<td>distribute/Priority information reserved</td><td>114</td>
<td>NASSynchronization indicator</td><td>115</td>
X.Short message service
FemtoThe cell system supports both circuit mode (CSmodel)SMSService, also supports grouping mode (PSmodel)SMSservice. operateUEofCS/PSMode may be able to useMMSublayer orGMMThe sub-layer to send and receive short messages. operateUEofPSMode may be able to use only GMMThe sub-layer to send and receive short messages. The following sections describe aboutSMSService andFemto Interaction of the cell.
A.Circuit mode (CSmodel)SMSService andCSmodelSMSSupport relatedFemtoThe cell protocol architecture is based on the aboveFEMTO In the cell system structure sectionCSarea-The circuit service signaling structure described in the Control Plane Structure section. picture41Show some examples forCSmodelSMSThe agreement structure.
FemtoCommunityCSmodelSMSSupport is based onCSThe same mechanism for mobility management and call control. existUE 4105 -side,SMSFloor4110(Including supportCMSub-layer function)
200780043341.5 First useMMFloor4115Services, implemented in accordance with the standard circuit model, to deliverSMSinformation. use GA-CSRThe message relay function in the protocol, inUE4105andMSC4115Between, effectively openSM-CPProtocol tunnel. asCSMobility management is the same as call control processing,SMSuseFAPandINC 4120betweenUEdedicatedTCPSignaling connection throughUpinterface 4125Provide reliableSMStransfer.
B. Grouping mode (PSmodel)SMSService andPSmodelSMSSupport relatedFemtoThe cell protocol structure is based on the aboveFEMTO In the cell system structure sectionPSarea-The packet service signaling structure described in the control plane structure section. picture42Shows the grouping mode in some embodimentsSMSofGANAgreement structure.
existUE 4205 One side,SMSFloor4210 (Including supportCMSub-layer function) implemented in accordance with the standard grouping mode, usingGMMFloor4215Service to deliverSMSinformation. useGA-PSRThe message relay function in the protocol, inUE 4205andSGSN 4220Between, effectively passing throughSM-CP protocol. Just like packet service signaling processing,SMSuseFAPandINC 4225betweenUE dedicatedTCPSignaling connection throughUpinterface 4230Provide reliableSMStransfer.
C. SMSThe following scenario shows the situation viaFemtoVarious of the communitySMSThe message flow involved in the situation.
1.Circuit mode originated from the mobile stationSMS picture43Shows the passage in some embodimentsGANCircuit mode originated from the mobile stationSMS transfer. As shown in the figure, the user enters a message and calls theUE4305From the mobile stationSMSFunction. picture43Steps in4to10Corresponds to the steps in the call from the mobile station section in the call management section above2to7. Next,UE 4305Will be encapsulated in the air interfaceCP-In the data messageSMSMessage sent (in step8 )arriveFAP 4310»
FAPWill be encapsulated inGA-CSR ULDirectly in the messageCP-Data message relay (in step9 )arriveINC 4315.INCuseRANAPDirect messaging willCP-Data message forwarding (in step10 )arriveMSC 4320.MSCuseMAP-MO-Forward-SMCall message viaSMS InteractiveMSC (IWMSC ) 4325,Forward the message (in step11 )arriveSMSC.
MSCSend (in step12) CP-data-ACK,ToCP-The receipt of the data message is confirmed.SM-CPIs designed in the following way: inUEandSMSC (SMEach point-to-point connection between service centers) confirms eachCP-Data block to ensure the underlying transport layer (in this caseRANAP) Work without error, this is because there is no clear response toRANAPDirect messageack ο
200780043341. 5 NS
INC4315Relay the confirmation (in step13)arriveFAP4310.FAPThrough the air interfaceCP-data-ACKForward (in step14)arriveUE 4305.SMSCRespond toIWMSC Send (in step15)SMSNews, andIWMSCexistMAP-MO-Forward-SMReturn result message toMSCSend response.
Next,MSC 4320existCP-The response is relayed in the data message (in step16)arrive INC4315.INC 4315useGA-CSR DLRelay the response directly (in step17)arriveFAP 4310o FAPUse existingRRCThe connection via the air interface will respond to the relay (in step 18)arrive UE<sub>O</sub> AsSM-CP ackPart of the processing,UETowardsFAPconfirmCP-Data reception (in step19 ).FAPRelay the confirmation (in step20 )arriveINC.INCuseRANAPSend the message directly to forward the confirmation (in step21 )arriveMSC.
Next,MSC 4320willIuRelease message sending (in step22 )arriveINC,This message indicates a request to release session resources.SCCPThe connection identifier is used to determine the corresponding session.INC 4315 Then release (in step23 ) Leads to theFAPofGA-CSRconnect. same, FAP 4310Release (in step24)forUEThe corresponding radio resources. at last,INCexist IuIn the release complete messageMSCConfirm (in step25 ) The release. andINCandMSCAssociated with the callSCCPThe connection is released.
2. CSThe end of the mode is at the mobile stationSMS picture44Shows the passage in some embodimentsFemtoCommunityCSThe end of the mode is at the mobile stationSMStransfer. as the picture shows,SMSC 4425TowardsSMSGatewayMSC ( GMSC ) 4420 Send (in step1) ToUE 4405ofSMSinformation.GMSCuseMAP-send-routing -INFO-SMCall message toHLRQuery routing information.
HLRUse and serviceMSCAssociatedMSCNumber to respond (in step2 ).SMS GMSC useMAP MT-Forward-SMCall message willSMSMessage delivery (in step3 )arriveMSC. Except that the user tries to terminateSMSBeyond the message, the steps4to10Same as the steps in the section on calls terminating at the mobile station above2to8Same; therefore, only the signaling channel is necessary.
Next,MSC 4420Will be encapsulated inCP-In the data messageSMSMessage sent (in step
11)arriveINC 4415.INCuseGA-CSR DLDirect delivery to relay the message (in step
12)arriveFAP 4410o FAPUse existingRRCConnect via the air interfaceCP-Data message relay (in step13)arriveUE 4405 ο AsSM-CP ackPart of the process,UETowardsFAPConfirm (in step14 ) CP-data
200780043341.5 The first reception.FAPRelay the confirmation (in step15)arriveINC.INCuseRANAPSend the message directly to forward the confirmation (in step16)arriveMSC.
UEUpSMSEntity via another CP-Data message (response) pairSMSMessage to confirm (in step17),The other CP-The data message is sent over the air interface toFAP.FAPWill be encapsulated inGA-CSRULDirectly pass the response in the messageCP-Data message relay (in step18 )arriveINC» INCuseRANAPDirect delivery of the message will respondCP-Data message forwarding (in step 19)arrive MSCo Next,MSC 4420existMAP-MT-Forward-SMReturn result message toSMS GMSC 4425Send response (in step20).GMSCRelay the response toSMSC» MSCTowardsINC ) Confirm (in step21) CP-Data reception.INC 4415willCP-data-ACKRelay (in step 22 )arrive FAPo Next,FAP4410Through the air interfaceCP-data-ACKForward (in step23)arrive UE 4405.MSC 4420Will indicate the request for the release of session resourcesIuRelease message sending (in step 24)arriveINC4415.SCCPThe connection identifier is used to determine the corresponding session.
INC 4415Then release (in step25 ) Leads to theFAPofGA-CSR connect.FAPRelease (in step26)forUEThe corresponding radio resources.INCexistIuIn the release complete messageMSCConfirm (in step27)freed. andINCandMSCAssociated with the callSCCPThe connection is released.
XI.The transparent support of emergency services to emergency services is a key adjustment requirement.FemtoCommunity emergency service support capabilities include support for flexibleUMTS-FemtoCommunitySAIMapping andINCAssign functional support. This makes it possible toFAPAssigned toINC,That is, in turn, connect to be able to route calls to FemtoIn the community service areaPSAPofMSC. This can also enable service providers to define alignment with the macro network service areaFemtoCell service area to adjust the existing service area-basedPSAPRouting method.
FemtoThe cell emergency service support capability also includes the use of enhanced service access control functions to support retrieval and storage from external databasesFAPlocation information.FemtoCommunity emergency service support capabilities further include, supportRANAPPosition report processing, through this processing,INCDuring emergency call processingMSCreturnFAPlocation information. Some embodiments do not support theFAPFrom unauthorizedUEEmergency call (due to specificFAPService access control).
UMTS-FemtoOne of the functions of cell mapping processing is to useFemtoCommunityUEPlace
200780043341.5 Call assignmentFemtoCommunity service area.FAP,During registration, provide information about macro coverage (such as macroLAI, Macro3GCommunity-idEtc.), the macro override can be mapped toFemtoCommunity service area identification (SAI ). ShouldFemtoCommunitySAICan be used to support the routing of emergency calls to the correctPSAPAbility; that is, based onSAI. However, in order to satisfy the need to route emergency calls to the correct PSAPIn fact, there are two feasible methods: (1) Based on service area (ie,SAI) Routing, and (2) Location-based routing.
A. Service area-based routing Due to service area-based routing,PSAPThe routing decision is based on theSAIService area code within (SAC)of. picture45The routing scenarios based on the service area of some embodiments are shown. As shown in the figure, the user is usingFemtoPre-occupiedUE 4505Issued (in step1)Emergency call. UEBuild (in step2)andFAPofRRCThe connection is established because of an emergency call.
After receiving the request from the upper layer,UEwillCMService request (itsCMThe service type is set to emergency call establishment) to send (in step3)arriveFAP4510.FAPPerform as described in the previous sections (in step4 )andINC 4515ofGA-CSRConnection establishment processing (the reason for establishment indicates an emergency call).
FAP4510Then useGA-CSR ULDirect messaging willCMService request forwarding (in step5fallINC 4515oINC 4515useRANAPinitialUEMessage establishmentMSC 4520 ofSCCPConnect and putCMService request forwarding (in step6)arriveMSC4520. This initial message includes theFAPLocation area (LAI) And service area (SAI) Relevant information.
MSC4520,INC 4515andUE 4505Continue (at step7 ) Call establishment signaling.MSC Call basedUEService area to determine the servicePSAP,And route emergency calls (in step8) To the appropriatePSAP. existUEandPSAPExchange other signal messages betweenUEAnd appropriate servicePSAPEstablished between (in step9)Emergency call.
B. Location-based routing One of the disadvantages of service area-based routing is that it will need to be based onPSAPRouting requirements will FemtoThe cell service is divided into multiple service areas. The location-based routing method eliminates this limitation. Location-based routing is also calledΧ/YRoute or use the route of the location, and be in the location service (LCS );Functional descriptionStage 2, 3GPP TS 23.271Defined in. Some embodiments support location-based routing, while other embodiments do not support location-based routing.
