A communication method and apparatus

By using access network equipment that supports 3GPP access type in remote areas, wireless access to fixed network is achieved, solving the problem of broadband service inaccessibility caused by difficulties in fiber optic cable laying, and improving the coverage and performance of communication system.

CN115643562BActive Publication Date: 2026-01-06HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110812409.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-19
Publication Date
2026-01-06
Estimated Expiration
2041-07-19

AI Technical Summary

Technical Problem

The difficulty in laying fiber optic cables in remote areas results in a low fiber-to-the-home rate, making existing wired broadband access methods unsuitable and unable to effectively provide broadband services.

Method used

Access network equipment supporting 3GPP access type is used as an intermediate node. Terminal equipment establishes a connection with the access network equipment through 3GPP access technology to realize wireless access to the fixed network. Terminal equipment transmits data with fixed network gateway equipment through access network equipment.

Benefits of technology

It simplifies the access process for terminal devices, reduces signaling overhead, improves the coverage and performance of the communication system, and enables broadband service access in remote areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643562B_ABST
    Figure CN115643562B_ABST
Patent Text Reader

Abstract

The application provides a communication method and device to solve the problem that optical fiber laying is difficult and wired access cannot be used to obtain fixed network services. The method comprises: an access network device obtaining first information, the access network device supporting a third generation partnership project (3GPP) access technology; the access network device establishing a user plane connection with a first terminal device according to the first information; and the access network device obtaining user plane data of the first terminal device through the user plane connection and sending the user plane data to a first fixed network gateway device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0002] Fixed-line networks typically provide broadband services to homes, shops, and other locations via fixed lines. Currently, fixed-line terminals, such as customer-premises equipment (CPE), need to connect to the fixed-line network via wired means such as fiber optic cables, and communicate with the fixed-line broadband network gateway (BNG) via Internet Protocol over Ethernet (IPoE) or Point-to-Point Protocol over Ethernet (PPPoE).

[0003] For some remote areas, laying fiber optic cables is difficult, resulting in low fiber-to-the-home rates. Accessing broadband services via wired connections is not suitable for these areas. Therefore, how to enable broadband access in areas where fiber optic deployment is challenging is a problem worthy of investigation. Summary of the Invention

[0004] This application provides a communication method and apparatus to provide wireless access to fixed networks and bandwidth services through access network equipment that supports the 3rd Generation Partnership Project (3GPP).

[0005] In a first aspect, embodiments of this application provide a communication method, comprising: an access network device acquiring first information, wherein the access network device supports 3GPP access type; the access network device establishing a user plane connection with a first terminal device based on the first information; the access network device acquiring user plane data of the first terminal device through the user plane connection, and sending the user plane data to a first fixed network gateway device.

[0006] In this embodiment, an access network device supporting 3GPP access type is used as an intermediate node between the terminal device and the fixed network gateway device. The terminal device establishes a connection with the access network device using 3GPP access technology, and the access network device can transmit data from the terminal device to the fixed network gateway device, enabling the terminal device to obtain fixed network broadband services through 3GPP access. Compared to the traditional method of fixed network terminals accessing the fixed network via wired connection, this simplifies deployment, enhances coverage, and improves the performance of the communication system.

[0007] In one possible design, the first information is used to indicate that the type of the first terminal device is a target type and / or to indicate that the first terminal device is allowed to access fixed-line services provided by the first fixed-line gateway device; wherein, the target type includes one or more of home gateway, home terminal, and client terminal device.

[0008] In one possible design, the first information comes from the first terminal device, and the first information indicates that the type of the first terminal device is the target type. In another possible design, the first information is pre-configured in the access network device or comes from the first fixed network gateway device; wherein, the first information includes subscription data information corresponding to the first terminal device, and the subscription data information is used to determine whether the first terminal device is allowed to obtain fixed network services provided by the first fixed network gateway device. Establishing a user plane connection in this way simplifies the access process for terminal devices, saves signaling overhead, and reduces costs.

[0009] In one possible design, before the access network device obtains the user plane data of the first terminal device through the user plane connection, the method further includes: the access network device sending second information to the first fixed network gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed network gateway device; the access network device receiving third information from the first fixed network gateway device, the third information indicating that the connection between the first terminal device and the first fixed network gateway device has been successfully established.

[0010] In one possible design, the access network device executes a user plane connection management process based on the third information; wherein the user plane connection management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources, or releasing user plane resources.

[0011] In one possible design, the third information includes at least one of the following: identification information of the first terminal device; authentication information of the first terminal device, which indicates that the first terminal device has been authenticated through the fixed network corresponding to the first fixed network gateway device; subscription data information of the first terminal device, which includes one or more of fixed network service information, Quality of Service (QoS) information, and priority information; and security context information of the first terminal device, which is used to establish a secure connection between the access network device and the first terminal device. By performing targeted user plane connection management processes on the terminal device based on its relevant characteristics, such as its subscription data information, the user experience can be improved.

[0012] In one possible design, before the access network device establishes a user plane connection with the first terminal device based on the first information, the method further includes: the access network device establishing a connection with at least one fixed network gateway device, wherein the at least one fixed network gateway device includes the first fixed network gateway device.

[0013] In one possible design, before the access network device establishes a user plane connection with the first terminal device based on the first information, the method further includes: the access network device obtaining fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device; and the access network device establishing a secure connection between the access network device and the first terminal device based on the fourth information and using the security context information of the first terminal device. Establishing a secure connection between the access network device and the terminal device using the security context information of the terminal device can improve communication security.

[0014] In one possible design, the fourth information includes a first serial number corresponding to the security context information of the first terminal device; the access network device establishes a secure connection between itself and the first terminal device based on the fourth information and using the security context information of the first terminal device, including: the access network device obtaining security context information and an identifier set of at least one terminal device, the identifier set including a first serial number set for indicating the security context information of the at least one terminal device, the first serial number set including the first serial number; the access network device obtaining the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device based on the first serial number; and the access network device establishing a secure connection between itself and the first terminal device using the security context information of the first terminal device.

[0015] In one possible design, the identifier set further includes a second sequence number set; after the access network device establishes a secure connection between the access network device and the first terminal device using the security context information of the first terminal device, the method further includes: replacing the first sequence number with a second sequence number from the second sequence number set, and sending the second sequence number to the first terminal device, wherein the second sequence number is used to indicate the security context information of the first terminal device. Updating the sequence number of the security context information after the authentication process is completed ensures that the identifier or index number of the security context is dynamically changing, further enhancing communication security.

[0016] In one possible design, the fourth information may also include the identification information of the fixed network corresponding to the first fixed network gateway device.

[0017] In one possible design, before the access network device obtains the fourth information, the method further includes: the access network device sending at least one of the following information:

[0018] The access network device's capability information, indicating that the access network device supports fixed network transmission; the identification information of the fixed network supported by the access network device, including the fixed network corresponding to the first fixed network gateway device; and network priority information, indicating the priority of the mobile operator to which the access network device belongs.

[0019] In one possible design, before the access network device obtains the fourth information, the method further includes:

[0020] The access network device acquires information sent by the first terminal device indicating that the type of the first terminal device is the target type and / or the identification information of the fixed network that the first terminal device requests to access; the access network device determines that it supports the fixed network transmission of the first terminal device based on the type of the first terminal device and / or the identification information of the fixed network that the first terminal device requests to access.

[0021] Secondly, embodiments of this application provide a communication device applied to an access network device supporting 3GPP access types. This communication device can be an access network device, a device within an access network device, or a device compatible with an access network device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the first aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software implementation. In another design, the communication device may include a processing module and a communication module. For example,

[0022] The communication module is used to acquire first information; the processing module is used to establish a user plane connection with the first terminal device based on the first information; the communication module is also used to acquire user plane data of the first terminal device through the user plane connection and send the user plane data to the first fixed network gateway device.

[0023] In this embodiment, an access network device supporting 3GPP access type is used as an intermediate node between the terminal device and the fixed network gateway device. The terminal device establishes a connection with the access network device using 3GPP access technology, and the access network device can transmit data from the terminal device to the fixed network gateway device, enabling the terminal device to obtain fixed network broadband services through 3GPP access. Compared to the traditional method of fixed network terminals accessing the fixed network via wired connection, this simplifies deployment, enhances coverage, and improves the performance of the communication system.

[0024] In one possible design, the first information is used to indicate that the type of the first terminal device is a target type and / or to indicate that the first terminal device is allowed to access fixed-line services provided by the first fixed-line gateway device; wherein, the target type includes one or more of home gateway, home terminal, and client terminal device.

[0025] In one possible design, the first information comes from the first terminal device, and the first information indicates that the type of the first terminal device is the target type.

[0026] In one possible design, the first information is pre-configured in the access network device or the first information comes from the first fixed network gateway device; wherein, the first information includes subscription data information corresponding to the first terminal device, and the subscription data information is used to determine whether the first terminal device is allowed to obtain fixed network services provided by the first fixed network gateway device.

[0027] In one possible design, before the communication module obtains user plane data from the first terminal device via the user plane connection:

[0028] The communication module is further configured to send second information to the first fixed-line gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed-line gateway device;

[0029] The communication module is also configured to receive third information from the first fixed-line gateway device, the third information indicating that the connection between the first terminal device and the first fixed-line gateway device has been successfully established.

[0030] In one possible design, the processing module is further configured to execute a user plane connection management process based on the third information; wherein the user plane connection management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources, or releasing user plane resources.

[0031] In one possible design, the third information includes at least one of the following: identification information of the first terminal device; authentication information of the first terminal device, the authentication information being used to indicate that the first terminal device has been authenticated through the fixed network corresponding to the first fixed network gateway device; subscription data information corresponding to the first terminal device, the subscription data information including one or more of fixed network service information, QoS information, and priority information; and security context information of the first terminal device, the security context information being used to establish a secure connection between the access network device and the first terminal device.

[0032] In one possible design, the access network device establishes a connection with at least one fixed network gateway device, the at least one fixed network gateway device including the first fixed network gateway device.

[0033] In one possible design, before the processing module establishes a user plane connection with the first terminal device based on the first information: the communication module is further configured to obtain fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device; the processing module is further configured to establish a secure connection between the access network device and the first terminal device based on the fourth information and using the security context information of the first terminal device.

[0034] In one possible design, the fourth information includes a first serial number corresponding to the security context information of the first terminal device; the processing module is further configured to: obtain security context information and an identifier set of at least one terminal device through the communication module, the identifier set including a first serial number set for indicating the security context information of the at least one terminal device, the first serial number set including the first serial number; obtain the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device according to the first serial number; and establish a secure connection between the access network device and the first terminal device using the security context information of the first terminal device.

[0035] In one possible design, the identifier set further includes a second sequence number set; the processing module is further configured to replace the first sequence number with a second sequence number from the second sequence number set after establishing a secure connection between the access network device and the first terminal device using the first terminal device security context information; the communication module is further configured to send the second sequence number to the first terminal device, the second sequence number being used to indicate the security context information of the first terminal device.

[0036] In one possible design, the fourth information may also include the identification information of the fixed network corresponding to the first fixed network gateway device.

[0037] In one possible design, before acquiring the fourth information, the communication module is further configured to send at least one of the following information: capability information of the access network device, the capability information indicating that the access network device supports fixed network transmission; identification information of the fixed network supported by the access network device, the fixed network supported by the access network device including the fixed network corresponding to the first fixed network gateway device; and network priority information, the network priority information used to indicate the priority of the mobile operator to which the access network device belongs.

[0038] In one possible design, the communication module is further configured to acquire, before acquiring the fourth information, information sent by the first terminal device indicating that the type of the first terminal device is a target type and / or the identification information of the fixed network to which the first terminal device requests access; the processing module is further configured to determine, based on the type of the first terminal device and / or the identification information of the fixed network to which the first terminal device requests access, that the access network device supports the fixed network transmission of the first terminal device.