XII. FEMTOCommunity safety
200780043341.5 NS
GAN FemtoThe cell supports security mechanisms at different levels and interfaces, as shown in the figure46Shown. As shown in the figure, the security mechanism passesUpinterface 4605Protect inFAP4610andGANC SeGW4615 The signaling, voice, and data service flows between them are protected from unauthorized use, data manipulation, and eavesdropping; that is, it supports authentication, encryption, and data integrity mechanisms.
The authentication of users by the core network takes place at MSC/VLRorSGSN 4620andUE 4625Between and rightGANC 4640transparent.UE 4625andFAP 4610The air interface between is protected by encryption (decoding) and integrity check. In some embodiments, the use of encryption for the air interface is optional.
allowablePSAnother application-level security mechanism is used in the domain to ensureFAP 4605And application server4630End-to-end communication between. E.g,FAPallowableSSLRun on sessionHTTPAgreement to guaranteewebAccess.
Depend onFAP 4605andGANC-SeGW 4615Secure tunnel between (e.g.,IPSecTunnel) to protect throughUpinterface 4605existFAPandGANCAll signaling services and users sent between -Plane services, which use the same mechanism as specified in the following standards to provide mutual authentication (usingSIM orUSIM Credentials), encryption and data integrity:3G security; Wireless Local Area Network ( WLAN) interworking security> 3GPP TS 33.234 standard'Hereinafter referred to asTS 33.234standard. useFAP4610andGANC 4640Single secure tunnel between, enabling multipleUE 4625 (For brevity, the figure46Only one is shown in) andFemtoThe cell itself (e.g.,FAPSignaling or whenFAPuseFAPIMSIWhen supporting local services,FAPThe signaling and user plane use the same IPSectunnel). useFAPandGANCSingleIPSec The advantages of tunnels include makingSeGWIt is not necessary to support a large number of secure tunnels.
A.Authentication In some embodiments,UpInterface supportUMTSVoucher pairFAPaboutGANCThe ability to perform authentication (for the purpose of establishing a secure tunnel). Will useIKEv2insideEAP-AKA orΕΑΡ-SIMTo executeFAPandGANCBetween authentication.
FAPandGANC-SeGWEstablished to protect signaling services and users-Security association for flat (voice and data) services. The protocol used for authentication isIKEv2<sub>o</sub>Mutual authentication and key generation are made by EAP-AKAorΕΑΡ-SIMwhich provided.
The basic elements of these processes are as follows. andGANC-SeGW ofFAPConnection is initiated by IKEv2Initial exchange (IKE_SA_INIT ) And initiated. As a result of these exchanges, start EAP-AKAorΕΑΡ-SIMhandle. existFAPandAAAServer (it has been connected to
200780043341.5 NS
AuC/HLR/HSSTo retrieve user information) between execution, for only havingSIMofFAPOr haveUSIMofFAP (But does not haveUMTS AKAcapableΕΑΡ-SIMhandle. existFAP andAAAExecute between servers, used to haveUSIMAnd haveUMTS AKAcapableFAP of EAP-AKA handle.GANC-SeGW act as EAP-SIM/EAP-AKA The relay of the message.
whenEAP-AKA/EAP-SIMWhen the processing has been successfully completed, you can continueIKEv2Process to complete it and guaranteeFAPandGANC- SeGWThe signaling channel between. Then,FAPYou can continue to perform discovery or registration processing. The following subsections show the use ofEAP-AKA/EAP-SIM Authentication signaling flow.
1.Used for authenticationΕΑΡ-SIMDeal withExtensible Authentication Protocol Method for GSM Subscriber Identity Modules (EAP-SIM) , IETF RFC 4686 Stipulated in ΕΑΡ-SIM Authentication mechanism. This section describes how toFemtoThis mechanism is used in the cell. picture47Shows some examples of ΕΑΡ-SIMAuthentication processing. as the picture shows,FAP 4705Connect to UniversalIPConnect to the network and go through DNSQuery fetch (in step1) Default or serviceSeGWofIPaddress. In response,DNS server4710Return (in step2 ) SeGWofIPaddress.
Next,FAP4705Start by (in step3a-3c ) IKE_SAoneINITSwap to initializeIKEv2Authentication processing. By message from3 (IKE_AUTHThe first message exchanged) omit AUTHPayload to indicate the need to useΕΑΡ,And the composition of the initiator identity conforms to the network access identifier specified in the following standards (ΝΑΙ)Format:The Network Access Identifier, IETF RFC 2486,Hereinafter referred to asIETF RFC 2486,The identity of the initiator includesIMSIAnd should useEAP-SIMInstructions.
Next,GANC-SeGW 4715willΕΑΡresponse/Identity message sent (in step4)arrive ΑΑΑserver4720,Including the identity of the initiator, and the identity of the initiator is included in the thirdIKE News.NAILeading digits of (leading digit)instructFAPWant to useΕΑΡ-SIM» AAA server4720Identify the user as a pair based on the received identityEAP-SIMCandidates for authentication and verification based on order information should be usedEAP-SIM.Then,AAAwillΕΑΡask/SIMStart packet transmission (in step5)arriveGANC-SeGW4715<sub>O</sub>
GANC-SeGWwillΕΑΡask/SIM-Start packet forwarding (in step6)arriveFAP.FAP Choose fresh random numbersNONCE_MT. This random number is used in network authentication.FAPTowards GANC-SeGWSend (in step7 ) ΕΑΡresponse/SIM-Start grouping,includeNONCE_MT.
GANC-SeGWwillΕΑΡresponse/SIM-Start packet forwarding (in step8 )arriveAAAservice
200780043341.5 The first device.AAAserver4720based onIMSIfromHLR 4725Request (in step9 ) Authentication data. AAAThe server can be used insteadHLRThe retrieved cache triples (triplets) To continue the authentication process.
Optionally,AAA 4720fromHSS/HLR 4725Receive (in step10 ) User subscription and multiple triples.AAAThe server is ordered by the user and/Or fromFAPReceived instructions to determine which will be usedΕΑΡmethod(SIMorΑΚΑ). In this sequence diagram, supposeFAPholdSIMAnd will useEAP-SIM.
ΑΑΑServer formulation has multipleRANDQuestioningEAP-SIM/Question, andAAA The server includes the message authentication code (MAC),Its master key is based on the associatedKcKey and NONCE_MTCalculated. can useΕΑΡ-SIMThe generated key material is used to select and protect (ie, encryption and integrity protection) the new re-authentication identity.AAAServer atΕΑΡask /SIM-The challenge messageRAND,MACAnd re-authenticate the identity sent (in step11 )arrive GANC-SeGWo GANC-SeGWwillΕΑΡask/SIM-Challenge message forwarding (in step12 )arrive FAP, Every time for every receivedRAND, FAPRun (in step12) NSecond-rateSIMmiddle GSM A3/A8algorithm. This calculation givesNPieceSRESandKcvalue.FAPUse the newly derived key material to calculate its network authenticationMAC,And check it with the receivedMACAre they equal. ifMACIncorrect, the network authentication has failed andFAPCancel the authentication. only atMAC Under the right circumstancesFAPOnly then continue the authentication exchange.FAPCovered withNPieceSRESResponse connectedΕΑΡThe new key material of the message to calculate the newMAC οIf re-authentication is receivedID,but FAPStore theIDFor future authentication.
FAP 4705Will include the calculatedMACofΕΑΡresponse/SIM-The challenge is sent to (in step 14 )GANC-SeGW 4715.GANC-SeGW will ΕΑΡ response/SIM-The challenge message is forwarded to (in step15 ) AAAserver4720.AAAServer verification (in step16) Its responseMAC Copy of and receivedMACequal.
If the steps16The comparison is successful, thenAAAServer willΕΑΡThe success message is sent to (in step17 ) GANC-SeGW» AAAThe server is included in the lower layerAAAProtocol message (that is, not inΕΑΡRank) forFAPandGANC-SeGWConfidentiality and/Or integrity-protected derived key material.
GANC-SeGWuseΕΑΡSuccess message notification (in step18 ) FAPSuccessful authentication. Now, ΕΑΡ-SIMThe exchange has been successfully completed,IKESignaling can be completed (in step19).FAPand
200780043341.5 NS
GANC-SeGWThe security association between has been completed andFAPCan continue to executeFemtoCell discovery or registration processing.
2.Used for authenticationEAP-AKADeal withExtensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA) , IETF RFC 4187 Stipulated in EAP-AKAAuthentication mechanism. This section describes how toFemtoThis mechanism is used in the cell. picture48 Showing some embodimentsEAP-AKAAuthentication processing. as the picture shows,FAP 4805Connect to Universal IPConnect to the network and go throughDNSQuery fetch (in step1 ) Default or serviceSeGWofIPaddress.DNSserver4810Return (in step10) SeGWofIPaddress.
<sub>|</sub> FAP 4805Start byIKE_SA_INITSwap to initializeIKEv2Authentication processing (step 3a-3c). It passes from the message3 (IKE_AUTHThe first message exchanged) omitAUTHPayload to indicate the need to useΕΑΡ,And the composition of the initiators identity conforms toIETF RFC 2486The network access identifier specified in (ΝΑΙ) Format, which includesIMSIAnd should useEAP-AKA Instructions.
Next,GANC-SeGW 4815willΕΑΡresponse/The identity message is sent to (in step4) ΑΑΑserver4820,The message includes the thirdIKEThe identity of the initiator contained in the message.NAI Leading digit indicatorFAPWant to useΕΑΡ-ΑΚΑ» AAABased on the received identity, the server recognizes the user asEAP-AKACandidates who are authenticated on the Internet, and based on the order information to verify that they should be usedEAP-AKA.AAAServer slaveHSS/HLR 4825Request (in step5 ) User profile andUMTSAuthentication vector (one or more), if inAAAThe server cannot get these words.
Optionally,AAAfromHSS/HLRReceive (in step6 ) User ordering andUMTSAuthentication vector (one or more).UMTSThe authentication vector consists of a random part (RAND ), authentication token (AUTN ), the expected result part (XRES) And for integrity check (IK) And encryption (CK) Is composed of the session key.AAAThe server is ordered by the user and/Or fromFAPReceived instructions to determine what will be usedΕΑΡmethod(SIMorΑΚΑ ). In this sequence diagram, supposeFAPHold what will be used USIM and EAP-AKA.
Next,AAAserver4820useRAND,AUTN,Expressed by formulaΕΑΡ-ask /ΑΚΑQuestion, andΑΑΑserver4820Including the message authentication code (MAC),The master key of this code is based on the associatedIKandCKCalculated. can useEAP-AKAThe generated key material is used to select and protect (ie, encrypted and integrity protection) the new re-authentication identity.AAA
200780043341.5 The server is inΕΑΡask/ΑΚΑ-Lieutenant generalRAND,AUTN,MACAnd re-authenticate the identity sent to (in step7) GANC-SeGW 4815.
GANC-SeGWwillΕΑΡask/AKA-The challenge message is forwarded to (in step8 ) FAP.FAP existUSIMRun on (in step9 ) UMTSalgorithm.USIMverifyAUTNWhether it is correct and thus authenticate the network. ifAUTNIncorrect,FAPReject authentication. ifAUTNis correct,USIMcalculateRES. IKandCK.FAPUse coverageΕΑΡThe new key material for the message (ΙΚandCK) To calculate the newMAC. If re-authentication is receivedID,butFAPStore theID Used for future authentication.
Then,FAPWill include the calculatedRESandMACofΕΑΡresponse/AKA-The challenge is sent to (in step10) GANC-SeGW» GANC-SeGW willΕΑΡresponse/AKA-The challenge message is forwarded to (in step11) AAAserver.
AAAServer pair receivedMACPerform verification (in step12 ) AndXRESAnd receivedRESCompare. If the steps12The check result is successful, thenAAAServer willΕΑΡThe success message is sent to (in step13 ) GANC-SeGW. At the bottomAAAIn the protocol message (that is, not in theΕΑΡgrade),ΑΑΑServer includes forFAPandGANC-SeGW Confidentiality and/Or integrity-protected derived key material.
GANC-SeGWuseΕΑΡSuccess message to notify (in step14 ) FAPRegarding authentication success. Now,ΕΑΡ-SIMThe exchange has been successfully completed,IKESignaling can be completed (in step15).FAP andGANC-SeGWThe security association between has been completed, andFAPCan continue toFemto Cell discovery or registration processing.
3.Fast re-authentication When frequently performing authentication processing, especially when there are a large number of connectedFemtoWhen the cell access point, performing fast re-authentication can reduce the network load caused by the authentication. Quick re-authentication processing allowedAAAThe server authenticates the user based on the key derived from the last complete authentication process.
For example, when due toFAPofIPAddress change and create a new oneSATime,FAPandGANC-SeGW The processing for quick re-authentication can be used toFAPPerform re-authentication. Quick re-authentication is passedEAP-AKAwhich provided,And don't useUMTSalgorithm.FAPcan useIKE_SA_INIT Re-authentication inID. The decision to use fast re-authentication processing is made byAAAMade by the server.
The basic elements of these processes are as follows.FAPWas connected to before using itGANC-SeGW Initiate a newSA,And inIKE_SA_INITUse re-authentication in exchangeID (In the previous complete inspection
200780043341.5 Re-authentication received during the processing of rightsID). As a result of these exchanges, startEAP-AKA handle.AAAServer andFAPRe-authenticate each other based on the key derived from the previous complete authentication.
B. Encryption passedUpAll control and user plane services carried out by the interface shall pass throughIPSecTunnel to send, theIPSecThe tunnel is established as a result of the authentication process. Encryption should use negotiated encryption algorithm (negotiated cryptographic algorithm ),Based on the core network strategy, by GANC-SeGWMandatory.
FAPandGANC-SeGW A security association is established, and all services are sent through the security association. Apply a single negotiated encryption algorithm to the connection.
1.The establishment of the security association is after the authentication process,FAPShould beGANC-SeGW (which is,INCPublicIPInterface) request on the protected networkIPaddress.FAPShould be inFAPandGANC-SeGWBuild one betweenIPSecSecurity Association (SA).
FAPShould initiateSAIs created; that is, it should act as a traffic selector (Traffic Selector ) The initiator of the negotiation. Flow selector (TS) In the agreementIDThe field should be set to zero, indicating the protocolIDirrelevant.TSimiddleIPThe address range should be set to be assigned toFAPAddress (in theGANC-SeGWWithin the protected network).TSrmiddleIPThe address range should be set to 0.0.0.0-255.255.255.255.FAP and GANC-SeGW Should use IKEv2 Mechanism to detect NAT,NAT Through (NAT traversal) And keep alive.
passFAPandINCbetweenUpAll control and user plane data carried out by the interface shall pass throughSAAnd be sent. The encryption mode is negotiated during connection establishment. existSADuring the establishment of FAPInclude a list of supported encryption algorithms (asIKEPart of signaling), the list includes IPSecProfile (IPSecprofile Mandatory and supported optional algorithms defined in ), andNULL encryption.GANC-SeGWChoose one of these algorithms and send it toFAP.
When appliedNULLWhen encrypting, both control and user plane services are sent in an unencrypted state. For example, when generalIPAccess to the network andGANCWhen the connection is under the control of the operator, this configuration can be selected. For these two configurations, the integrity algorithm is the same, that is, non-encrypted services are also integrity protected.
C. IKEv2 'S profile (Profile) In some embodiments, forFemtoCommunity systemIKEv2The profile is similar toTS 43.318
200780043341.5 The profile defined in the first standard.
D. IPSec ESP In some embodiments, the profile is used forFemtoCommunity systemIPSEC ESPThe profile is similar toTS 43.318The profile defined in the standard.
E. Safe Mode Control Chart49The message flow for security mode control in some embodiments is shown. as the picture shows, CN ( VLR/SGSN) 4920andUE 4905useAKAProcessing execution (in step1 ) Mutual authentication.CNAuthentication is asCNProcessing comes fromUEbeginning ofL3The result of the message, byCNInitiated.
When the authentication is successful,CNwillRANAPThe safe mode command message is sent to (in step2))GANC. The message includes the integrity key (IK) Key, encryption (or password) key (CK), user integrity algorithm (UIA),And the encryption (or user encryption) algorithm to be used when encoding the password (UEA).
In some embodiments,GANCStore encryption keys and integrity keys and algorithms.GANC With specificUE IMSIThe associated encryption key and integrity key and algorithm GA-CSRThe safe mode command is sent to (in step3) FAP 4910.FAPFor specificUEStore encryption keys and integrity keys and algorithms (in step4 ).FAPIt should be ensured that these keys cannot be used by third-party applications orFAPAccess to any other modules on the computer. In addition, these keys should not be stored on any permanent storage.CKandUEAIs used to pass encryptionFAPandUEBusiness to protectFAPandUEThe air interface between.IKandUIAIs used to ensure thatFAPandUEThe integrity of messages exchanged over the air interface, for example, by making sure that the message has not been changed. In some embodiments,UIAandUEAIt is a software method executed by the processor.
FAPGenerate random numbers (FRESH ) And use the integrity key (IK ) And the integrity algorithm (MAC-I) To calculate the downlink (ie, fromFAParriveUE ) Message authentication code (MAC ), And the security mode command and the calculated message authentication code for integrity (MAC-I)and FRESΗsend toU(In steps5 )UE 4905» FRESHVariables represent random numbers or3G Security; Security architecture, 3GPPTS 33.102 Standard (hereinafter referred to asTS 33.102 The random number defined in the standard (nonce).UECalculate locally (in step6) MAC-I (Expected MAC-IorXMAC-I) And verify (in step6) Downlink receivedMAC-IAre they the same.ΌΈBy using the indicatedUIA, StoredSTARTGeneratedCOUNT-IAnd as TS 33.102Received as defined in the standardFRESHParameters to calculate information about the received messageXMAC-LFrom this message onwards, a downlink integrity check is performed. For slaveFAPTowards
200780043341. 5 NS
UE (Downlink message) All subsequent messages sent, using similar steps5to6Steps to ensure the integrity of the message.
When successfully verifiedMACHour,UEUse the safe mode to complete the command postback response (in step7) And also send for uplink (ie fromUEarriveFAP) NewsMAC-L FAPCalculation (in step8 ) Uplink messageXMAC-I,And verify (in step8 ) ReceivedMAC-IIs it with the calculatedXMAC-Isame. The uplink integrity check starts from this message onwards. For slaveUEsend toFAPFor all subsequent messages (uplink messages), use steps similar to7to8Steps to ensure the integrity of the message.
MAC-IIs calculated by the senderMAC-I, XMAC-IIs the expectation calculated by the receiverMAC-I. As mentioned above, this calculation is done for a given message using algorithms and other variables that only the sender and receiver know. This prevents the middleman (man-in-the-middle )attack' Because the entity in the middle will not have calculationsMAC-IThe necessary information required, so the message cannot be tampered with.
When successfully verifying the uplinkMACHour,FAPwillGA-CSRThe safe mode complete command is sent to (in step9) GANCo GANCVia correspondingRANAPThe message relays the safe mode completion command to (in step10) CN.
F.Core network authentication is based on the core networkAKAThe authentication is provided for mutual authentication with the network.AKAProcessing is also used to generate encryption keys (encryption and integrity), which then provide confidentiality and integrity protection for signaling and user data. The basis of the mutual authentication mechanism is the master keyK(Permanent secret, its length is128Bits), the master keyKIs user'sUSIMShared with the home network database. Encryption key (Ck) And the integrity key (Ik) Is from the master keyKExported.
picture50Shows some embodiments for mutual authenticationAKAhandle. As shown in the figure, when UE 5005CorrectFemtoCell access point5010When pre-occupied, it givesCNInitiated (in step1 ) Location update request (Location Update Request (or Location Updating Request)).INC 5015willRANAPThe location update request in the message is forwarded to (in step2 )VLR/SGSN 5020.
This triggered VLR/SGSNAuthentication process in and its sending (in step3 ) Authentication data requestMAPMessage to the home environment (HE) 5025Authentication Center in (AuC ).AuCincludeUE Master key and is based onIMSIof,AuCWill be specificUEGenerate an authentication vector. In response to authentication dataMAPIn the message, the vector list is sent back (in step4 ) VLR/SGSN.
VLR/SGSNSelect from list.(In steps5 ) An authentication vector (each operation of authentication processing
200780043341.5 Line only needs1Vectors)° VLR/SGSNThe user authentication request (AUTREQ) The message is sent to (in step6) INC»The message also includes two parameters, namely,RANDandAUTN (From the selected authentication vector).