[0039] Thirdly, embodiments of this application provide a communication device, which includes a processor for implementing the method described in the first aspect. The communication device may further include a memory for storing instructions and data. The memory is coupled to the processor, and when the processor executes the instructions stored in the memory, it can implement the method described in the first aspect. The device may also include a communication interface for communicating with other devices. For example, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface, and the other devices may be network devices. In one possible device, the device includes:

[0040] Memory, used to store program instructions;

[0041] The processor is configured to acquire first information through a communication interface, establish a user plane connection with a first terminal device based on the first information, acquire user plane data of the first terminal device through the user plane connection, and send the user plane data to a first fixed-line gateway device.

[0042] Fourthly, embodiments of this application also provide a computer program that, when run on a computer, causes the computer to perform the method provided in the first aspect.

[0043] Fifthly, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a computer, causes the computer to perform the method provided in the first aspect.

[0044] In a sixth aspect, embodiments of this application also provide a chip for reading a computer program stored in a memory and executing the method provided in the first aspect above.

[0045] In a seventh aspect, embodiments of this application also provide a chip system including a processor for supporting a computer device in implementing the methods provided in any of the first aspects. In one possible design, the chip system further includes a memory for storing necessary programs and data for the computer device. The chip system may be composed of chips or may include chips and other discrete devices.

[0046] For the technical effects that can be achieved in aspects two through seven above, please refer to the description of the technical effects that the corresponding technical solutions in aspect one above can bring, which will not be repeated here. Attached Figure Description

[0047] Figure 1 This is a schematic diagram of a fixed wired network architecture;

[0048] Figure 2 This is a schematic diagram of a fixed-line transmission protocol stack.

[0049] Figure 3 This is a schematic diagram of an IPoE communication process;

[0050] Figure 4 This is a schematic diagram of a PPPoE communication process;

[0051] Figure 5 A schematic diagram of a communication system architecture provided in an embodiment of this application;

[0052] Figure 6 This is a schematic flowchart of a screen selection method provided in an embodiment of this application;

[0053] Figure 7 This is a schematic diagram of another screen selection method provided in an embodiment of this application;

[0054] Figure 8 A schematic diagram of a protocol stack architecture provided for an embodiment of this application;

[0055] Figure 9 One of the flowcharts of the communication method provided in the embodiments of this application;

[0056] Figure 10 A schematic diagram of a data transmission process provided in an embodiment of this application;

[0057] Figure 11 One of the flowcharts of the communication method provided in the embodiments of this application;

[0058] Figure 12 One of the flowcharts of the communication method provided in the embodiments of this application;

[0059] Figure 13This is a schematic diagram of another protocol stack architecture provided in an embodiment of this application;

[0060] Figure 14 One of the flowcharts of the communication method provided in the embodiments of this application;

[0061] Figure 15 This is a schematic diagram of another data transmission process provided in an embodiment of this application;

[0062] Figure 16 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0063] Figure 17 This is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation

[0064] The following is combined first Figures 1-4 This section explains the technical solutions involved in wired access to fixed networks.

[0065] See Figure 1 This diagram illustrates a fixed wireline network architecture, which can be simply divided into four parts: fixed-line terminals, access nodes (ANs), broadband network gateways (BNGs), and service provider networks. Figure 1 The access node in the code can also be replaced with an access network (AN), and Figure 1 In this context, "access node" refers to a wired access node, and "access network" refers to a wired access network.

[0066] Fixed-line terminals, also known as customer-premises equipment (CPE), include devices such as telephones, routers, network switches, residential gateways (RGs), set-top boxes, fixed-mobile converged products, home network adapters, and internet access gateways. A CPE is a device that receives mobile signals and / or broadband signals and forwards them as wireless fidelity (Wi-Fi) signals. For example, a CPE can convert high-speed 4G or 5G signals into Wi-Fi signals, or broadband signals into Wi-Fi signals. A CPE can support a large number of mobile devices accessing the internet simultaneously. These mobile devices can be laptops, mobile phones, tablets, smart TVs, and other devices that can access the internet via Wi-Fi. CPEs support both wired access, such as wired access to fixed wired networks (e.g., wired broadband networks), and wireless access, which can be understood as accessing mobile networks through the 3rd Generation Partnership Project (3GPP) access type.

[0067] An access node (AN) is a node in a switched network where users transmit signals to or from the network. Access nodes perform various functions, such as protocol and encoding conversion, serving as the access point for object storage, verifying user authentication and authorization information, and writing data to the underlying storage node. Access nodes can include Ethernet access nodes, which support Ethernet-based subscriber lines and uplinks to Ethernet-based aggregation networks, as well as forced forwarding via Media Access Control (MAC). Wired access networks include wired access nodes and optionally some form of aggregation.

[0068] A broadband network gateway (BNG) is an Internet Protocol (IP) edge node, which can be further divided into a broadband remote access server (BRAS) and a service router (SR). The BRAS serves as the entry point for traditional Internet services, while the SR serves as the entry point for new premium services. Similar to the BRAS, the SR is used to terminate and manage PPPoE / IPoE sessions of users (i.e., CPEs).

[0069] like Figure 2 This diagram illustrates a fixed-line network transmission protocol stack. The aforementioned fixed-line terminal accesses the fixed-line network via an access node in a wired manner, such as through fiber optic cables connecting the fixed-line terminal and the access node, or between the access node and the BNG. The fixed-line terminal and the BNG can communicate via IPoE or PPPoE protocols. If the terminal device uses IPoE, an authentication process is required to obtain an IP address. If the terminal uses PPPoE, a PPPoE connection will be established between it and the BNG, and a PPPoE session identifier will be obtained. In a fixed wired network structure, the fixed-line terminal can convert the wired broadband network into a WiFi network for use by laptops, mobile phones, etc.

[0070] The following describes the scheme for communication between fixed-line terminals and BNG via IPoE or PPPoE protocols.

[0071] See Figure 3 This diagram illustrates an IPoE communication process, demonstrating how a fixed-line terminal performs IPoE authentication and obtains an IP address. It involves interaction between the fixed-line terminal, a BNG (which can be a BRAS or SR), a Dynamic Host Configuration Protocol (DHCP) server, and an Authentication, Authorization, and Accounting (AAA) server. The DHCP server assigns IP addresses to authenticated fixed-line terminals, while the AAA server performs authentication, such as determining whether the fixed-line terminal is allowed to connect online or whether it has activated broadband service. The specific steps are as follows:

[0072] S31, the fixed-line terminal initiates a DHCP Discover message, carrying information indicating the type of the fixed-line terminal in Option 60 of the DHCP Discover message. After receiving the DHCP Discover message, the Access Node (AN) can insert information indicating the location of the fixed-line terminal device in Option 82 of the DHCP Discover message, and then send the DHCP Discover message to the BNG. Figure 3 The process involved in accessing the node is omitted.

[0073] For example, a Line ID can be inserted into Option 82 of the DHCP Discover message. This Line ID is location-based, indicating the location of the fixed-line terminal. For instance, a home address of XX Province, XX City, XX District, XX Road, XX Room corresponds to a Line ID. If this address has activated home broadband service, BNG / AAA can know that the user (i.e., the fixed-line terminal) corresponding to this Line ID has activated home broadband service, and therefore authentication of this fixed-line terminal can be successful.

[0074] S32, after receiving the DHCP Discover message from the fixed-line terminal, the BNG marks the corresponding Option 82 information and sends a DHCP Discover message to the DHCP server.

[0075] S33, after receiving the DHCP Discover message, the DHCP server extracts the relevant information from the DHCP Discover message, constructs the username required for authentication and the Nas-Port-ID (or Line ID) required for authentication, and sends the username and Nas-Port-ID to the AAA server for authentication through an access request message.

[0076] S34, the AAA server authenticates the fixed-line terminal. If authentication fails, it sends a rejection message such as "access deny," and the DHCP server sends a DHCP NACK message to the BNG. The BNG then sends a DHCP NACK message to the fixed-line terminal through the access node (AN). If authentication succeeds, it sends an acceptance message such as "access accept," and the DHCP server assigns an IP address. The assigned IP address is then encapsulated in a DHCP offer message and sent to the fixed-line terminal through the BNG. The DHCP offer message also includes authentication information (Option 125) so that the fixed-line terminal can authenticate the DHCP offer message and identify whether it comes from a trusted DHCP server.

[0077] For example, Figure 3 The dashed line indicates one possible execution of S34, namely... Figure 3 In S34a: The DHCP server sends a DHCP NACK to the BNG, and the BNG sends this DHCP NACK to the fixed-line terminal through the access node. Another possible execution of S34 is illustrated with a solid line. Figure 3In S34b: The DHCP server sends a DHCP response to the BNG, and the BNG sends the DHCP response to the fixed-line terminal through the access node.

[0078] S35, Since the DHCP Discover message in step S31 is a broadcast message, it may be received by multiple DHCP servers. Therefore, in step S34, multiple DHCP servers may also assign IP addresses to the fixed-line terminal and send DHCP Offer messages. If the fixed-line terminal receives DHCP Offer messages from multiple DHCP servers, it can send a DHCP Request message based on one of the DHCP Offer messages. The DHCP Request message contains the IP address assigned by that DHCP server. Specifically, the fixed-line terminal can send the DHCP Request message based on the first DHCP Offer message it receives.

[0079] For example, suppose Figure 3 The DHCP response sent by the DHCP server, as shown in the diagram, is the first one received by the fixed-line terminal. Figure 3 In S35: After receiving a DHCP response, the fixed-line terminal can send a DHCP request message to the BNG through the access node, and the BNG will then send a DHCP request message to the DHCP server.

[0080] S36, after receiving a DHCP request message from a fixed-line terminal, the DHCP server assigning the IP address identifies that the IP address was assigned by it based on the IP address contained in the DHCP request message, and then sends a DHCP ACK to the BNG. The BNG then sends a DHCP ACK to the fixed-line terminal through the access node. Similarly, other DHCP servers that have also assigned IP addresses can determine that the IP address was not assigned by them, and then release the assigned IP address without sending a response message to the fixed-line terminal.

[0081] Through the above steps, the fixed-line terminal has passed authentication and obtained an IP address, thus enabling it to send or receive service flow data.

[0082] See Figure 4 This diagram illustrates a PPPoE communication process, specifically the procedure for establishing a session between a PPPoE client and a PPPoE server. The PPPoE client can be the aforementioned fixed-line terminal, and the PPPoE server can be the aforementioned BNG. Figure 4 The diagram illustrates a fixed-line terminal (PPPoE client) and a BNG (PPPoE server), describing the steps involved in establishing a PPPoE connection between the fixed-line terminal and the BNG.

[0083] S41, the fixed-line terminal sends a PPPoE active discovery initiation (PADI) message to the BNG through the access node AN; the message is sent in the form of a broadcast and includes the service name of the service requested by the fixed-line terminal. Figure 4 The access node AN, which is located between the fixed-line terminal equipment and the BNG, is omitted.

[0084] S42. When the BNG receives the PADI message, it determines whether it can provide the service. If it can, it will respond by sending a PPPoE Active DiscoveryOffer (PADO) message to the fixed-line terminal through the access node. The PADO message includes the PPPoE server (i.e., BNG) name, which is the same service name as in the PADI message. If the BNG cannot provide the service, it will not send a PADO message. Figure 4 The diagram illustrates the scenario where the BNG can provide services, specifically S42: the BNG sends a PADO message to the fixed-line terminal. The AN is omitted here; specifically, the BNG sends the PADO message; the AN receives the PADO message and then sends a PADO message to the fixed-line terminal.

[0085] S43. Since PADO messages are broadcast, fixed-line terminals may receive more than one PADO message. When a fixed-line terminal receives multiple PADO messages, it can select a PPPoE server (i.e., BNG) based on the server name or service provided in the PADO message, and send a PPPoE Active Discovery Request (PADR) message to the selected BNG through the access node. The PADR message includes the service requested by the fixed-line terminal.