INC 5015existGA-CSR DLLieutenant GeneralAUTREQThe message is relayed to (in step7) FAP5010» FAPThrough the air interfaceAUTREQForward to (in step8 ) UE. UEUpUSIMInclude master keyK,And use that master keyKAnd parametersRANDandAUTN As input,USIMexistAuCPerform similar calculations in (computation resembling) Authentication vector generation. According to the generated output,USIMVerification (in step9) Is the correctAuC Generated AUTNo
USIMThe calculation is also generated (in step10 ) RES,ShouldRESSending toCNThe authentication response message is sent toCN.FAPForward the authentication response to (in step11 ) INCo INCexistRANAP The message will respond as well asRESParameter relay to (in step12) CNo
VLR/SGSN (In steps13 )willUEresponseRESWith expected responseXRES (It is part of the authentication vector) for comparison. If they match, the authentication is successful. Then,CNCan be initiated (in step14) Safe mode processing (as above"As described in the Security Mode Control section) to distribute the encryption key toINC.
G. FemtoThe misappropriation of services in the community is by definition,FAPHas for andUECommunication radio interface (Uu) And the network interface connected to the mobile station network ( Up ).FAPrelayUEThe messages between the core network and the core network can be eavesdropped and intercepted.FAP,In the case of a leak, a disgraceful person in the middlemans safety exposure is in normal operation, the macro cell network guidesUETo scanFemtoCommunityUTRAAbsolute radio frequency channel number (UARFCN) And scrambling code (SC),In order to beUEdetectedFAPWhen the radio is covered,UECan try toFAPPreemption. Hope willFAP{UARFCN, SC}Configure in macro network RNCList of neighboring cells in order toRNCCan beUEProvide the list of neighboring cells so thatUEPerform scanning of neighboring cells and final cell selection for neighbors who are better for camping.UEPerform a location update and provide its identity (orIMSI,EitherTMSI),Want to authenticate it, and then proceed toFemtoThe cell is pre-occupied. This is exactlyUEAccess to the network authorizedFAPWhen you want to happen.
whenFAPWhen secrets are leaked or deceived, thenUEMay expose themselves and be stolen services. when UETowardsFAPWhen providing his identity,FAPCan pretend to mobile station networkUE. normally,UEAuthentication
200780043341.5 The first can prevent this kind of identity theft, but in the core network andUEDuring the communication betweenFAPVictimizedUERelay the authentication request to make the authentication fail.
UEBelieve that you are being authenticated by the network and provide the correct authentication response toFAP FAP Send the correct response to the core network, and now the core network believesFAPHas been authenticated. Between authentication requests initiated by the network,FAPMay pretend to be victimizedUEThe mobile station network requests and receives monthly services. For example, now, fromFAPThe call may be victimized byUECome to pay. under these circumstances,UMTSThe signaling message integrity mechanism may not be helpful for this, because theUEandFAPIntegrity protection is provided between.
due toFAPHave end users and interact withGANCCommunication, leaking or fraudulent FAPMay try to bypassUMTSSecurity structure. FraudulentFAPIs typicalUEandCNBetween the man in the middle attacker. In the absence of adequate network security verification and enforcement of access rules, fraudulentFAPCan impersonate the victimUE,And use the victimizedUEIdentity to use mobile station network services.FAPIt is classified into the following three access control modes: closed access, semi-open access or open access.
In the case of closed access, pass the givenFAPTo the completeFemtoAccess to cell services is restricted to closed user groups. In the case of semi-open access, restricted access is provided to all users. Users who are not members of the closed group are allowed to pass semi-openFAPTo receive incoming calls andSMS. In addition, users are also allowed to use semi-open access modeFAPTo make an emergency call. All other services such as outgoing calls are blocked. Finally, in the case of open access, all users of a given operator are allowed to passFAPTo complete service access. In some embodiments, the following techniques are used to protect those working in one of the above modesFAPAtUEImpersonation and misappropriation of services.
1.Closed access pointFAPIn, asFAPOf members of the private user groupUEWon't suffer becauseFAPAnd in the private user groupUEIs linked by order processing-GANCCan enforce network-based service access control to prevent victimizedUEEnter fraudulentFAPThe trap. ifUENot fraudulentFAPA member of the private user group,GANCWill refuse toUEService access. This means fraud preventionFAPUse victimizedUETo steal the service.
GANCWill also be in eachUEThe transaction executed under the registration context is strictly bound to the initial authorizedUEIdentity to prevent fraudFAPUse victimizedUEIdentity through authorizedUEContext to piggyback(piggybacking)information. Strict binding requirementsGANCTrack eachUEBody
200780043341.5 First share, even when it was assigned for the confidentiality of the users identityTMSIandP-TMSITime. The following describes in more detail the prevention of service theft in the closed access mode.
2. Semi-open and open access points are only fraudulent on semi-open and open access pointsFAPImpersonating a victimUEPossibility. VictimizedUEWould be the network allowing fraudulentFAPPreempt but notFAPOf members of the private user groupUE»For theseUE,The possibility of misappropriating services does exist because of fraudulent FAPMotivated to record its own usage expenses on the victimizedUEOrder on the account.
It should be noted that the case of service misappropriationUEPreempt the fraudulentFAPIt can happen only when. FraudulentFAPcan be used asUETo the core network (CN) Authenticate and then impersonateUE TowardsCNRequest service. As long as the victimUEFraudulentFAPKeep preemption,FAPYou can continue to send authentication requests and continue to impersonate.
For semi-openFAP,By definition, prevention is notFAPOf members of the private user groupUE Initiated external connection service (outgoing service ). Enforcing semi-open access control based on the network can prevent fraudFAPImpersonate victimUETo steal the service. However, when the victimUEPreemptive fraudFAP FraudulentFAPCan block the victimUECall in, or eavesdrop on the conversation. Half openFAP Situation and opennessFAPThe situation is similar, as described below.
For openFAP,By definition,GANCCan't be against anyUEUse mobile station network services to set restrictions. It is also impossible to determine the origin of the call every time you callUELegally FAPImpersonate victimUEMade. This makes the network enforceUEAccess control is preventingUEImpersonation is invalid. Prevention methods must focus on ensuring that only the real unmodifiedFAPTo be granted open access.
3. Enhanced security solutions for open access points openFAPMay be abused through the following two situations: (1 ) Completely replace the real one with a fraudulent deviceFAP,and(2) From an authorized seller to modify theFAPExisting software running on it.
a) Detect the realFAP Technology based on public and private keys can be used to prevent fraudulent devices from replacing realFAP. In this solution, the requirementFAPaccompanyingUMAThe registration message provides the message authentication code (MAC ),The message authentication code (MAC ) Is calculated based on the vendors private key. useAAAofGANCCan be comparedUMAOn the registration messageMACAnd useFAPCalculated by the sellers public keyMAC,To verifyUMAOn the registration messageMAC. Only the realFAPTo be able toUMAProvide the correct in the registration messageMAC ο
200780043341.5 The details of the processing are as follows. EachFAPSeller generates private/Public key pair. The public key is stored in the networkFAPIn the database. whenFAPTowardsGANCWhen registering,GANCBy including in the questionRANDNumber to send the registration challenge message.FAPSend a challenge response and include the one generated using the vendors private keyMAC (Message authentication code).MACIs used forSHA1 Generated by the standard algorithm.
GANCviaS1The interface will random numbers and generatedMACRelay toAAA.AAAfromFAP The database retrieves the public key and calculates its expectationsMAC. If calculated locallyMACSame as received on the network, thenAAAVerified FAPit is true. ifAAAmiddleMACThe check fails and the registration is rejected, thereby preventing the use of theGANCAccess services. It should be noted that all purchases from the same sellerFAPHave the same private key, so eachFAPHave the same reflection. The private key is never stored in an unencrypted manner. This detection method must be combined with the following methods to protect the private key fromFAPWas extracted.
b)Ensure unmodifiedFAP
FAPThe hardware can implement software authentication technology to ensure that only trusted and authorized software can be allowed inFAPRun on hardware. Some embodiments implement the following software authentication techniques. Boot loading(bootloader)Software, which is responsible for establishing the initial state of the system so that it can load the correct operating system and application programs, and will control the download and authorization of the software. The bootloader software must be absolutely trusted, so the software needs to be immutable. Can be passed, for example, inROMorOTPBoot loader software is implemented in flash memory to meet this requirement.
Use the private key corresponding to each vendor,FAPSign the loaded software. The bootloader software may be responsible for verifying the signature using the vendor's public key. The result of the signature check being a failure will prevent the fraudulent software from running successfully. It should be noted that the public key can be passed to the bootloader software via a signed certificate, or the public key can be directly stored locally in the bootloader.
The above technology prevents the software from being loaded into by anyone other than the sellerFAPOn the hardware. Only the seller possesses the private key necessary to sign the software to pass the software authentication.
4.Advanced processing diagram51Can lead to fraudFAPAdvanced handling of misappropriated services. The following pairsFemtoThe description of cell service misappropriation processing makes the following assumptions:(1 )FraudulentFAPIs closedAP,which is,Femto Cell service access is limited toUEConfidence list(In this example, only the identityIMSI-1/TMSI-1 AssociatedUE-1Allowed to use fraudulentFAPconductFemtoCommunity service access),(2 )As FAPAnd associatedUEPart of mutual trust between closedAPHas implied security.
200780043341.5 First closedAPAct by the network inUEUse service access control when registering (SAC ) To ensure that (3 ) VictimUEAnd identityIMSI-2/TMSI-2Associated and does not allow the fraudulentFAPOn the service, and (4), fraudTAPVictims that have been leaked and attempted to use outside the confidence list UETo steal the service. Although the figure51to53Shows the circuit-switched resources (CSR) For the relevant steps, those skilled in the art will be able to exchange resources (PSR) Apply the technology.
As shown51Shown, authorizedUE5110Build (in stepla) And what it preemptsFAP5115 ofRRCconnect.UE5110TowardsCN5130Start (in steplb ) Location update processing.FAP5115 Will intercept location update requests and try to pass existingIPSECTunnel willUE 5110Register to the associated serviceGANC 5120. If usingTMSICompleted the location update,FAP 5115Can be requested (in steplc) And receive (in stepId) UE5110ofIMSI ,Because yesUEThis is required for initial registrationIMSL Next,FAP 5115useUEDedicatedTCPConnect, send via (in step2 ) GA-RCRegister request to tryUE 5110Register toGANC 5120superior. The message includes: (1 ) Registration type: indicates that the device being registered isUE, (2) GeneralIPAccess network attachment point information:ΑΡ-ID, (3) UE identity:UE-IMSI,as well as(4) FAP identity:FAP-IMSL GANC 5120Will passAAAserver5125,Use the information provided in the registration request toUE 5110To authorize (in step2a-2c )» AAAserver5125The authorization logic on the will also check UE 5110Is it allowed to use specificFAP 5115conductFemtoCell access.
whenGANC 5115When accepting registration attempt,GANCuseGA-RCRegister to accept and respond (in step3 ).FAP 5115Update locationNAS PDUPackage (in step4 )existGA-CSR ULIn direct message delivery, theGA-CSR ULPass the message directly via the existingTCPConnection is forwarded to GANC 5120.
GANC 5120Establish a pathCNofSCCPConnect and useRANAPinitialUELocation update requestNAS PDUForward to (in step5 ) CNoWill useRANAPDirect message deliveryGANCandCNSend betweenUEAnd core network follow-upNASinformation. CN 5130Use standardUTRANAuthentication processing pairUE 5110Perform authentication (in step6 ).CN 5130Also initiated (still in step6)likeTS 33.102The standard security mode control process described in the standard, which leads to the use of specificUESecurity key {CK, IK}viaGANCIs assigned toFAP.
Next,CN5130Use send toGANG 5120The location update acceptance message indicates (in step7) It has received the location update and it will accept the location update.GANC 5120exist GA-CSR DLIn direct delivery, the message is forwarded toFAP5115. Next,FAPThrough the air
200780043341.5 The first interface relays location update acceptance to (in step9) UE5120.
At this time, authorized for specificUE-1Uses its credentials for the sessionIMSI-1existFAP 5115 andGANC 5120Is established between (in step10). Next, the victimUE5105,Fraudulent FAP 5115Nearby, found through the air interfaceFAP5115Will try to preempt the fraudulentFAP5115. This will triggerUE5105Build (in step11a) And fraudulentFAP5115ofRRCconnect. Then,UEWill go toCN5130Start (in steplib) Location update processing.FAP5115Location update requests will be intercepted. If usingTMSIComplete the location update, thenFAPWill request (in steplie) And receive (in steplid) VictimUE5105ofIMSL FraudulentFAPDon't try to be victimizedUE 5105Register toGANC 5120,But will reuseUE-1 5110Of existing authorized sessions (as in the steps10Described),viaGANC 5120Pass the message toCN 5130. It is important to note that if fraudulentFAPUse victimizationUECredentials (i.e.,IMSI-2) To try to victimizeUERegister, web-basedSACMay have rejected the registration request because of the victimUE-2 5105Unauthorized passage of that specific fraudulent FAP 5115useFemtoCommunity service.
FAP5115Update locationNAS PDUPackage toGA-CSR ULIn direct message delivery, theGA-CSRULDirect message viaUE-1 5110Of existingTCPThe connection is forwarded (in step13 )arriveGANC 5120.GANC 5120Build a path toCN 5130ofSCCPConnect and useRANAPinitialUELocation update requestNAS PDUForward (in step14 )arrive CN 5130. Will useRANAPDirect message deliveryGANC 5120andCN5130Send between UE 5105And core network5130Between subsequentNASinformation.
Next,CN 5130Use standardUTRANVictimizationUE-2Perform authentication (in step15). The authentication message isGANC 5120andFAP5115Transparently relay toUE5105.CN 5130Also initiated (in step15 )likeTS 33.102The standard security mode described in the standard controls the processing, which leads to the use of the victimΌΕSecurity key {CK, IK}viaGANCIs assigned toFAP.
When the authentication is completed,CN 5130Use location update to accept messages toGANC 5120Instructions (in step16) It has received the location update and it will accept the location update.GANC 5120exist GA-CSRDLForward the message in direct delivery (in step17)arriveFAP5115» FAP5115 Receive the location update through the air interface to be relayed (in step17) To the victimUE.
Now,CN5130Considering that it has passedFAP5115andGANC 5120To the victimUE5105 Has been authenticated and will accept from the victimUE5105Service requests, and no additional authentication is performed for a specific time window. During this time window, no additional authentication is performed for a given user,
200780043341.5 The time window is typicallyCN 5130Based on specific implementation to control.FAP 5115Use this time window and you can use the victim nowUE 5105Credentials and identity initiate service request,E.g,FAP 5115Can be used nowIMSI-2Starting from the mobile station as a user (MO) Call, resulting in deceptive expenses being recorded in the victimUEUnder the order name. Its important to note that evenCN5130 Decide on each service request from a given user (such as,MO) For authentication,FAP5115It can also relay the authentication message to the victimUE5105And successfully completedCN5130Authentication.
H. Used to preventFemtoThe mechanism of service embezzlement in the cell is disclosed in this section to protect the mobile network from the above-mentioned middleman embezzlement. GANC. For differentUEAt different levels, the risk of service misappropriation is different. For product purchase accounts through links (such as family planning (family plan))andFAPAssociatedUEYes, the risk of service misappropriation can be mitigated by designing a pricing plan that removes any stimulus that misleads the network.FAP It will only be able to steal the service from its own account.
For not andFAPAssociatedUE,The possibility of misappropriating services does exist because of fraudulentFAP Now I have the motivation to record the cost of my own use as the victimUEOn the account.GANCResponsible to prevent unrelatedUEquiltFAPcapture.GANCBy adding eachFAPRestrict to serve the defined association UEList to accomplish this duty. based onAAAPublic service access controlGANCProvided to start theUERestricted decision logic. EachUEAccess atUE UMAPassed during registration AAAIs separately authorized.AAAOnly in verificationUEandFAPAre connected andUEAccess comes from the same -IPAfter the address is passed andFAPidenticalIPSecTunnel authorizationUEAccess.GANCBy accepting or rejectingUEofUMARegistration request to enforceAAAAuthorization decision.
in addition,GANCRight fromUETo verify all subsequent communications to prevent fraudFAP Try to be victimizedUEThe control plane message is inserted into the previously authorized registration context. GANCmonitorTMSIandΡ-TMSITowardsUEDistribution so that it can transferUEWith the followingUE Any one of the identities is associated with:IMSL TMSIandP-TMSLThis allowsGANCEnforcement aboutUEAnd the communication between the core networkUE-FAPAssociation, regardless of whether control plane messages are usedUE IMSL TMSIorΡ-TMSITo address. The following two subsections describe the use of two different methods to prevent fraudFAPAttempt advanced handling of service theft.
I. Service theft prevention·Method1 picture52Showing some embodimentsFemtoMeasures to prevent theft of community services. step1-7With the above about figure51The steps described1-7same.GANC 5220Monitoring (in step8 )CN 5230 Assign a new temporary identity toUE5210,That is, forCSServicesTMSIAnd used forPSservice
200780043341.5 The firstP-TMSI,And createTMSIorP-TMSIWith specificUEThe association between the identities of the session. GANCWill use this information toUEFollow-up that originated on a dedicated sessionNASThe session identity of the layer message performs a security check.
GANC 5220useGA-CSR DLDirect delivery of the message will be fromCN 5230The received location update information is forwarded to (in step9) FAP5215<sub>O</sub> FAP 5215Relay location update acceptance to (in step10) UE5210<sub>o</sub> At this time, use its credentialsIMSI-1existFAP 5215andGANC 5220Established between (in step11 ) Authorized for specificUE-1Conversation. Next, the victimΌΕ 5205,Fraudulent FAP5215Nearby, found through the air interfaceFAP 5215Based on its internal cell selection logic to try to preempt the fraudulentFAP. This will triggerΌΈ 5205To build (in step12a) And fraudulentFAPofRRCconnect. Then,UE 5205TowardsCN 5230Start (in step12b) Location update processing.FAP5215Intercept location update requests. If usingTMSILocation update, then FAPWill request (in step12c ) And receive (in step12d) VictimUE 5205ofIMSI.
FraudulentFAP 5215Don't try to be victimizedUE 5205Register toGANC 5220,But will be reused (in step13 ) UE-1 5210Of existing authorized sessions (in the steps above11 Described), viaGANC 5220Pass the message toCN5230. It is important to note that if fraudulentFAP 5215Use victimizationUE 5205Credentials (i.e.,IMSI-2) To try to victimize ΌΈ5205Register, web-basedSACMay have rejected the registration request because of the victim UE-2 5205Unauthorized passage of that specific fraudulentFAP 5215useFemtoCommunity service.
Next,FAP 5215Update locationNAS PDUPackage toGA-CSR ULIn direct message delivery, theGA-CSR ULDirect message viaUE-Γ 5210Of existingTCPThe connection is forwarded (in step14 )arriveGANC 5220.GANC 5220Perform on the session identity (in step15 ) Security check. Because of the identity carried in the location update message, that is,IMSI-2,With the known identity of the session (as the identity used for registration and authorization)IMSI-1,Or as the steps above8describe GANC 5220LearnedTMSI) Does not match any of them,GANC 5220Ability to detect attempted service misappropriation.
GANCBy will be used forUE-1 5210The session is unregistered to prevent attempted service misappropriation. GANC 5220In the specific session (used forUE-1Of the authorized session) send a deregistration message to (in step16) FAP5215.
2.Service theft prevention-Method2 picture53Shows some examples ofFemtoPrevention of theft of community services. step1-15And on
200780043341.5 About the picture52The steps described1-15same. due toNAS PDUThe identity carried in does not match any known identity used for the session,GANC 5320Replace the identity in the location update message with the original authorized identity for the specific session, that is, useNAS PDUmiddleIMSI-1 To replaceIMSI-2.GANCBuild a path toCN 5330ofSCCPConnect and useRANAP initialUEThe message will be modified after the location update requestNAS PDUForward to (in step16) CN 5330.CN 5330Use the requestUE-1To receive the service request, and will associate the request withUE-1 5310User data (including bills, etc.) are linked.
XIII. FEMTOCell Service Access Control
FemtoCell Service Access Control (SAC ) And billing services are based onINCAnd one or more AAABetween serversS1interface. In the aboveU.S.Apply11/349,025Specifically defined in S1 Interface function.
FemtoThe goal of cell service access control is to provide operators with information based on real-time information from users andITThe non-real-time information provided in the system and service database to correctly implement itsFemtoTools for community service plans. Using this service strategy, the operator can implement a certain range of creative services and control applied to each user, which leads to any decentralizedFemto Acceptance or rejection of the cell session registration request. Mainly, the service strategy is used to identify whether the user's current access request meets the conditions of the service plan they have subscribed toο In some embodiments,FemtoCommunitySACIncluding discovery, registration and redirection functions, as well as enhanced service access control functions, such as based on reportedFAP MACAddress or adjacent macro networkUMTSCell information to limitFemtoCommunity service access.
Due to implementation reasons, it can beFAPTo execute localSAC (E.g:FAPCan use localSACTo quickly deny neither accessFemtoThe cell service is not allowed to pass the specificFAPAccessFemtoCommunity serviceUE ).
The key elements of the service access control design method are as follows:) There are two service access control configuration options: a) Basic service access control: not usedSI (INC-AAA ) Interface and byINCProvides a limited set of service access control capabilities.
i) INCResponsibleFemtoCell discovery, registration and redirection functions.
ii) UMTSarriveFemtoThe cell mapping logic and data are located inINCWithin; that is, the logic and data are used to support discovery, registration, and redirection functions, and are used to support specificFAPSAllocate service areas.