[0086] S44, after the BNG receives the PADR message from the fixed-line terminal, the BNG responds by sending a PPPoE Active Discovery Session-confirmation (PADS) message to the fixed-line terminal through the access node. This PADS is used to establish a PPPoE session. If the BNG creates a PPPoE session identifier (Session ID) for the PPPoE session, the PADS message includes the PPPoE session identifier. Then, both communicating parties can obtain the session identifier and the other party's MAC address, and thus define a PPPoE session based on the session identifier (Session ID) and MAC address.

[0087] Furthermore, the fixed-line terminal interacts with the BNG using Link Configure Protocol (LCP) messages to complete the configuration of data link parameters. This includes, in S45, the fixed-line terminal sending a Link Configure Request message to the BNG, and in S46, the BNG sending an LCP Configure-Ack message to the fixed-line terminal.

[0088] S47, the fixed-line terminal and BNG conduct the authentication phase, which involves the Password Authentication Protocol (PAP) and the Challenge Handshake Authentication Protocol (CHAP).

[0089] S48, the fixed-line terminal and BNG negotiate network-side parameters (Network Control Protocol, NCP), during which the fixed-line terminal obtains its IP address.

[0090] The wired fixed-line access solutions described above involve the laying of optical cables. However, in some remote areas, due to environmental or local jurisdictional limitations, laying optical fibers is either impossible or extremely difficult, resulting in low fiber-to-the-home rates. Therefore, the technology of obtaining broadband services through wired fixed-line access is not suitable for these areas.

[0091] Based on this, embodiments of this application provide a communication method that aims to provide broadband services to areas where wired lines cannot be laid by introducing access network equipment that supports 3GPP access types and enabling wireless access to fixed networks. The embodiments of this application will be further described below with reference to the accompanying drawings.

[0092] In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. Furthermore, it should be understood that although terms such as "first," "second," etc., may be used to describe various data in the embodiments of this invention, these data should not be limited to these terms. These terms are only used to distinguish the data from each other.

[0093] See Figure 5 This illustration depicts a communication system architecture. The communication method provided in this application embodiment can be applied to this communication system, which includes at least one terminal device, at least one access network device supporting 3GPP access types, and at least one fixed network gateway device. For example, Figure 5 The diagram illustrates a terminal device, an access network device, and a fixed network gateway device, namely the first fixed network gateway device.

[0094] Among these, terminal equipment, also known as user equipment (UE), access terminal, terminal, or terminal device, can receive mobile signals and provide wireless local area network (WLAN) communication capabilities to at least one terminal device within its coverage area. The WLAN can be a wireless fidelity (Wi-Fi) network, Bluetooth, etc. For example, the type of terminal equipment can be a fixed-line terminal, such as a home gateway, home terminal, or customer premises equipment (CPE).

[0095] The access network equipment involved in the embodiments of this application can also be referred to as base station equipment, base station, relay station, or radio access node (RAN), etc. For example, the access network equipment can be a base transceiver station (BTS) in a Global System for Mobile Communication (GSM) or Code Division Multiple Access (CDMA) network, an NB (NodeB) in a Wideband Code Division Multiple Access (WCDMA) network, or an eNB or eNodeB (evolutionary NodeB) in a Long Term Evolution (LTE) system. The access network equipment can also be base station equipment in a 5G network or network equipment in a future evolved Public Land Mobile Network (PLMN) network.

[0096] The fixed-line gateway device involved in this application embodiment can be a Broadband Network Gateway (BNG) or other gateway devices. Optionally, the access network device can be deployed by a mobile operator, and the fixed-line operator to which the fixed-line gateway device belongs can lease the access network device by signing a contract with the mobile operator. In this scenario, the access network device may serve both the terminal devices of the mobile operator and the fixed-line terminals of the fixed-line operators to which the mobile operator has a contract. Alternatively, the access network device can be deployed independently by the fixed-line operator. In this scenario, the access network device can serve only the fixed-line terminals of the fixed-line operator.

[0097] Terminal devices establish a secure air interface connection with access network equipment through authentication and / or verification, and then wirelessly access the fixed network to transmit data and obtain relevant fixed network services. Authentication involves the network and terminal device verifying each other's trustworthiness based on a pre-configured security scheme; verification determines whether the terminal device is authorized to access fixed network services (such as home broadband services) by authenticating the terminal device's identifier or username / password. The terminal device uses 3GPP access technology to access the network, which simplifies deployment compared to traditional wired fixed network access, enhances coverage, and improves communication system performance.

[0098] The following is a detailed description of the scheme for terminal devices to access the fixed network through access network equipment using 3GPP access technology.

[0099] First, let me introduce the network selection process before terminal devices can access the fixed network.

[0100] See Figure 6 This diagram illustrates a screen selection method, which mainly includes the following steps:

[0101] S601, the terminal device receives a message from at least one access network device, wherein the message sent by each access network device includes capability information of the access network device and / or identification information indicating the fixed network supported by the access network device. Optionally, the message may be sent in the form of a broadcast.

[0102] The capability information indicates whether the access network device supports fixed-line network transmission, or whether it supports data transmission from fixed-line terminals such as home gateways. The aforementioned identification information may be a fixed-line network identifier and / or a fixed-line service provider identifier. An access network device may support one or more fixed-line networks, and each fixed-line network may include (or correspond to) at least one fixed-line gateway device. For example, if an access network device supports one fixed-line network, the access network device may connect to at least one fixed-line gateway device in that fixed-line network. Similarly, if an access network device supports multiple fixed-line networks, the access network device may connect to at least one fixed-line gateway device in each fixed-line network.

[0103] Optionally, the message may also include network priority information, which indicates the priority of the mobile operator to which the access network device belongs. The mobile operator is capable of providing mobile network capabilities. Specifically, corresponding to the aforementioned scenario: the access network device may be deployed by a mobile operator, and the fixed-line network operator to which the fixed-line gateway device belongs may lease the access network device through a contract with a mobile operator. That is, the access network device serves both mobile operator terminals and fixed-line network operator terminals (i.e., fixed-line terminals). Fixed-line network operators may have contracts with multiple mobile operators; therefore, in the area where the terminal device is located, access network devices from different mobile operators may be capable of providing fixed-line transmission capabilities. In this case, network priority information can be used to indicate the priority of each mobile operator's network, allowing the terminal device to select a suitable network based on the network priority information, choosing a cell that can provide fixed-line transmission capabilities.

[0104] As an example, Figure 6 Three access network devices are shown: Access Network Device 1, Access Network Device 2, and Access Network Device 3. Figure 6 S601 in the diagram specifically illustrates how the terminal device receives broadcast messages from access network device 1, access network device 2, and access network device 3.

[0105] S602, the terminal device performs network selection and cell selection based on the messages sent by each access network device.

[0106] Specifically, the terminal device can select a network (hereinafter referred to as network selection) and a cell based on at least one of the following: the capability information of each access network device, the fixed network identifier, the fixed network service provider identifier, and the network priority information. For example, the terminal device can select an access network device that supports fixed network transmission, and the terminal device can select a fixed network from the fixed networks corresponding to one or more fixed network gateway devices supported by the access network device that supports fixed network transmission, such as selecting the fixed network network corresponding to the first fixed network gateway device.

[0107] S603 If the terminal device selected access network device 1 in S602, then the terminal device can establish a control plane connection with access network device 1, or the terminal device can establish a radio resource control (RRC) signaling connection with access network device 1.

[0108] Specifically, the terminal device may send a connection request to the access network device 1, the connection request being used to request the establishment of a control plane connection; the access network device and the terminal device establish the control plane connection. Optionally, the connection request may also include information indicating that the terminal device is of a target type, the target type including one or more of a home gateway, a home terminal, and a client terminal device.

[0109] See Figure 7 This diagram illustrates another screen selection method, which mainly includes the following steps:

[0110] S701, the terminal device selects one of the at least one access network device and establishes a control plane connection with that access network device.

[0111] Optionally, the terminal device can receive network information sent by at least one access network device and select a network according to configuration information. This network information can be sent in broadcast form. The terminal device can also select an accessible cell based on requirements such as cell signal quality and establish a control plane connection with the access network device corresponding to the selected network. For example, Figure 7 The diagram illustrates three access network devices: Access Network Device 1, Access Network Device 2, and Access Network Device 3. The terminal device selects Access Network Device 1 and establishes a control plane connection (RRC connection) with it.

[0112] S702, the terminal device sends a first RRC message to the access network device 1. The first RRC message includes at least one of the following: information indicating that the type of the terminal device is the target type, the target type including one or more of home gateway, home terminal, and client terminal device; identification information of the fixed network to which the terminal device requests access, the aforementioned identification information of the fixed network may include a fixed network identifier and / or an identifier provided by the service provider.

[0113] S703, Access Network Device 1 determines whether it supports fixed network transmission and data transmission requested by terminal devices.

[0114] When access network device 1 learns from the first RRC message that the terminal device is a fixed network terminal such as a home gateway, client terminal, or home terminal, and determines that it can support fixed network transmission, it can determine whether it can support the data transmission requested by the aforementioned terminal device based on the fixed network identifier / service provider identifier.

[0115] If so, then execute S704: Access network device 1 sends a second RRC message to the terminal device. The second RRC message is used to indicate acceptance or support for the data transmission of the terminal device. When access network device 1 determines that it can support the data transmission of the aforementioned terminal device, it may also choose not to send an RRC message, indicating that it accepts or supports the data transmission of the terminal device by default, and maintains the control plane connection.

[0116] Otherwise, steps S705 and S706 are executed. S705: Access network device 1 sends a third RRC message to the terminal device, which includes information instructing the terminal device to perform network reselection and / or cell reselection. S706: Access network device 1 releases the control plane connection (or RRC connection) with the terminal device. Furthermore, if access network device 1 does not support the terminal device's data transmission, the network selection procedure needs to be re-executed until a suitable network and cell supporting the terminal device's data transmission is selected.

[0117] Then, the process of terminal devices accessing the fixed network and transmitting data is described in detail below, combining Scheme 1 and Scheme 2.

[0118] Option 1:

[0119] See Figure 8 This application provides a protocol stack architecture, specifically illustrating the control plane protocol stack and the user plane protocol stack. As an optional implementation, this protocol stack architecture can be constructed by implementing Scheme Two, or it can be understood that this protocol stack architecture can be applied to Scheme One. It should also be noted that... Figure 8 The illustrated protocol stack is only one possible implementation method. Other protocol stack architectures can also be used in this solution, and this application embodiment does not limit them.

[0120] The control plane protocol stack on both the terminal device and access network device sides consists of the following layers: RRC layer, Packet Data Convergence Protocol (PDCP) layer, Radio Link Control (RLC) layer, Medium Access Control (MAC) layer, and Physical (PHY) layer. The user plane protocol stack on the terminal device side consists of the IPoE / PPPoE protocol layer, 802.1ad protocol layer, Service Data Adaptation Protocol (SDAP) layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer. The user plane protocol stack on the access network device side, communicating with the terminal device, consists of the 802.1ad protocol layer, SDAP layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer. The user plane protocol stack on the access network device side, communicating with the fixed network gateway device, consists of the 802.1ad protocol layer, MAC layer, and PHY layer. The user plane protocol stack on the fixed network gateway device side is divided into the IPoE / PPPoE protocol layer, the 802.1ad protocol layer, the MAC layer, and the PHY layer.

[0121] Access network equipment supports 3GPP access types, allowing terminal devices to transmit with it via 3GPP technology (or cellular air interface). For example, a terminal device can establish a control plane connection with the access network equipment, and control plane messages can be transmitted via RRC signaling; a terminal device can also establish a user plane connection with the access network equipment, and user plane messages can be transmitted through this connection. The access network equipment acts as a switch, transmitting data with the fixed-line gateway equipment via a wired connection. Therefore, the terminal device can establish a connection with the fixed-line gateway equipment through the access network equipment, i.e., ... Figure 8 As illustrated, the terminal device communicates with the fixed-line gateway device using PPPoE or IPoE protocols. The access network device acts as a forwarding mechanism, capable of forwarding data from the terminal device to the fixed-line gateway device and vice versa. The access network device can be understood as a bridge between the terminal device and the fixed-line gateway device. It should also be noted that, since there is no need to interact with the core network, the terminal device in this solution does not need to support core network-related protocol layers, such as the non-access stratum (NAS) layer.