200780043341.5 NS iii) No users orFAP-Dedicated service access control.
b) Enhanced service access control: adoptS1Interface, andAAAProvide extended service access control features, including customer features required by service providers.
i) UMADiscovery, registration and redirection functions remain inINCsuperior.
ii) UMTSarriveFemtoThe cell mapping logic and data are kept inINCInside.
iii) AAASupports an interface to an external database server; for example, via LDAPv3.
iv) In the aboveU.S.Apply11/349,025The details of these enhanced service access control functions are defined in.
2) Start the enhanced service access control support function (ie,S1The service access control function of the interface) isINCConfiguration options; if activated,INCuseRADIUSForward the attributes received in the discovery and registration request toAAA. This allowsAAADo the following (for example):
a) Determine when to allow or denyUERegistration attempts (e.g., limit service to a singleFAP) b) Retrieve from an external databaseFAPLocation information and send that information toINC.
c ) Provide the billing rate indicator to theUMTSarriveFemtoCommunitySAICombined in the mapping processINCmiddle.
d) Indicates the turn-in to the user (hand-in),distribution(hand-out) Or the activation or deactivation of both.
A. UMTS-FemtoCell mapping
UMTSarriveFemtoThe cell mapping process includes the following:) UMTS-INCMapping (orINCOption) Provide the following functions: a) It allowsINCAs a supplyINCTo guide the mobile station to its designated default INC'o b) It allowsINCAs defaultINCTo direct the mobile to the appropriate serviceINC (For example, inFAPIn its normal defaultINCOutside the coverage area).
c) It allowsINCjudgeUMTSIs the coverage areaFemtCommunity-Restricted, and if so, denial of service.
) UMTS-FemtoCell service area mapping (orFemtoCommunity service area selection) provides the following functions: a) It allowsINCAs default or serviceINCTo be allocated withFAPRegistration (and
200780043341. 5 Preempt the specificFAPall ofUE) AssociatedFemtoCommunity service area. Then, the service area can be used for emergency call routing, as described in the service area-based routing section in the emergency services section above.
B.Service Access Control (SAC) Examples The following exemplary service access control is described in this section: (1 )newFAPConnected toGAN FemtoCommunity network, (2 ) FAPConnected toGAN FemtoCell network (redirected connection), (3) FAPRestrictedUMTSTry to connect in the coverage area, (4 ) AuthorizedUERoaming to authorized useFemtoCommunity serviceFAPIn, and (5 ) UnauthorizedUERoaming to authorized useFemtoCommunity serviceFAPmiddle.
1.newFAPConnected toGAN FemtoCommunity network diagram54Shows some embodiments for connecting toFemtoNew in the community networkFAPof SAC -As shown in the figure, ifFAP 5405Have supplySeGWSupplied or derived FQDN,Then it executes (in step1 ) DNSQuery (via generalIPAccess network interface),In order toFQDNResolve toIPaddress. ifFAPHas for supplySeGWSuppliedIPAddress, omitDNSstep.
DNSserver5410Return response (in step2),The response includes supplySeGW 5415 ofIPaddress.FAP 5405useIKEv2andEAP-AKAorΕΑΡ-SIMBuild (in step 15 ) Lead to supplySeGW 5415Safe tunnel.
ifFAPHave supplyINCSupplied or derivedFQDN,Then it executes (in step4 ) DNSEnquiry (via a secure tunnel),In order toFQDNResolve toIPaddress. ifFAP Has for supplyINCSuppliedIPAddress, it will be omittedDNSStep (step4 ).DNS server5420Return response (in step5),The response includes supplyINCofIPaddress.
Next,FAP 5405In supplyINC 5425Build on (in step6) To a well-defined portTCPconnect. Then,FAP 5405useGA-RCDiscovery request query (in step7) For defaultINCSupply ofINC. The message includes cell information andFAPidentity. For cell information, ifFAPMacro network coverage is detected, then it provides the detectedUTRANCommunityIDand UTRANLALifFAPIf no macro network coverage is detected, it will provide the lastFAPSuccessfully registeredLAI,And an indicator showing which it is. forFAPIdentity, the message includesIMSL
INC 5425willRADIUSAccess-The request message is sent to (in step8) AAAserver 5435,Including fromGA-CSRDiscover the attributes exported by the request message.AAAserver5435Query (in step9 ) FemtoCommunity user database5440,To find andFAPofIMSIMatching records.
200780043341.5 The user record is returned to (in step9 ) AAAserver.AAAServer verifies thatFAP IMSI Is authorized andFAPIs licensed (based onΑΡ-ID,which is,FAPofMACaddress).
AAAThe server is based onΑΡ-IDandIMSIUse access to accept messages toINC 5425Return (in step10 )SelectedFemtoCell location information.INC 5425useUMTS-FemtoCell mapping function (see aboveUMTSarriveFemtoCell mapping section) Judgment (in step11) The default security gateway andINC (E.g,INC#2 5430). This is done to makeFAP 5405Pointed toHPLMNLocal defaultINC,To optimize network performance.
supplyINC 5425existGA-RCFound that the acceptance message returned (in step12 )defaultINC information. It was found that the acceptance message also indicatedINCAnd providedSeGWShould the address beFAPstorage.FAPRelease (in step13 ) TCPConnect andIPSecTunnel and continue executionINC #2On the registration.
FAPUse assigned defaultINC FQDNExecute (in step14 )privateDNSInquire. privateDNSserver5420Return (in step15 )INC #2 5430ofIPaddress.FAPBuild (in step16) Leading toINC #2 5430ofTCPconnect.FAPwillGA-RCThe registration request message is sent to (in step17) INC.
INCwillRADIUSAccess-The request message is sent to (in step18 ) AAAServer, including longGA-RCRegister the attributes exported by the request message.AAAServer query (in step19 ) Femto , Bu district user database to find andFAP IMSIMatching records. The user record is returned to (in step19 ) AAAserver.AAAServer verificationIMSIIs authorized andFAPIs allowed (based onAP-ID)» Next,AAAServer toINCReturn (in step20 )SelectedFemtoCommunity service attributes.INCuseUMTS-FemtoCell mapping function to determine (in step21) This is the correct service for the current location of the mobile stationINC.INCAlso useUMTS-FemtoCell mapping function to determine (in step21)andFAPAssociatedFemtoCommunity service area.INCTowardsMSReturn (in step22 ) GA-RCRegister to receive messages.
2. FAPConnected toGAN FemtoCell network (redirected connection) diagram55Show some examples forFAPexistFemtoRedirected in the cell network SAC οstep1to10With the new one aboveFAPConnected toGAN FemtoThe steps described in the cell network section are the same. Next,INC 5525useUMTS-FemtoCell mapping function to judge (in step11) FAP 5505Should be another INCservice.
INC 5525existGA-RCRegister the new service in the redirect messageSeGWandINC FQDN
200780043341.5 No. sent to (in step12) FAP 5505.FAPRelease (in step13 ) TCPConnect andIPSec Tunnel and proceed to the designatedINCRegistration.
3. FAPTry on the restrictedUMTSConnection diagram in coverage area56Shows some examples for use in restrictedUMTSCoverage areaFAPRegisteredSAC. As shown in the figure, the steps1to10With the new one aboveFAPConnected toGAN Femto The steps described in the cell network section are the same. Next,INC 5625use UMTS-FemtoCell mapping function to judge (in step11 ) FAP 5605InFemtoRestrictedUMTSArea (that is, not allowed in the areaFemtoCell access).
INCwillGA-RCThe registration rejection message is sent to (in step12 ) FAP,Including the reason for rejection" Location is not allowed.FAPRelease (in step13 ) TCPConnect andIPSecTunnel and dont try again from the same UMTSThe coverage area is registered until the power is off.
4. AuthorizedUERoaming to authorized useFemtoCommunity serviceFAPThe inner event sequence is the same as the aboveUEThe same as described in the registration section.
5. UnauthorizedUERoaming to authorized useFemtoCommunity serviceFAPUnauthorizedUE (Unauthorized passage of specificFAPuseFemtoCommunity service), when rightFAPPre-occupied time (via its internal cell selection mechanism),Will passFAPTowardsCNInitiateNAS Layer location update processing (LUIs triggered becauseFAPBroadcast its neighboring macro cell and other neighboringFemtoDifferent districtLAI).FAPWill intercept location update messages and try toUERegister to [NC,This is described below. picture57Shows some examples for unauthorized UEAccess authorizedFAPofSACo as the picture shows,UE 5705Build (in stepla) And what it preemptsFAPofRRCconnect. UEStart (in steplb) TowardsCNThe location update processing.FAP5710Will intercept location update requests and try to pass existingIPSecTunnel willUERegister to the associated serviceINC. Optionally, If usingTMSIPerform location updates,FAPCan be requested (in steplc) UEofIMSI,Because UEThe initial registration must be carried out using a permanent identity, that is,UEofIMSL
FAPexistINC 5715On (for eachUE ) Establish a path to the destinationTCPSeparate TCPconnect.INCdestinationTCPPort andFAPThe same is used for registration.FAPSent by (in step2 ) GA-RCRegister request, try toUERegister toINCsuperior. The message includes (1 ) Registration type, which indicates that the device being registered isUE, (2) UEIdentity, that is,UE-IMSI,as well as(3 ) FAP Identity, that is,FAP-IMSL Optionally, ifINCHas been configured to passS1Service access control of the interface
200780043341.5 NS(SAC ), INCWill (in step3),viaAAAserver5420,Use the information provided in the registration request toUE 5405Authorize.AAAThe authorization logic on the server is also checked (in step4 ),LookUEIs it allowed to use specificFAPconductFemtoCell access.AAA SACLogical instructions are being registeredUESpecificFAPAccessFemtoCommunity service.
Next,AAA 5720Deny access (and equal toUENot allowed inFAPThe reason for the rejection) is sent to (in step5) INC 5715o INCMap the access denial to (in step6) GA-RCRegister rejection message toFAPIndicate the reason for rejection.
then,FAP5710TowardsUE5705Send (in step7 ) The location update is rejected with the reason that the location area is not allowed. This will preventUETry to preempt a particularFAP. While some embodiments use location areas that are not allowed as used to deny unauthorizedUEMechanism, other embodiments can use other appropriateUERejection mechanism.