[0122] The following provides a detailed description of different implementation methods for performing authentication and / or certification of terminal devices during network access.

[0123] Method 1: The access network device obtains the information used for terminal device authentication and authorization, and performs the terminal device authentication and authorization.

[0124] See Figure 9 This illustrates a communication method, which mainly includes the following process.

[0125] S901, the access network device obtains first information, namely, that the access network device supports 3GPP access types. This support for 3GPP access types may include support for air interface transmission of wireless networks such as 4G / 5G.

[0126] The first information may be information pre-configured in the access network device or obtained from at least one fixed-line gateway device connected to the access network device; wherein, the first information includes subscription data information corresponding to at least one terminal device, the subscription data information being used to determine whether the terminal device is allowed to obtain fixed-line services provided by the fixed-line gateway device, or the subscription data information being used to determine whether the terminal device is not allowed to obtain fixed-line services provided by the fixed-line gateway device. The subscription data information may include one or more of fixed-line service information, quality of service (QoS) information, and priority information, the QoS information and / or priority information being used as the basis for subsequently configuring user plane resources for the terminal device.

[0127] In addition, the first information may also include security context information of at least one terminal device and an identifier set; wherein, the security context information is used to establish a secure connection between the access network device and the terminal device, and the security context information may specifically include one or more of the information used to establish a secure connection, such as a root key, public key, private key, and certificate. Establishing a secure connection may include authentication procedures or key negotiation procedures. The identifier set may include a first sequence set and a second sequence set. It can be understood that the first sequence set includes at least one sequence number currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers not currently used to indicate the security context information of the terminal device. The sequence numbers in the first sequence set / second sequence set can be dynamically changed. For example, after completing an authentication process, a sequence number can be selected from the second sequence set, such as denoted as sequence number A; the sequence number currently corresponding to the security context information involved in the authentication process (such as denoted as sequence number B) is replaced with the previously selected sequence number A. That is, the selected sequence number A is incorporated into the first sequence set, while the original sequence number B in the first sequence set is removed. Optionally, sequence number B can also be incorporated into the second sequence set for subsequent reuse.

[0128] S902, the access network device obtains fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device.

[0129] The first terminal device can be any one of the at least one terminal devices mentioned in S901. Optionally, the fourth information includes the first serial number corresponding to the security context information of the first terminal device.

[0130] The fourth information may further include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device. The identification information of the fixed network may include the fixed network identifier and / or the fixed network service provider identifier. For example, if the fixed network gateway device supported by the first terminal device is a first fixed network gateway device, meaning that the first fixed network gateway device can provide fixed network services to the first terminal device, the fourth information includes the identification information of the fixed network corresponding to the first fixed network gateway device. The first fixed network gateway device may be included in at least one fixed network gateway device connected to the access network device.

[0131] Before the access network device obtains the fourth information, the first terminal device can also complete the network selection using either of the two aforementioned network selection methods. It can be understood that the first terminal device has selected the access network device described in S902, and the first terminal device establishes a control plane connection with that access network device. Then, the access network device can receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device.

[0132] For example, Figure 9 The process is illustrated in S902 as follows: The first terminal device completes network selection and establishes a control plane connection with the access network device. The access network device receives the fourth information from the first terminal device through the control plane connection.

[0133] S903, the access network device establishes a secure connection between the access network device and the first terminal device based on the fourth information.

[0134] The access network device can obtain security context information and an identifier set of at least one terminal device. For example, based on the first information described in S901 above, the access network device can obtain security context information and an identifier set of at least one terminal device from the first information. Then, if the access network device determines that the first sequence number set in the identifier set includes a first sequence number, the access network device can obtain the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device according to the first sequence number, and establish a secure connection between the access network device and the first terminal device using the security context information of the first terminal device. For example, the access network device can perform mutual authentication with the first terminal device based on the security context information corresponding to the first sequence number to determine that both the access network device and the first terminal device are trusted devices for each other.

[0135] After a secure connection is established between the access network device and the first terminal device, the access network device can replace the first sequence number with a second sequence number from the second sequence number set and send the second sequence number to the first terminal device. The second sequence number is used to indicate the security context information of the first terminal device. Alternatively, it can be understood that after a secure connection is established between the access network device and the first terminal device, the sequence number stored in the first terminal device to indicate the security context information of the first terminal device is updated from the original first sequence number to the second sequence number. It should also be noted that the implementation time (or implementation phase) for replacing the first sequence number with the second sequence number can be immediately following S903, such as replacing the first sequence number with the second sequence number after S903 and before S904; or, it can be done after the first terminal device accesses the fixed network. This application embodiment does not limit the specific implementation time of the operation of replacing the first sequence number with the second sequence number. As an example, Figure 9 S912 to S914, following S911, illustrate the operation of replacing the first serial number with the second serial number.

[0136] S904, the access network device establishes a user plane connection with the first terminal device based on the first information.

[0137] Specifically, the access network device determines whether the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device based on the subscription data information of the first terminal device. If it is determined that the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device, the access network device establishes a user plane connection with the first terminal device, i.e., establishes user plane resources such as data radio bearer (DRB), based on the fixed-line service information, priority information, QoS information, etc. in the subscription data information corresponding to the first terminal device, and continues to execute the process after S904. If it is determined that the first terminal device is not allowed to access the fixed-line services provided by the first fixed-line gateway device, the process after S904 can be skipped, or the process after S904 can continue to be executed.

[0138] Furthermore, regarding the aforementioned provision that the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device, this can be understood as the first terminal device having the access permission and being able to access the fixed-line services provided by the first fixed-line gateway device; or, in other words, the first terminal device has activated the fixed-line services provided by the first fixed-line gateway device. Conversely, regarding the aforementioned provision that the first terminal device is not allowed to access the fixed-line services provided by the first fixed-line gateway device, this can be understood as the first terminal device lacking the access permission and being unable to access the fixed-line services provided by the first fixed-line gateway device; or, in other words, the first terminal device has not activated the fixed-line services provided by the first fixed-line gateway device.

[0139] S905, the access network device sends second information to the first fixed network gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed network gateway device.

[0140] In one optional implementation, if the first terminal device and the first fixed-line gateway device need to communicate via the IPoE protocol, the access network device can obtain a DHCP Discover message from the first terminal device. If it is determined that the first terminal device is allowed to obtain the fixed-line services provided by the first fixed-line gateway device, the access network device adds an accessible identifier to the DHCP Discover message sent by the first terminal device. The accessible identifier is used to indicate that the first terminal device is allowed to obtain the fixed-line services provided by the first fixed-line gateway device. If it is determined that the first terminal device does not support the fixed-line services provided by the first fixed-line gateway device, the access network device adds an inaccessible identifier to the DHCP Discover message sent by the first terminal device. The inaccessible identifier is used to indicate that the first terminal device is not allowed to obtain the fixed-line services provided by the first fixed-line gateway device. Optionally, the first terminal device can send the DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, the first terminal device can also send the DHCP Discover message to the access network device through the user plane connection between the first terminal device and the access network device. This is not limited here.

[0141] In another optional implementation, if the first terminal device and the first fixed-line gateway device need to communicate via the PPPoE protocol, the access network device can obtain a PPPoE active discovery initiation (PADI) message from the first terminal device. If it is determined that the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device, the access network device adds an accessibility flag to the PADI message sent by the first terminal device. The accessibility flag indicates that the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device. If it is determined that the first terminal device is not allowed to access the fixed-line services provided by the first fixed-line gateway device, the access network device adds an inaccessibility flag to the PADI message sent by the first terminal device. The inaccessibility flag indicates that the first terminal device is not allowed to access the fixed-line services provided by the first fixed-line gateway device. Optionally, the first terminal device can also send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, the first terminal device can also send a PADI message to the access network device through the user plane connection between the first terminal device and the access network device. Regarding the accessible and inaccessible identifiers: In one optional implementation, the first information obtained by the access network device in S901 may further include a set of accessible identifiers and a set of inaccessible identifiers. The access network device may select an accessible identifier from the aforementioned set of accessible identifiers and add it to a DHCP Discover message or a PADI message to generate the aforementioned second information. It can be understood that the second information refers to a DHCP Discover message with an accessible identifier added or a PADI message with an accessible identifier added. For example, the accessible or inaccessible identifiers may be represented by Line IDs. For instance, the set of accessible identifiers may include one or more accessible Line IDs, and the set of inaccessible identifiers may include one or more inaccessible Line IDs. That is, the Line ID in this first method is used to indicate whether the terminal device supports the fixed-line services supported by the fixed-line gateway device. In another optional implementation, the values ​​of the accessible and inaccessible identifiers are different. For example, the accessible identifier may be "1" and the inaccessible identifier may be "0"; or, the accessible identifier may be "0" and the inaccessible identifier may be "1".

[0142] For example, Figure 9Taking the communication between the first terminal device and the first fixed network gateway device via the IPoE protocol as an example, S905 is illustrated as follows: the first terminal device sends a DHCP discovery message to the access network device; the access network device adds an accessibility identifier to the DHCP discovery message sent by the first terminal device, i.e., generates second information; the access network device sends the DHCP discovery message with the accessibility identifier added to the first fixed network gateway device.

[0143] S906, the first fixed-line gateway device sends the received DHCP discovery message to the DHCP server.

[0144] S907, the DHCP server sends an access request message to the AAA server. This access request message carries the accessibility identifier or inaccessibility identifier from the DHCP discovery message, so that the AAA server can determine whether the first terminal device can access the fixed network corresponding to the first fixed network gateway based on the aforementioned accessibility identifier or inaccessibility identifier. Alternatively, it can be understood that the AAA server further authenticates the first terminal device based on the aforementioned access network device authentication or authorization, and determines whether the first terminal device can pass the authentication.

[0145] S908, if the AAA server obtains an accessible identifier, the AAA server can send an access accept message to the DHCP server; if the AAA server obtains an inaccessible identifier, the AAA server can send an access deny message to the DHCP server.

[0146] For example, Figure 9 The diagram illustrates the situation where the AAA server sends an access acceptance message to the DHCP server.

[0147] S909, if the DHCP server receives an access accept message, the DHCP server can send a DHCP offer message to the first terminal device through the first fixed network gateway device and the access network device; if the DHCP server receives an access deny message, the DHCP server can send a DHCP NACK message to the first terminal device through the first fixed network gateway device and the access network device.

[0148] It is understandable that the DHCP server can send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device.

[0149] For example, Figure 9The diagram illustrates the process of a DHCP server sending a DHCP response message to a first terminal device through a first fixed-line gateway device and an access network device. Specifically, this includes: the DHCP server sending a DHCP response message to the first fixed-line gateway device; the first fixed-line gateway device forwarding the DHCP response message to the access network device; and the access network device forwarding the DHCP response message to the first terminal device.

[0150] S910, the first terminal device can send a DHCP request message to the DHCP server through the access network device and the first fixed network gateway device.

[0151] S911, the DHCP server can send third information to the first terminal device through the first fixed-line gateway device and the access network device. This third information indicates that the connection between the first terminal device and the first fixed-line gateway device has been successfully established. Specifically, the DHCP server sends the third information to the first fixed-line gateway device, the first fixed-line gateway device forwards the third information to the access network device, and the access network device forwards the third information to the first terminal device. If the access network device receives the third information, it can determine that the connection between the first terminal device and the first fixed-line gateway device has been successfully established. If the access network device does not receive the third information, it can be considered that the connection between the first terminal device and the first fixed-line gateway device has not been successfully established.

[0152] Optional, such as Figure 9 The S911 diagram shows that the third information can be implemented using a DHCP ACK message.

[0153] S912, the access network device replaces the first serial number with the second serial number in the second serial number set.

[0154] In S913, the access network device sends an update instruction to the first terminal device, which instructs the first terminal device to update the serial number corresponding to its security context information. This update instruction may include a second serial number. Further, the update instruction may also include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S902. Additionally, this update instruction can also be understood as instructing the first terminal device to update the fourth information.

[0155] S914, in response to the update instruction information, the first terminal device sends an update response information to the access network device, which is used to indicate that the first terminal device has successfully received the update instruction information.

[0156] Furthermore, it should be noted that if the first terminal device and the first fixed-line gateway device need to communicate via the PPPoE protocol, the DHCP discovery message sent by the first terminal device in S906 can be replaced with a PADI message. Subsequent steps S907 to S911 can also be adjusted based on the PPPoE communication process as described in S42 to S48, which will not be elaborated upon in this embodiment. Depending on actual needs, some or all of the processes S901 to S911 involved in Method 1 can be selectively executed. That is, it should be understood that some processes in S901 to S911 can be considered optional processes, which can be executed or not, and this embodiment does not impose any restrictions on this. For example, for scenarios where terminal device authentication is not required, S904 can be executed after S901, without executing S902 to S903, or S902 to S904 can be omitted. This embodiment does not restrict the execution order of processes S901 to S914; the execution order of some processes can be changed or executed in parallel depending on the actual situation.

[0157] Further, see Figure 10 Regarding data transmission from the first terminal device, the following method can be used:

[0158] S1001, the first terminal device sends user plane data to the access network device via a user plane connection. The access network device then sends the user plane data from the first terminal device to the first fixed network gateway device, which in turn sends the user plane data to the application server. The user plane data sent by the first terminal device can also be understood as uplink data. The user plane data sent by the first terminal device can be its own user plane data, or it can be user plane data from other terminal devices within the coverage area of ​​the first terminal device that use the first terminal device to provide wireless LAN communication capabilities.

[0159] S1002, the application server sends the user plane data of the first terminal device to the first fixed network gateway device. The first fixed network gateway device sends the user plane data received from the AAA to the access network device, and then the access network device sends the user plane data from the first fixed network device to the first terminal device through the user plane connection. The user plane data from the application server can also be understood as downlink data.

[0160] It should be noted that the execution order of S1001 and S1002 is not limited in the embodiments of this application. S1001 can be executed first and then S1002; or S1002 can be executed first and then S1001.

[0161] The method one provided in this application simplifies the access process for terminal devices, saves signaling overhead, and reduces costs. Furthermore, performing authentication and authorization on the terminal devices ensures secure transmission.

[0162] Method 2: The access network device performs terminal device authentication based on the information used for terminal device authentication, and the fixed network gateway device performs terminal device authentication.

[0163] See Figure 11 This illustrates a communication method, which mainly includes the following process.

[0164] S1101, the access network device obtains security context information and an identifier set of at least one terminal device, wherein the access network device supports 3GPP access types. It can be understood that the access network device supporting 3GPP access types may include the access network device supporting air interface transmission technologies such as 4G / 5G.

[0165] Specifically, the security context information and identifier set of the aforementioned at least one terminal device may be pre-configured in the access network device or may come from at least one fixed network gateway device.

[0166] Security context information is used to establish a secure connection between access network devices and terminal devices. This security context information can specifically include one or more of the following: root key, public key, private key, certificate, etc., used to establish a secure connection. Establishing a secure connection may include authentication procedures or key negotiation procedures. The identifier set may include a first sequence set and a second sequence set. The first sequence set includes at least one sequence number currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers not currently used to indicate the security context information of the terminal device. The sequence numbers in the first / second sequence sets can be dynamically changed. For example, after completing an authentication process, a sequence number can be selected from the second sequence set, such as sequence number A; the sequence number currently corresponding to the security context information involved in that authentication process (such as sequence number B) can be replaced with the previously selected sequence number A. That is, the selected sequence number A is merged into the first sequence set, while the original sequence number B in the first sequence set is removed. Optionally, sequence number B can also be merged into the second sequence set for later reuse.

[0167] S1102, the access network device obtains fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device.

[0168] The first terminal device can be any one of the at least one terminal device mentioned in S1101. Optionally, the fourth information includes the first serial number corresponding to the security context information of the first terminal device.

[0169] The fourth information may further include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device. The identification information of the fixed network may include the fixed network identifier and / or the fixed network service provider identifier. For example, if the fixed network gateway device supported by the first terminal device is a first fixed network gateway device, meaning that the first fixed network gateway device can provide fixed network services to the first terminal device, the fourth information includes the identification information of the fixed network corresponding to the first fixed network gateway device. The first fixed network gateway device may be included in at least one fixed network gateway device connected to the access network device.

[0170] Before the access network device obtains the fourth information, the first terminal device can also complete the network selection using either of the two aforementioned network selection methods. It can be understood that the first terminal device has selected the access network device described in S1102, and the first terminal device establishes a control plane connection with the access network device. Then, the access network device can receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device. Furthermore, during the network selection process, the access network device can obtain first information from the terminal device, which indicates that the type of the first terminal device is the target type, and the target type includes one or more of home gateway, home terminal, and client terminal device.

[0171] For example, Figure 11 The process is illustrated in S1102 as follows: The first terminal device completes network selection and establishes a control plane connection with the access network device. The access network device receives the fourth information from the first terminal device through the control plane connection.

[0172] S1103, the access network device establishes a secure connection between the access network device and the first terminal device based on the fourth information.

[0173] Specifically, the access network device can obtain security context information and an identifier set of at least one terminal device. For example, based on the first information described in S1101 above, the access network device can obtain security context information and an identifier set of at least one terminal device from the first information; then, the access network device determines that the first sequence number set in the identifier set includes a first sequence number. The access network device can then obtain the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device according to the first sequence number, and establish a secure connection between the access network device and the first terminal device using the security context information of the first terminal device. For example, the access network device can perform mutual authentication with the first terminal device based on the security context information corresponding to the first sequence number to determine that both the access network device and the first terminal device are trusted devices for each other.

[0174] A secure connection is established between the access network device and the first terminal device. The access network device can also replace the first sequence number with a second sequence number from the second sequence number set and send the second sequence number to the first terminal device. The second sequence number is used to indicate the security context information of the first terminal device. Alternatively, it can be understood that after the secure connection between the access network device and the first terminal device is established, the sequence number stored in the first terminal device to indicate the security context information of the first terminal device is updated from the original first sequence number to the second sequence number. It should also be noted that the implementation time (or implementation phase) for replacing the first sequence number with the second sequence number can be immediately following S1103, such as replacing the first sequence number with the second sequence number after S1103 and before S1104; or, it can be done after the first terminal device accesses the fixed network. This application embodiment does not limit the specific implementation time of the operation of replacing the first sequence number with the second sequence number. As an example, Figure 11 S1112 to S1114, following S1111, illustrate the operation of replacing the first serial number with the second serial number.

[0175] S1104, the access network device establishes a user plane connection with the first terminal device.

[0176] It is understood that the user plane connection established in S1104 of this process corresponds to the establishment of temporary user plane resources. These temporary user plane resources can be used to carry the DHCP discovery message or PADI message sent by the first terminal device to the access network device in S1105. Optionally, S1104 can be an optional process. It can be omitted, that is, S1105 can be executed directly after S1103.

[0177] S1105, the access network device sends second information to the first fixed network gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed network gateway device.

[0178] In one optional implementation, if the first terminal device and the first fixed network gateway device need to communicate via the IPoE protocol, the access network device can obtain a DHCP Discover message from the first terminal device. The access network device adds the identification information of the first terminal device to the DHCP Discover message sent by the first terminal device. This identification information can be determined based on the MAC address of the first terminal device or the aforementioned first serial number. For example, the identification information can be the first serial number or a line ID; or, the identification information can be determined based on the location of the first terminal device, such as using the Line ID as the identification information in this second method to indicate the location of the first terminal device. Optionally, the first terminal device can send a DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, when performing S1104, i.e., establishing a user plane connection, the first terminal device can also send a DHCP Discover message to the access network device through the user plane connection between the first terminal device and the access network device.

[0179] In another optional implementation, if the first terminal device and the first fixed network gateway device need to communicate via the PPPoE protocol, the access network device can obtain a PPPoE active discovery initiation (PADI) message from the first terminal device. The access network device adds the identification information of the first terminal device to the PADI message sent by the first terminal device. This identification information can be determined based on the MAC address of the first terminal device or the aforementioned first serial number. For example, the identification information of the first terminal device can be the first serial number or a line ID; or, the identification information of the first terminal device can be determined based on the location of the first terminal device. For example, in this second method, the Line ID can be used as the identification information of the first terminal device to indicate its location. Optionally, the first terminal device can send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, when performing S1104, i.e., establishing a user plane connection, the first terminal device can also send a PADI message to the access network device through the user plane connection between the first terminal device and the access network device. For example, Figure 11Taking the communication between the first terminal device and the first fixed network gateway device via the IPoE protocol as an example, S1105 is illustrated as follows: the first terminal device sends a DHCP discovery message to the access network device; the access network device adds the identification information of the first terminal device to the DHCP discovery message sent by the first terminal device, that is, generates the second information; the access network device sends the DHCP discovery message with the identification information of the first terminal device added to it to the first fixed network gateway device.

[0180] S1106, the first fixed-line gateway device sends the received DHCP discovery message to the DHCP server.

[0181] S1107, the DHCP server sends an access request message to the AAA server. This access request message carries the identification information of the first terminal device.

[0182] The AAA server can determine the subscription data information corresponding to the first terminal device based on the identification information of the first terminal device. This subscription data information is used to determine whether the first terminal device is allowed to access fixed-line services provided by the first fixed-line gateway device, or to determine whether the first terminal device is not allowed to access fixed-line services provided by the first fixed-line gateway device. The subscription data information may include one or more of fixed-line service information, QoS information, and priority information. The QoS information and / or priority information can be used as a basis for subsequent adjustments to the temporary user plane resources previously configured on the first terminal device. Therefore, the AAA server can determine whether the first terminal device is allowed to access fixed-line services provided by the first fixed-line gateway device, or in other words, whether the first terminal device has passed authentication, based on the subscription data information corresponding to the first terminal device.

[0183] Specifically, the statement that the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device can be understood as the first terminal device having the permission to access these services, and being able to access them; or, in other words, the first terminal device has activated the fixed-line services provided by the first fixed-line gateway device. Conversely, the statement that the first terminal device is not allowed to access the fixed-line services provided by the first fixed-line gateway device can be understood as the first terminal device lacking the permission to access these services, and being unable to access them; or, in other words, the first terminal device has not activated the fixed-line services provided by the first fixed-line gateway device.

[0184] S1108, if the AAA server determines that the first terminal device has passed authentication, the AAA server may send an access accept message to the DHCP server; if the AAA server determines that the first terminal device has failed authentication, the AAA server may send an access deny message to the DHCP server.

[0185] For example, Figure 11 The diagram illustrates the situation where the AAA server sends an access acceptance message to the DHCP server.

[0186] S1109, if the DHCP server receives an access accept message, the DHCP server can send a DHCP offer message to the first terminal device through the first fixed network gateway device and the access network device; if the DHCP server receives an access deny message, the DHCP server can send a DHCP NACK message to the first terminal device through the first fixed network gateway device and the access network device.

[0187] It is understandable that the DHCP server can send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device.

[0188] For example, Figure 11 The diagram illustrates the process of a DHCP server sending a DHCP response message to a first terminal device through a first fixed-line gateway device and an access network device. Specifically, this includes: the DHCP server sending a DHCP response message to the first fixed-line gateway device; the first fixed-line gateway device forwarding the DHCP response message to the access network device; and the access network device forwarding the DHCP response message to the first terminal device.

[0189] S1110, the first terminal device can send a DHCP request message to the DHCP server through the access network device and the first fixed network gateway device.