XIV.Computer system diagram58The computer system used to implement some embodiments of the present invention is conceptually shown. computer system5800Including bus5805,processor5810, System memory5815,ROM5820, Permanent storage5825, Input device5830,And output device5835.
bus5805The overall representative supports the computer system5800All systems, peripherals and chipset buses for communication between the internal devices. For example, the bus5805Will processor5810Read-only memory5820, System memory5815And permanent storage5825Can be connected communicatively.
processor5810The instructions to be executed and the data to be processed are retrieved from these various storage units, thereby executing the processing of the present invention. In some embodiments, the processor includes a field programmable gate array (FPGA ),ASICOr various other electronic components used to execute instructions. ROM(ROM) 5820Storage processor5810And static data and instructions required by other modules of the computer system. On the other hand, permanent storage5825,Is reading-Write storage device. The device is a non-volatile storage unit, which stores instructions and data, even in computer systems5800When closed. Some embodiments of the present invention use mass storage devices (such as magnetic disks or optical disks and their corresponding disk drives) as permanent storage devices5825. Some embodiments use one or more removable storage devices (flash cards or memory sticks) as permanent storage devices.
Similar to permanent storage5825,System memory5815Is reading-Write storage device. However, with the storage device5825Unlike, the system memory is volatile to read-Write memory, such as random access memory. The system memory stores some instructions and data required by the processor at runtime.
200780043341. 5 The first embodiment executes the instructions required for processing and/Or the data is stored in the system memory5815, Permanent storage5825,ROM5820Or any combination of the above three. For example, various storage units include instructions for processing multimedia items according to some embodiments. processor5810 The instructions to be executed and the data to be processed are retrieved from these various storage units, thereby executing the processing of some embodiments.
bus5805Also connected to the input device5830And output device5835. The input device enables the user to pass information to the computer system and select commands. Input device5830Includes alphanumeric keyboard and cursor controller. Output device5835Display the image generated by the computer system. Output devices include printers and display devices, such as cathode ray tubes (CRT) Or liquid crystal display (LCD). Finally, as shown58Shown, the bus5805Also connect the computer through a network adapter (not shown)5800 Coupling to the network5865. In this way, the computer can be part of a computer network (such as a local area network (LAN),Wan(WAN), or intranet) or one of various networks (such as the Internet).
Those skilled in the art should understand that in combination with the present invention, a computer system can be used5800 Any or all of the components. For example, refer to the figure58Some or all of the components of the described computer system include the aboveUE,FAP,GANCandGGSNSome examples. In addition, those skilled in the art will understand that any other system configuration can also be used in combination with the present invention or the components of the present invention.
XV.Definitions and abbreviations The following is a list of definitions and abbreviations used in this article
AAA Authentication, authorization and billing
ACL Access control list
AES Advanced Encryption Standard
AH Authentication header (IPSec)
AKA Authentication and key agreement
ALI Automatic location recognition
AMS Access point management system
ANI Automatic number recognition
AP Access Point
APN Access point name
ΑΓΜ Asynchronous transfer mode
200780043341.5 NS
<td>AuC</td><td>Authentication Center</td>
<td>CBC</td><td>Cell Broadcast Center</td>
<td>CBC</td><td>Cryptographic blockchain</td>
<td>CC</td><td>Call control</td>
<td>CDR</td><td>Call detail record</td>
<td>CMDA</td><td>Code division multiple access</td>
<td>CGI</td><td>Cell global identification</td>
<td>CgPN</td><td>Calling party number</td>
<td>CLIP</td><td>Call line indication</td>
<td>CK</td><td>Cryptographic key</td>
<td>CM</td><td>Connection management</td>
<td>CM-sub</td><td>Connection management sublayer</td>
<td>CN</td><td>Core network</td>
<td>CPE</td><td>Client device</td>
<td>CRC</td><td>Cyclic redundancy code</td>
<td>CRDB</td><td>Coordinate routing database(Cooridnate Routing Database )</td>
<td>CS</td><td>Circuit switching</td>
<td>CTM</td><td>Cellular text phone modem, such as3GPP26.226Stipulated in</td>
<td>DL</td><td>Downlink</td>
<td>DNS</td><td>Domain Name System</td>
<td>EAP</td><td>Scalable authentication protocol</td>
<td>EAPOL</td><td>LANUpΕΑΡ</td>
<td>ECB</td><td>Electronic code book (AESmodel)</td>
<td>ELID</td><td>Emergency location information transmission</td>
<td>E-OTD</td><td>Enhanced observation time difference</td>
<td>ESN</td><td>Emergency service number</td>
<td>ESP</td><td>Emergency service protocol or encapsulated security payload (IPSec )</td>
<td>ESRD</td><td>Emergency service routing number</td>
<td>ESRK</td><td>Emergency service routing key</td>
<td>ETSI</td><td>European Telecommunications Standards Institute</td>
<td>FCAPS</td><td>Fault, configuration, billing, performance and security management</td>
200780043341.5 NS
<td>FAP</td><td>FemtoCell access point</td>
<td>FCC</td><td>Federal Communications Commission</td>
<td>FQDN</td><td>Fully qualified domain name</td>
<td>GA-CSR</td><td>Universal access-Circuit switched resources</td>
<td>GAN</td><td>Universal access network</td>
<td>GANC</td><td>GANNetwork controller</td>
<td>GA-PSR</td><td>Universal access-Packet switching resources</td>
<td>GA-RC</td><td>Universal access-Resource control</td>
<td>GDP</td><td>General digital parameters</td>
<td>GERAN</td><td>GSM EDGEWireless access network</td>
<td>GGSN</td><td>GatewayGPRSSupport node</td>
<td>GMLC</td><td>Gateway Mobile Location Center</td>
<td>GMM/SM</td><td>GPRSMobility management and session management</td>
<td>GMSC</td><td>GatewayMSC</td>
<td>GPRS</td><td>General Packet Radio Service</td>
<td>GPS</td><td>Global Positioning System</td>
<td>GMM-sub</td><td>GPRSMobility Management Sublayer</td>
<td>GRR-sub</td><td>GSMmiddleGPRSRadio resource sublayer</td>
<td>GSM</td><td>Global System for Mobile Communications</td>
<td>GSN</td><td>GPRSSupport node</td>
<td>GTP</td><td>GPRSTunneling protocol</td>
<td>GTT</td><td>GSMGlobal text call orSS7Global name translation</td>
<td>HLR</td><td>Home location register</td>
<td>HMAC</td><td>Hash message authentication code(Hashed Message Authentication Code )</td>
<td>HPLMN</td><td>AttributionPLMN</td>
<td>IAM</td><td>Initial address message</td>
<td>ICMP</td><td>Internet Control Message Protocol</td>
<td>IETF</td><td>International Internet Engineering Task Force</td>
<td>IK</td><td>Integrity key</td>
<td>IKEv2</td><td>Internet key exchange version2</td>
<td>IMEI</td><td>International Mobile Station Equipment Identification Code</td>
100
200780043341.5 NS
<td>IMSI</td><td>International mobile user identity</td>
<td>INC</td><td>IPNetwork controller</td>
<td>IP</td><td>Internet protocol</td>
<td>IPSec</td><td>IPSafety</td>
<td>IPv4</td><td>Internet Protocol version4</td>
<td>IPv6</td><td>Internet Protocol version6</td>
<td>ISDN</td><td>Integrated service digital network</td>
<td>ISP</td><td>Internet Service Provider</td>
<td>ISUP</td><td>ISDNUser part</td>
<td>Iu</td><td>interface UTRAN</td>
<td>IV</td><td>Initialization vector</td>
<td>LA</td><td>Location area</td>
<td>LAC</td><td>Location area code</td>
<td>LAI</td><td>Location area identifier</td>
<td>LAU</td><td>Location area update</td>
<td>LU</td><td>Location update</td>
<td>LCS</td><td>Location service</td>
<td>LEAP</td><td>Lightweight ΕΑΡ (same EAP-Cisco )</td>
<td>LLC</td><td>Logical link control</td>
<td>LLC-sub</td><td>Logical link control sublayer</td>
<td>LMSI</td><td>Local mobile user identification code</td>
<td>LSB</td><td>Least important bit</td>
<td>LSP</td><td>Location Service Agreement</td>
<td>M</td><td>Mandatory</td>
<td>M3UA</td><td>MTP3User adaptation layer</td>
<td>MAC</td><td>Media access control or message authentication code (same asMIC)</td>
<td>MACaddress</td><td>Media access control address</td>
<td>MAC-I</td><td>Message authentication code for integrity</td>
<td>MAP</td><td>Mobile application part</td>
<td>MDN</td><td>Mobile directory number</td>
<td>ME</td><td>Mobile station device</td>
101
200780043341.5 NS
<td>MIC</td><td>Message integrity check(Same message authentication code)</td>
MGorMGW Media gateway
<td>MM MM-sub MPCMSMSBMSC MSISDN MSRNMTP 1/2/3NASNCASNDCNSNSAPI</td><td>Mobility Management Mobility Management Sub-layer Mobile Positioning Center Mobile Station Most Important Bit Mobile Switching Center Mobile Station InternationalISDNNumber Mobile Station Roaming Number Messaging Part No.1/2/3Layer Non-Access Layer Non-Call Related Signaling Country Destination Code Network Service Network Layer Service Indoor Base Station Identifier(Network layer Service IndoorBase Station Identifier )</td>
<td>NSS 0 OCBOTP pANIPCSPCUPDCHPDEPDNPDPPDUPEAPPKI</td><td>Optional offset code book for network subsystem(Offset Code Book) ( AESmodel)One-time programmable pseudo-ANI:orESRDorESRKPersonal communication service packet control unit packet data channel positioning entity packet data network packet data protocol, for example,IPorX.25Protocol data unit protectedΕΑΡPublic key infrastructure</td>
102
200780043341. 5 NS
<td>PLMN</td><td>Public land mobile network</td>
<td>POI</td><td>Interface point</td>
<td>PPF</td><td>Paging progress flag</td>
<td>PPP</td><td>Point-to-point protocol</td>
<td>PSAP</td><td>Public safety answering point</td>
<td>PSTN</td><td>Public switched telephone network</td>
<td>PTM</td><td>Point-to-multipoint</td>
<td>P-TMSI</td><td>GroupingTMSI</td>
<td>PTP</td><td>Point to point</td>
<td>PVC</td><td>Permanent virtual circuit</td>
<td>QoS</td><td>service quality</td>
<td>R</td><td>needs</td>
<td>RA</td><td>Routing area</td>
<td>RAB</td><td>RANAPAssignment request</td>
<td>RAC</td><td>Routing area code</td>
<td>RADIUS</td><td>Remote authentication dial-in user service</td>
<td>RAI</td><td>Routing area identification</td>
<td>RAN</td><td>Wireless access network</td>
<td>RANAP</td><td>Wireless access network application part</td>
<td>RFC</td><td>Request comments (IETFstandard)</td>
<td>RLC</td><td>Wireless link control</td>
<td>RNC</td><td>Wireless network controller</td>
<td>RR-sub</td><td>Radio resource management sublayer</td>
<td>RSN</td><td>Robust security network</td>
<td>RTCP</td><td>Real-time control protocol</td>
<td>RTP</td><td>Real-time protocol</td>
<td>SAC</td><td>Service access control</td>
<td>SAC</td><td>Service area codeSCScrambling</td>
<td>SCCP</td><td>Signaling connection control part</td>