[0190] S1111, the DHCP server can send third information to the first terminal device through the first fixed network gateway device and the access network device. The third information is used to indicate that the connection between the first terminal device and the first fixed network gateway device has been successfully established.

[0191] Specifically, the DHCP server sends a third message to the first fixed-line gateway device, which then forwards the third message to the access network device, which in turn forwards it to the first terminal device. If the access network device receives the third message, it can determine that the connection between the first terminal device and the first fixed-line gateway device has been successfully established. If the access network device does not receive the third message, it can be considered that the connection between the first terminal device and the first fixed-line gateway device has not been successfully established.

[0192] Optional, such as Figure 11 The S1111 diagram illustrates that the third piece of information can be implemented using a DHCP ACK message.

[0193] The aforementioned third information may further include at least one of the following: identification information of the first terminal device; authentication information of the first terminal device, wherein the authentication information is used to indicate that the first terminal device has passed authentication by the fixed network corresponding to the first fixed network gateway device, or the authentication information is used to indicate that the first terminal device has failed authentication by the fixed network corresponding to the first fixed network gateway device; and subscription data information corresponding to the first terminal device, wherein the subscription data information includes one or more of fixed network service information, QoS information, and priority information. For example, when the third information is implemented using a DHCP ACK message, the DHCP ACK message may include the subscription data information and the authentication information of the first terminal device, wherein the authentication information included in the DHCP ACK message is used to indicate that the first terminal device has passed authentication by the fixed network corresponding to the first fixed network gateway device; or, the DHCP ACK message indicating that the first terminal device has passed authentication by the fixed network corresponding to the first fixed network gateway device may only include the subscription data information of the first terminal device.

[0194] For example, when the third information is implemented using a DHCP NACK message, the DHCP NACK message may include the identification information and / or authentication information of the first terminal device. If the DHCP NACK message includes the authentication information of the first terminal device, the authentication information is used to indicate that the first terminal device has not passed the authentication of the fixed network corresponding to the first fixed network gateway device; or if the DHCP NACK message does not include the authentication information of the first terminal device, the device receiving the DHCP NACK message may also determine, based on the DHCP NACK message and the identification information of the first terminal device therein, that the first terminal device has not passed the authentication of the fixed network corresponding to the first fixed network gateway device.

[0195] Furthermore, the access network device can execute a user plane connection management process based on the third information. This user plane connection management process includes at least one of the following operations: reserving user plane resources, establishing user plane resources, modifying user plane resources, or releasing user plane resources.

[0196] For example, regarding reserving user plane resources: the access network device can reserve temporary user plane resources based on the subscription data information corresponding to the first terminal device without adjusting them. Regarding establishing user plane resources: the access network device can add new user plane resources based on the subscription data information corresponding to the first terminal device, building upon the aforementioned temporary user plane resources. Regarding modifying user plane resources: the access network device can modify user plane resources based on the aforementioned temporary user plane resources, building upon the aforementioned temporary user plane resources, building upon the subscription data information corresponding to the first terminal device. Regarding releasing user plane resources: the access network device can release the aforementioned temporary user plane resources upon receiving a message such as a DHCP NACK message.

[0197] S1112, the access network device replaces the first serial number with the second serial number in the second serial number set.

[0198] S1113, the access network device sends an update instruction information to the first terminal device, which instructs the first terminal device to update the serial number corresponding to its security context information.

[0199] Optionally, the update instruction information may include a second serial number. Further, the update instruction information may also include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S1102. Additionally, the update instruction information can also be understood as instructing the first terminal device to update the fourth information.

[0200] S1114, in response to the update instruction information, the first terminal device sends an update response information to the access network device. The update response information is used to indicate that the first terminal device has successfully received the update instruction information.

[0201] Furthermore, it should be noted that if the first terminal device and the first fixed-line gateway device need to communicate via the PPPoE protocol, the DHCP discovery message sent by the first terminal device in S1105 can be replaced with a PADI message. Subsequent steps S1107 to S1111 can also be adjusted based on the PPPoE communication process as described in S42 to S48 above; this embodiment will not elaborate further. Depending on actual needs, some or all of the processes S1101 to S1111 involved in Method 1 can be selectively executed. That is, it should be understood that some processes in S1101 to S1111 can be considered optional processes, which can be executed or not, and this embodiment does not impose any restrictions on this. For example, in scenarios where terminal device authentication is not required, S1104 can be executed after S1101, without executing S1102 to S1103, or S1102 to S1104 can be omitted. The embodiments of this application do not restrict the execution order of processes S1101 to S1114. Depending on the actual situation, the execution order of some processes can be changed or they can be executed in parallel.

[0202] Furthermore, regarding data transmission from the first terminal device, please refer to... Figure 10 The implementation method is as described in the previous embodiment, and will not be repeated here.

[0203] The second method provided in this application simplifies the access process for terminal devices, saving signaling overhead and reducing costs. The access network device executes the authentication process for the terminal device. After authentication, the access network device can establish temporary user plane resources with the terminal device to forward messages related to the terminal device's desire to establish an IPoE or PPPoE connection. By including the terminal device's subscription data information in the DHCP ACK message, the access network device can establish or modify the terminal device's user plane resources in a targeted manner based on this subscription data information, enabling differentiated processing between different terminal devices and improving user experience.

[0204] Method 3: The fixed network gateway device performs authentication of the terminal device and sends authentication information to the access network device. The access network device establishes a secure connection with the terminal device based on the authentication information (when authentication is successful) or releases air interface resources (when authentication fails).

[0205] See Figure 12 This illustrates a communication method, which mainly includes the following process.

[0206] S1201, the first terminal device completes network selection and establishes a control plane connection with the access network device.

[0207] The first terminal device can complete network selection using either of the two aforementioned network selection methods. It can be understood that the first terminal device has selected... Figure 12 The access network device described herein and the fixed network corresponding to the first fixed network gateway device, wherein the first terminal device establishes a control plane connection with the access network device.

[0208] During the network selection process, the access network device can obtain first information from the terminal device, which can indicate that the type of the first terminal device is the target type. The target type includes one or more of home gateway, home terminal, and client terminal device.

[0209] S1202, the access network device establishes a user plane connection with the first terminal device.

[0210] It is understandable that the user plane connection established in S1204 of this process corresponds to the establishment of temporary user plane resources. These temporary user plane resources can be used to carry the DHCP discovery message or PADI message sent by the first terminal device to the access network device in S1203. S1202 can be considered an optional process and can be omitted, meaning that S1203 can be executed directly after S1201.

[0211] S1203, the access network device sends second information to the first fixed network gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed network gateway device.

[0212] In one optional implementation, if the first terminal device and the first fixed network gateway device need to communicate via the IPoE protocol, the access network device can obtain a DHCP Discover message from the first terminal device. The access network device adds the identification information of the first terminal device to the DHCP Discover message sent by the first terminal device. This identification information can be determined based on the MAC address or the C-RNTI of the first terminal device, where C-RNTI refers to the identifier used by the access network device to mark the first terminal device. Alternatively, the identification information can be determined based on the location of the first terminal device; for example, in this third embodiment, Line ID can be used as the identification information of the first terminal device to indicate its location. Optionally, the first terminal device can send a DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, if S1202 is executed, i.e., a user plane connection is established, the first terminal device can also send a DHCP Discover message to the access network device through the user plane connection between the first terminal device and the access network device.

[0213] In another optional implementation, if the first terminal device and the first fixed network gateway device need to communicate via the PPPoE protocol, the access network device can obtain a PPPoE active discovery initiation (PADI) message from the first terminal device. The access network device can add the identification information of the first terminal device to the PADI message sent by the first terminal device, which can be determined based on the MAC address or the C-RNTI of the first terminal device. The C-RNTI refers to the identifier used by the access network device to mark the first terminal device. Alternatively, the identification information of the first terminal device can be determined based on the location of the first terminal device; for example, in this third method, the Line ID can be used as the identification information of the first terminal device to indicate its location. Optionally, the first terminal device can send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, when performing S1202, i.e., establishing a user plane connection, the first terminal device can also send a PADI message to the access network device through the user plane connection between the first terminal device and the access network device.

[0214] For example, Figure 12 Taking the communication between the first terminal device and the first fixed network gateway device via the PPPoE protocol as an example, S1203 is illustrated as follows: the first terminal device sends a PADI message to the access network device; the access network device adds the identification information of the first terminal device to the PADI message sent by the first terminal device, that is, generates the second information; the access network device sends the PADI message with the identification information of the first terminal device added to it to the first fixed network gateway device.

[0215] S1204 After receiving the PADI message, the first fixed network gateway device responds by sending a PPPoE Active Discovery Offer (PADO) message to the first terminal device through the access network device.

[0216] S1205, the first terminal device sends a PPPoE Active Discovery Request (PADR) message to the first fixed network gateway device through the access network device.

[0217] S1206 After receiving the PADR message, the first fixed network gateway device sends a PPPoE Active Discovery Session-confirmation (PADS) message to the first terminal device through the access network device as a response.

[0218] S1207, the first terminal device, the first fixed-line gateway device, and the AAA server interact to complete the Challenge Handshake Authentication Protocol (CHAP) authentication. Specifically, the first fixed-line gateway device forwards the authentication messages between the first terminal device and the AAA server. This authentication method can be based on a username and password, and the messages are transmitted in encrypted form, making it relatively secure.

[0219] S1208, the first terminal device and the first fixed network gateway device are in the network-side parameter (Network Control Protocol, NCP) negotiation stage, which involves the interaction between the first fixed network gateway device and DHCP. The first terminal device can obtain an IP address in this stage.

[0220] S1209, when the first fixed-line gateway device learns that the first terminal device has passed authentication, it sends third information to the access network device through the interface between the first fixed-line gateway device and the access network device. The third information is used to indicate that the connection between the first terminal device and the first fixed-line gateway device has been successfully established.

[0221] Optionally, the aforementioned third information may include one or more of the following: identification information of the first terminal device; security context information of the first terminal device; authentication information of the first terminal device, wherein the authentication information is used to indicate whether the first terminal device has passed the authentication of the fixed network corresponding to the first fixed network gateway device, or the authentication information is used to indicate whether the first terminal device has passed the authentication of the AAA server associated with the first fixed network gateway device; subscription data information corresponding to the first terminal device, wherein the subscription data information includes one or more of fixed network service information, QoS information, and priority information; and security context information of the first terminal device, wherein the security context information is used to establish a secure connection between the access network device and the first terminal device, and the security context information may specifically include one or more of the following information used to establish a secure connection: root key, public key, private key, certificate, etc. Establishing a secure connection may include an authentication process or a key negotiation process.

[0222] S1210, the access network device can identify the first terminal device based on the identification information of the first terminal device, and when the authentication information of the first terminal device indicates that it has passed the authentication of the AAA server, the access network device uses the security context information of the first terminal device in the third information to establish a secure connection between the access network device and the first terminal device, such as mutual authentication between the access network device and the first terminal device using the security context information of the first terminal device. If the authentication information of the first terminal device indicates that it has not passed the authentication of the AAA server, the access network device does not need to mutually authenticate with the first terminal device.

[0223] As an example, Figure 12 The diagram illustrates the authentication information of the first terminal device, indicating that it has been authenticated by the AAA server.

[0224] S1211, the access network device can execute a user plane connection management procedure based on third information. The user plane connection management procedure includes at least one of the following operations: reserving user plane resources, establishing user plane resources, modifying user plane resources, or releasing user plane resources.

[0225] When the authentication information of the first terminal device indicates that it has passed the authentication of the AAA server, the access network device may perform one or more of the following operations based on the subscription data information of the first terminal device: retain user plane resources, establish user plane resources, or modify user plane resources. When the authentication information of the first terminal device indicates that it has failed the authentication of the AAA server, the access network device may perform the operation of releasing user plane resources.

[0226] For example, regarding the retention of user plane resources: the access network device can retain the temporary user plane resources in S1202 based on the subscription data information corresponding to the first terminal device, without adjusting them. Regarding the establishment of user plane resources: the access network device can add new user plane resources based on the temporary user plane resources in S1202 based on the subscription data information corresponding to the first terminal device. Regarding the modification of user plane resources: the access network device can modify the user plane resources based on the temporary user plane resources based on the subscription data information corresponding to the first terminal device. Regarding the release of user plane resources: the access network device can release the temporary user plane resources when it is determined that the first terminal device has failed authentication by the AAA server.

[0227] The embodiments of this application do not restrict the execution order of S1210 and S1211. S1210 can be executed first and then S1211, or S1211 can be executed first and then S1210.

[0228] Furthermore, it should be noted that if the first terminal device and the first fixed-line gateway device need to communicate via the IPoE protocol, the PADI message sent by the first terminal device in S1204 can be replaced with a DHCP discovery message. Subsequent steps S1205 to S1211 can also be adjusted based on the IPoE communication process as described in S31 to S36 above; this embodiment will not elaborate further. Depending on actual needs, some or all of the processes S1201 to S1211 involved in Method 1 can be selectively executed. That is, it should be understood that some processes in S1201 to S1211 can be considered optional processes, which can be executed or not, and this embodiment does not impose any restrictions on this. For example, for some scenarios where terminal device authentication is not required, S1210 can be omitted. This embodiment does not restrict the execution order of processes S1201 to S1211; the execution order of some processes can be changed or executed in parallel depending on the actual situation.

[0229] Furthermore, regarding data transmission from the first terminal device, please refer to... Figure 10 The implementation method is as described in the previous embodiment, and will not be repeated here.

[0230] The method three provided in this application simplifies the access process for terminal devices, saving signaling overhead and reducing costs. After the terminal device completes authentication with the fixed-line gateway device, the fixed-line gateway device sends the authentication result, security context information, priority information, QoS information, etc., of the terminal device to the access network device through an enhanced interface. This reduces the leakage of the aforementioned information and improves communication security. Furthermore, the access network device can also selectively establish or modify the user plane resources of the terminal device based on the priority information and QoS information, enabling differentiated processing between different terminal devices and improving user experience.

[0231] Option 2:

[0232] See Figure 13 This application provides another protocol stack architecture, specifically illustrating the control plane protocol stack and the user plane protocol stack. As an optional implementation, this second solution can be used to construct this protocol stack architecture, or it can be understood that this protocol stack architecture can be applied to this second solution. It should be noted that... Figure 13 As one possible implementation, other protocol stack architectures may also be used in this second solution, and this application does not limit this.

[0233] The control plane protocol stack on both the terminal device and access network device sides consists of the RRC layer, Packet Data Convergence Protocol (PDCP) layer, Radio Link Control (RLC) layer, Medium Access Control (MAC) layer, and Physical (PHY) layer. The user plane protocol stack on the terminal device side consists of the IPoE / PPPoE protocol layer, 802.1ad protocol layer, Service Data Adaptation Protocol (SDAP) layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer. The user plane protocol stack on the access network device side, communicating with the terminal device, consists of the IPoE / PPPoE protocol layer, 802.1ad protocol layer, SDAP layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer. The user plane protocol stack on the access network device side, which communicates with the fixed network gateway device, consists of the IPoE / PPPoE protocol layer, the 802.1ad protocol layer, the MAC layer, and the PHY layer. The user plane protocol stack on the fixed network gateway device side also consists of the IPoE / PPPoE protocol layer, the 802.1ad protocol layer, the MAC layer, and the PHY layer.

[0234] The access network equipment supports 3GPP access types, allowing terminal devices to transmit with it via 3GPP technology (or cellular air interface). For example, the terminal device can establish a control plane connection with the access network equipment, and control plane messages can be transmitted via RRC signaling; the terminal device can also establish a user plane connection with the access network equipment, and user plane messages can be transmitted via the user plane connection. The access network equipment can also establish a connection with the fixed-line gateway equipment, such as a fixed-line connection, and transmit data according to the IPoE / PPPoE protocol. In this case, the access network equipment can send data from the terminal device to the fixed-line gateway equipment, and vice versa. The access network equipment can be understood as a bridge between the terminal device and the fixed-line gateway equipment. It should also be noted that, since there is no need to interact with the core network, the terminal device in this solution does not need to support core network-related protocol layers, such as the non-access stratum (NAS) layer.

[0235] The following provides a detailed description of the implementation methods for performing authentication and / or certification of terminal devices during network access.

[0236] See Figure 14 This illustrates a communication method, which mainly includes the following process.

[0237] S1401, the access network device obtains first information, namely, that the access network device supports 3GPP access types. This support for 3GPP access types may include support for air interface transmission technologies such as 4G / 5G.

[0238] The first information may be information pre-stored in the access network device or obtained from at least one fixed-line gateway device connected to the access network device; wherein, the first information includes subscription data information corresponding to at least one terminal device, the subscription data information being used to determine whether the terminal device is allowed to obtain fixed-line services provided by the fixed-line gateway device, or the subscription data information being used to determine whether the terminal device is not allowed to obtain fixed-line services provided by the fixed-line gateway device. The subscription data information may include one or more of fixed-line service information, QoS information, and priority information, the QoS information and / or priority information being used as the basis for subsequently configuring user plane resources for the terminal device.

[0239] The first information may further include security context information of at least one terminal device and an identifier set; wherein, the security context information may specifically include one or more of the information used to establish a secure connection, such as a root key, public key, private key, and certificate. Establishing a secure connection may include authentication procedures or key negotiation procedures. The identifier set may include a first sequence set and a second sequence set. It can be understood that the first sequence set includes at least one sequence number currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers not currently used to indicate the security context information of the terminal device. The sequence numbers in the first sequence set / second sequence set can be dynamically changed. For example, after completing an authentication process, a sequence number can be selected from the second sequence set, such as denoted as sequence number A; the sequence number currently corresponding to the security context information involved in the authentication process (such as denoted as sequence number B) can be replaced with the previously selected sequence number A. That is, the selected sequence number A is incorporated into the first sequence set, while the original sequence number B in the first sequence set is removed. Optionally, sequence number B can also be incorporated into the second sequence set for subsequent reuse.

[0240] Alternatively, the first information may also include an IP address resource pool, which contains multiple IP addresses to be assigned.

[0241] S1402, the access network device sends a DHCP Discover message or a PADI message to at least one fixed network gateway device. The DHCP Discover message or PADI message is used to request the establishment of a connection between the access network device and at least one fixed network gateway device, such as a fixed network connection.

[0242] For example, DHCP discovery messages or PADI messages can carry accessibility identifiers, such as an accessible LineID, to ensure that the access network device successfully establishes a connection with the fixed network gateway device after authentication. For example, Figure 14 Taking the communication between the access network device and the first fixed network gateway device among at least one fixed network gateway device via the IPoE protocol as an example, S1402 is illustrated as follows: the access network device sends a DHCP discovery message to the first fixed network gateway device.

[0243] S1403, the first fixed-line gateway device sends the received DHCP discovery message to the DHCP server.

[0244] S1404, the DHCP server sends an access request message to the AAA server. This access request message carries the accessibility identifier from the DHCP discovery message, so that the AAA server can determine whether the access network device can be authenticated based on the aforementioned accessibility identifier.

[0245] S1405, if the AAA server obtains the accessibility identifier, the AAA server can send an access accept message to the DHCP server.

[0246] S1406, when the DHCP server receives the access accept message, it can send a DHCP offer message to the access network device through the first fixed network gateway device.

[0247] S1407, the access network device sends a DHCP request message to the DHCP server through the first fixed network gateway device.

[0248] S1408, the DHCP server sends a DHCP ACK message to the access network device through the first fixed network gateway device. The DHCP ACK message indicates that the connection between the access network device and the first fixed network gateway device has been successfully established.

[0249] S1409, the access network device obtains fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device.

[0250] The first terminal device can be any one of the at least one terminal device mentioned in S1401. Optionally, the fourth information includes the first serial number corresponding to the security context information of the first terminal device.

[0251] Optionally, the fourth information may further include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device. The identification information of the fixed network may include a fixed network identifier and / or a fixed network service provider identifier. For example, if the first terminal device supports a fixed network gateway device that is itself a first fixed network gateway device, meaning the first fixed network gateway device can provide fixed network services to the first terminal device, the fourth information includes the identification information of the fixed network corresponding to the first fixed network gateway device. The first fixed network gateway device may be included in at least one fixed network gateway device that has established a connection with the access network device.

[0252] Before the access network device obtains the fourth information, the first terminal device can also complete the network selection using either of the aforementioned two network selection methods. It can be understood that the first terminal device selected... Figure 14 The access network device described herein establishes a control plane connection with the first terminal device. The access network device can then receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device.

[0253] For example, Figure 14 The process is illustrated in S1409 as follows: The first terminal device completes network selection and establishes a control plane connection with the access network device. The access network device receives the fourth information from the first terminal device through the control plane connection.

[0254] S1410, the access network device establishes a secure connection between the access network device and the first terminal device based on the fourth information.

[0255] Specifically, the access network device can obtain security context information and an identifier set of at least one terminal device. For example, based on the first information described in S1401 above, the access network device can obtain security context information and an identifier set of at least one terminal device from the first information; then, the access network device determines that the first sequence number set in the identifier set includes a first sequence number. The access network device can then obtain the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device according to the first sequence number, and establish a secure connection between the access network device and the first terminal device using the security context information of the first terminal device. For example, the access network device can perform mutual authentication with the first terminal device based on the security context information corresponding to the first sequence number to determine that both the access network device and the first terminal device are trusted devices for each other.

[0256] After a secure connection is established between the access network device and the first terminal device, the access network device can replace the first sequence number with a second sequence number from the second sequence number set and send the second sequence number to the first terminal device. The second sequence number is used to indicate the security context information of the first terminal device. Alternatively, it can be understood that after a secure connection is established between the access network device and the first terminal device, the sequence number stored in the first terminal device to indicate the security context information of the first terminal device is updated from the original first sequence number to the second sequence number. It should also be noted that the implementation time (or implementation phase) for replacing the first sequence number with the second sequence number can be immediately following S1410, such as replacing the first sequence number with the second sequence number after S1410 and before S1411; or, it can be done after the first terminal device accesses the fixed network. This application embodiment does not limit the specific implementation time of the operation of replacing the first sequence number with the second sequence number. As an example, Figure 14 S1412 to S1414, following S1411, illustrate the operation of replacing the first serial number with the second serial number.

[0257] S1411, the access network device establishes a user plane connection with the first terminal device based on the first information.

[0258] Optionally, the access network device determines whether the first terminal device is allowed to access the fixed-line services provided by the first fixed-line gateway device based on the subscription data information of the first terminal device. Here, "allowing the first terminal device to access the fixed-line services provided by the first fixed-line gateway device" can be understood as the first terminal device having the permission to access the services, and being able to access the fixed-line services provided by the first fixed-line gateway device; or, in other words, the first terminal device has activated the fixed-line services provided by the first fixed-line gateway device. "Disallowing the first terminal device to access the fixed-line services provided by the first fixed-line gateway device" can be understood as the first terminal device lacking the permission to access the services, and being unable to access the fixed-line services provided by the first fixed-line gateway device; or, in other words, the first terminal device has not activated the fixed-line services provided by the first fixed-line gateway device.

[0259] When the access network device determines that the first terminal device is allowed to obtain the fixed network services provided by the first fixed network gateway device, the access network device establishes a user plane connection with the first terminal device, that is, establishes user plane resources such as data radio bearer (DRB), based on priority information, QoS information, etc. in the subscription data information corresponding to the first terminal device, and allocates an IP address to the first terminal device based on the IP address resource pool of the first information.

[0260] S1412, the access network device replaces the first serial number with the second serial number in the second serial number set.

[0261] S1413, the access network device sends an update instruction information to the first terminal device, which instructs the first terminal device to update the serial number corresponding to its security context information.

[0262] Optionally, the update instruction information may include a second serial number. Further, the update instruction information may also include the identification information of the fixed network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S1410. Additionally, the update instruction information can also be understood as instructing the first terminal device to update the fourth information.