<td>SDCCH</td><td>Independent dedicated control channel</td>
<td>SDU</td><td>Service data unit</td>
103
200780043341.5 NS
SeGW
SGSN
SK
SIM
SM
GANCSecurity Gateway ServiceGPRSSupport node service key user identity module session management
SMLC Service Mobile Positioning Center
SMS Short message service
SM-AL SMS application layer
SM-TL Short message transport layer
SM-RL Short message relay layer
SM-RP Short message relay protocol
SMR Short message relay (entity)
SM-CP Short message control protocol
SMC Short message control (entity)
SM-SC Short Message Service Center
SMS-GMSCShort Message Service GatewayMSC
SMS-IWMSCShort message service interactionMSC
SNDCP Subnet dependent convergence protocol
SN-PDU SNDCP PDU
S/R Selective router
SS Ancillary services
SSID Service setting identifier (also called network name)
SSL Secure Socket Layer
STA stand(802.11 customer)
TA Time advance
TCAP Transaction processing capability application part
TCP Transmission Control Protocol
TDOA Arrival time difference
TEID Terminal endpoint identifier
TID Tunnel identifier
TKIP Temporary Key Integrity Protocol
104
200780043341.5 NS
TLLI Temporary logical link identification
TLS Transport layer security
TMSI Temporary mobile user identity
TOA Time of arrival
TRAU Code Conversion and Rate Adaptation Unit
TTY Text phone or teletypewriter
UARFCN UMTSAbsolute radio frequency channel number
UDP User Datagram Protocol
UE User device
UL Uplink
UMA Unauthorized mobile access
UMTS Universal Mobile Telecommunications System
USIM UMTSUser Identity Module/Universal User Identity Module
USSD Unstructured supplementary business data
UTC UTC
UTRAN UMTSTerrestrial wireless access network
VLR Visitor location register
VMSC VisitedMSC
VPLMN Public land mobile network visited
VPN Virtual private network
W-CDMA Wideband Code Division Multiple Access
WEP Wired Equivalent Privacy
WGS-84 World Geodesy System1984
WPA Wi-FiProtected access
WZ1 world1In the previous description, for the purpose of explanation, specific terms are used to enable the reader to thoroughly understand the present invention. However, it will be clear to those skilled in the art that specific details are not necessary for implementing the present invention. Thus, for the purpose of illustration and description, the foregoing description of the specific embodiments of the present invention is provided. These embodiments are not exclusive, nor are they intended to limit the present invention to the precise manner disclosed; obviously, with reference to the above disclosed solutions, many modifications and variations can be implemented. The selection and description of these embodiments are to better explain the principles of the present invention and its practical application, so as to make
105
200780043341.5 Those skilled in the art can make better use of the present invention, and various embodiments with various modifications are suitable for the specific intended use. In addition, although the present invention has been described with reference to many specific details, those skilled in the art will understand that the present invention can be implemented in other specific ways without departing from the spirit of the present invention.
In some examples and schematic diagrams, two components connected to each other may be described or shown. The connection may be a direct wired connection, or the two components may be communicatively coupled to each other through other components or through a wireless or broadband link. Therefore, those skilled in the art will understand that the present invention is not limited to the foregoing exemplary details, but is defined by the appended claims.
106
200780043341.5
Contents23
60 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN110574438A | Cited by | China | Search report |
| CN113783691A | Cited by | China | Search report |
| CN115714779A | Cited by | China | Search report |
| CN103428848A | Cited by | China | Search report |
| US11438760B2 | Cited by | United States of America | Applicant |
| US11490246B2 | Cited by | United States of America | Applicant |
| US12140927B2 | Cited by | United States of America | Applicant |
| CN102884836A | Cited by | China | Search report |
| US11930113B2 | Cited by | United States of America | Applicant |
| CN104010312A | Cited by | China | Search report |
| CN109690589A | Cited by | China | Search report |
| US9526013B2 | Cited by | United States of America | Applicant |
| CN108432176A | Cited by | China | Search report |
| US11626993B2 | Cited by | United States of America | Applicant |
| CN110832825A | Cited by | China | Search report |
| CN112887154A | Cited by | China | Search report |
| US12118627B2 | Cited by | United States of America | Applicant |
| US11496884B2 | Cited by | United States of America | Applicant |
| CN107113621A | Cited by | China | Search report |
| WO2020168585A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN104754654A | Cited by | China | Search report |
| US9408255B2 | Cited by | United States of America | Applicant |
| WO2011124172A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN110915183A | Cited by | China | Search report |
| WO2011124172A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| TWI587671B | Cited by | Taiwan Province of China | Examiner |
71 members in 7 offices
Priority claims41
| Document | Office | Kind | Date |
|---|---|---|---|
| 60826700 | United States of America | – | |
| 82670006 | United States of America | P | |
| 82670006 | United States of America | P | |
| 60862564 | United States of America | – | |
| 60869900 | United States of America | – | |
| 60884017 | United States of America | – | |
| 60884889 | United States of America | – | |
| 60893361 | United States of America | – | |
| 60911862 | United States of America | – | |
| 60911864 | United States of America | – | |
| 60949826 | United States of America | – | |
| 60949853 | United States of America | – | |
| 60954549 | United States of America | – | |
| 11859762 | United States of America | – | |
| 11859763 | United States of America | – | |
| 11859764 | United States of America | – | |
| 11859765 | United States of America | – | |
| 11859767 | United States of America | – | |
| 11859769 | United States of America | – | |
| 11859770 | United States of America | – | |
| 11859771 | United States of America | – | |
| 11859762 | – | – | – |
| 11859763 | – | – | – |
| 11859764 | – | – | – |
| 11859765 | – | – | – |
| 11859767 | – | – | – |
| 11859769 | – | – | – |
| 11859770 | – | – | – |
| 11859771 | – | – | – |
| 60826700 | – | – | – |
| 60862564 | – | – | – |
| 60869900 | – | – | – |
| 60884017 | – | – | – |
| 60884889 | – | – | – |
| 60893361 | – | – | – |
| 60911862 | – | – | – |
| 60911864 | – | – | – |
| 60949826 | – | – | – |
| 60949853 | – | – | – |
| 60954549 | – | – | – |
| US20060826700P | – | – | – |
Members71
| Document | Office | Kind | |
|---|---|---|---|
| WO2008009016A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2008039086A1 | United States of America | A1 | |
| US2008039087A1 | United States of America | A1 | |
| US2008043669A1 | United States of America | A1 | |
| US2008076386A1 | United States of America | A1 | |
| US2008076392A1 | United States of America | A1 | |
| US2008076393A1 | United States of America | A1 | |
| US2008076411A1 | United States of America | A1 | |
| US2008076412A1 | United States of America | A1 | |
| US2008076419A1 | United States of America | A1 | |
| US2008076420A1 | United States of America | A1 | |
| US2008076425A1 | United States of America | A1 | |
| WO2008036961A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008036961A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2008123596A1 | United States of America | A1 | |
| US2008130564A1 | United States of America | A1 | |
| US2008132224A1 | United States of America | A1 | |
| US2008137612A1 | United States of America | A1 | |
| US2008181204A1 | United States of America | A1 | |
| US2008207170A1 | United States of America | A1 | |
| WO2008106360A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2008261596A1 | United States of America | A1 | |
| WO2008106360A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2008009016A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2008305792A1 | United States of America | A1 | |
| US2008305793A1 | United States of America | A1 | |
| WO2009021152A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2009059848A1 | United States of America | A1 | |
| US2009061877A1 | United States of America | A1 | |
| WO2009039318A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009039318A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2044715A2 | European Patent Office (EPO) | A2 | |
| KR20090060405A | Republic of Korea | A | |
| EP2074839A2 | European Patent Office (EPO) | A2 | |
| CN101513108A | China | A | |
| WO2009021152A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CN101543107AThis record | China | A | |
| US2009262682A1 | United States of America | A1 | |
| US2009262683A1 | United States of America | A1 | |
| US2009262684A1 | United States of America | A1 | |
| US2009262702A1 | United States of America | A1 | |
| US2009262703A1 | United States of America | A1 | |
| US2009262704A1 | United States of America | A1 | |
| US2009264095A1 | United States of America | A1 | |
| US2009264126A1 | United States of America | A1 | |
| US2009265542A1 | United States of America | A1 | |
| US2009265543A1 | United States of America | A1 | |
| WO2009129516A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2115946A2 | European Patent Office (EPO) | A2 | |
| CN101617508A | China | A | |
| EP2044715A4 | European Patent Office (EPO) | A4 | |
| EP2074839A4 | European Patent Office (EPO) | A4 | |
| EP2115946A4 | European Patent Office (EPO) | A4 | |
| EP2186357A2 | European Patent Office (EPO) | A2 | |
| CN101822076A | China | A | |
| US7852817B2 | United States of America | B2 | |
| EP2272261A1 | European Patent Office (EPO) | A1 | |
| US7912004B2 | United States of America | B2 | |
| EP2186357A4 | European Patent Office (EPO) | A4 | |
| US7995994B2 | United States of America | B2 | |
| US8005076B2 | United States of America | B2 | |
| US8019331B2 | United States of America | B2 | |
| EP2044715B1 | European Patent Office (EPO) | B1 | |
| US8036664B2 | United States of America | B2 | |
| AT527853T | Austria | T | |
| ATE527853T1 | Austria | T1 | |
| US8041335B2 | United States of America | B2 | |
| US8073428B2 | United States of America | B2 | |
| ES2374745T3 | Spain | T3 | |
| US8150397B2 | United States of America | B2 | |
| US8204502B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Deemed withdrawal of patent application after publication (patent law 2001)C02 | C02 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 101543107
- Publication, DOCDB
- 101543107
- Publication, EPODOC
- CN101543107
- Application
- 800433415
- Application, DOCDB
- 200780043341
- Application, EPODOC
- CN2007843341
Titles2
- Chinese
- 用于资源管理的方法和设备
- English
- Method and equipment for resource management
Classification
- IPC, 2
- H04W8 04
- H04W60 00