[0263] S1414, in response to the update instruction information, the first terminal device sends an update response information to the access network device. The update response information is used to indicate that the first terminal device has successfully received the update instruction information.

[0264] Furthermore, it should be noted that if the access network device and the first fixed network gateway device need to communicate via the PPPoE protocol, the DHCP discovery message sent by the access network device in S1402 can be replaced with a PADI message. Subsequent steps S1402 to S1408 can also be adjusted based on the PPPoE communication process as described in S42 to S48 above; this embodiment will not elaborate further. Depending on actual needs, some or all of the processes S1401 to S1414 involved in Method 1 can be selectively executed. That is, it should be understood that some processes in S1401 to S1414 can be considered optional processes, which can be executed or not, and this embodiment does not impose any restrictions on this. For example, for some scenarios where sequence number updates and replacements are not required, S1412 to S1414 can be omitted. This embodiment does not restrict the execution order of processes S1401 to S1414; the execution order of some processes can be changed or they can be executed in parallel depending on the actual situation.

[0265] Furthermore, since the access network device in this second scheme has an IPoE or PPPoE protocol stack, it can communicate directly with the fixed-line gateway device as a fixed-line terminal. Optionally, a shared connection can be established for multiple terminal devices connected to the access network device. The RAN can also perform Network Address Translation (NAT) to map the connections between multiple terminal devices and the access network device to the connection between the access network device and the fixed-line gateway device. The following example, using two terminal devices (first terminal device and second terminal device) connected to the access network device, illustrates in detail the method of NAT performed by the access network device during the uplink and downlink data transmission of the terminal devices.

[0266] See Figure 15 This illustrates a data transmission method for a terminal device, which mainly includes the following process.

[0267] S1501a, the first terminal device sends first uplink data to the access network device. The source IP address of the message corresponding to the first uplink data is denoted as IP@1, and the port number is 1.

[0268] S1501b, the second terminal device sends second uplink data to the access network device. The source IP address of the message corresponding to the second uplink data is denoted as IP@2, and the port number is 1.

[0269] The first uplink data sent by the first terminal device can be the user plane data of the first terminal device itself, or it can be the user plane data of other terminal devices within the coverage area of ​​the first terminal device that use the first terminal device to provide wireless local area network communication capabilities.

[0270] S1502a, the access network device replaces the source IP address of the message corresponding to the first uplink data with IP@3 and the port number (port) is 2, and sends the first uplink data with the replaced source IP address to the application server through the fixed network gateway device.

[0271] The second uplink data sent by the second terminal device can be the user plane data of the second terminal device itself, or it can be the user plane data of other terminal devices within the coverage area of ​​the second terminal device that use the second terminal device to provide wireless local area network communication capabilities.

[0272] S1502b, the access network device replaces the source IP address of the message corresponding to the second uplink data with IP@3 and the port number (port) is 3, and sends the second uplink data with the replaced source IP address to the application server through the fixed network gateway device.

[0273] S1503, the access network device obtains downlink data from the application server through the fixed network gateway device. The destination IP address of the message corresponding to the downlink data is denoted as IP@3, and the port number is 2.

[0274] S1504, the access network device determines that the downlink data is to be sent to the first terminal device based on the destination IP address of the message corresponding to the downlink data. Then, the access network device replaces the destination IP address of the message corresponding to the downlink data with IP@1 and the port number (port) is 1, and sends the downlink data with the replaced destination IP address to the first terminal device.

[0275] In this second scheme, the access network device establishes a connection with the fixed network gateway device beforehand. For subsequent terminal devices requiring connection establishment, the access network device can directly establish user plane resources with the terminal device and assign an IP address (if a PPPoE connection is established, the access network device will also assign a PPPoE session identifier). In other words, the access network device has NAT functionality. The advantage is that only one or a few connections need to be established between the access network device and the fixed network gateway device. The access network device can directly determine whether to establish user plane resources and assign an IP address with the terminal device based on the terminal device's authentication and authorization results (or subscription data).

[0276] For the above embodiments, see Figure 16 This application provides a communication device 1600, which includes a communication module 1601 and a processing module 1602. The communication device 1600 can be an access network device, or an apparatus applied to an access network device that enables the access network device to execute the aforementioned communication method.

[0277] The communication module can also be called a transceiver module, transceiver, transceiver device, etc. The processing module can also be called a processor, processing board, processing unit, processing device, etc. Optionally, the device in the communication module used to implement the receiving function can be regarded as a receiving unit. It should be understood that the communication module is used to perform the sending and receiving operations on the access network device side in the above method embodiments, and the device in the communication module used to implement the sending function can be regarded as a sending unit. That is, the communication module includes a receiving unit and a sending unit. When the communication device 1600 is applied to the access network device, the receiving unit included in its communication module 1601 is used to perform the receiving operation on the access network device side, such as receiving the fourth information from the first terminal device; the sending unit included in its communication module 1601 is used to perform the sending operation on the access network device side, such as sending the second information to the first fixed network gateway device. In addition, it should be noted that if the device is implemented using a chip / chip circuit, the communication module can be an input / output circuit and / or a communication interface to perform input operations (corresponding to the aforementioned receiving operation) and output operations (corresponding to the aforementioned sending operation); the processing module is an integrated processor, microprocessor, or integrated circuit.

[0278] The following provides a detailed description of how the communication device 1600 is applied to access network equipment.

[0279] The communication device 1600 includes:

[0280] The communication module 1601 is used to acquire the first information.

[0281] The processing module 1602 is used to establish a user plane connection with the first terminal device based on the first information.

[0282] The communication module 1601 is further configured to obtain user plane data of the first terminal device through the user plane connection and send the user plane data to the first fixed network gateway device.

[0283] In this embodiment, an access network device supporting 3GPP access type is used as an intermediate node between the terminal device and the fixed network gateway device. The terminal device establishes a connection with the access network device using 3GPP access technology, and the access network device can transmit data from the terminal device to the fixed network gateway device, enabling the terminal device to obtain fixed network broadband services through 3GPP access. Compared to the traditional method of fixed network terminals accessing the fixed network via wired connection, this simplifies deployment, enhances coverage, and improves the performance of the communication system.

[0284] In one optional implementation, the first information is used to indicate that the type of the first terminal device is a target type and / or to indicate that the first terminal device is allowed to obtain fixed network services provided by the first fixed network gateway device; wherein, the target type includes one or more of home gateway, home terminal, and client terminal device.

[0285] In one alternative implementation, the first information comes from the first terminal device, and the first information indicates that the type of the first terminal device is the target type.

[0286] In one optional implementation, the first information is pre-configured in the access network device or the first information comes from the first fixed network gateway device; wherein, the first information includes subscription data information corresponding to the first terminal device, and the subscription data information is used to determine whether the first terminal device is allowed to obtain fixed network services provided by the first fixed network gateway device.

[0287] In an optional implementation, before the communication module 1601 obtains user plane data from the first terminal device via the user plane connection:

[0288] The communication module 1601 is further configured to send second information to the first fixed-line gateway device, the second information being used to request the establishment of a connection between the first terminal device and the first fixed-line gateway device.

[0289] The communication module 1601 is further configured to receive third information from the first fixed-line gateway device, the third information indicating that the connection between the first terminal device and the first fixed-line gateway device has been successfully established.

[0290] In an optional implementation, the processing module 1602 is further configured to execute a user plane connection management process based on the third information; wherein the user plane connection management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources, or releasing user plane resources.

[0291] In one optional implementation, the third information includes at least one of the following: identification information of the first terminal device; authentication information of the first terminal device, the authentication information being used to indicate that the first terminal device has been authenticated through the fixed network corresponding to the first fixed network gateway device; subscription data information corresponding to the first terminal device, the subscription data information including one or more of fixed network service information, QoS information, and priority information; and security context information of the first terminal device, the security context information being used to establish a secure connection between the access network device and the first terminal device.

[0292] In one optional implementation, the access network device establishes a connection with at least one fixed network gateway device, the at least one fixed network gateway device including the first fixed network gateway device.

[0293] In an optional implementation, before the processing module 1602 establishes a user plane connection with the first terminal device based on the first information: the communication module 1601 is further configured to obtain fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device; the processing module is further configured to establish a secure connection between the access network device and the first terminal device based on the fourth information and using the security context information of the first terminal device.

[0294] In an optional implementation, the fourth information includes a first serial number corresponding to the security context information of the first terminal device; the processing module 1602 is further configured to: obtain security context information and an identifier set of at least one terminal device through the communication module 1601, the identifier set including a first serial number set for indicating the security context information of the at least one terminal device, the first serial number set including the first serial number; obtain the security context information of the first terminal device from the security context information and identifier set of the at least one terminal device according to the first serial number; and the access network device establishes a secure connection between the access network device and the first terminal device using the security context information of the first terminal device.

[0295] In an optional implementation, the identifier set further includes a second sequence number set; the processing module 1602 is further configured to replace the first sequence number with a second sequence number in the second sequence number set after establishing a secure connection between the access network device and the first terminal device using the first terminal device security context information; the communication module 1601 is further configured to send the second sequence number to the first terminal device, the second sequence number being used to indicate the security context information of the first terminal device.

[0296] In one optional implementation, the fourth information further includes the identification information of the fixed network corresponding to the first fixed network gateway device.

[0297] In an optional implementation, before acquiring the fourth information, the communication module 1601 is further configured to: send at least one of the following information: capability information of the access network device, the capability information indicating that the access network device supports fixed network transmission; identification information of the fixed network supported by the access network device, the fixed network supported by the access network device including the fixed network corresponding to the first fixed network gateway device; network priority information, the network priority information used to indicate the priority of the mobile operator to which the access network device belongs.

[0298] In an optional implementation, the communication module 1601 is further configured to acquire, before acquiring the fourth information, information sent by the first terminal device indicating that the type of the first terminal device is a target type and / or the identification information of the fixed network to which the first terminal device requests access; the processing module 1602 is further configured to determine, based on the type of the first terminal device and / or the identification information of the fixed network to which the first terminal device requests access, that the access network device supports the fixed network transmission of the first terminal device.

[0299] The module division in this embodiment is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in each embodiment of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0300] Based on the same technical concept, this application also provides a communication device 1700. The communication device 1700 can be a chip or a chip system. Optionally, in the embodiments of this application, the chip system can be composed of chips, or it can include chips and other discrete devices.

[0301] Communication device 1700 can be used to achieve Figure 5The communication system illustrated describes the functions of a terminal device, access network device, or fixed network gateway device. The communication device 1700 may include at least one processor 1702 coupled to a memory. Optionally, the memory may be located within the device, integrated with the processor, or located outside the device. For example, the communication device 1700 may also include at least one memory 1703. The memory 1703 stores computer programs, configuration information, computer programs or instructions, and / or data necessary for implementing any of the above embodiments; the processor 1702 may execute the computer program stored in the memory 1703 to perform the methods in any of the above embodiments.

[0302] The coupling in this embodiment is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, used for information exchange between devices, units, or modules. Processor 1702 may operate in conjunction with memory 1703. This embodiment does not limit the specific connection medium between processor 1702 and memory 1703.

[0303] The communication device 1700 may also include a communication interface 1701, through which the communication device 1700 can interact with other devices. For example, the communication interface 1701 may be a transceiver, circuit, bus, module, or other type of communication interface. When the communication device 1700 is a chip-based device or circuit, the communication interface 1701 in the device 1700 may also be an input / output circuit, capable of inputting information (or receiving information) and outputting information (or sending information). The processor may be an integrated processor, a microprocessor, an integrated circuit, or a logic circuit, and the processor can determine the output information based on the input information.

[0304] Optional, see Figure 17 The communication interface 1701, the processing module 1702, and the memory 1703 are interconnected via a bus 1704. The bus 1704 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 17 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0305] In the embodiments of this application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0306] In the embodiments of this application, the memory can be non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or it can be volatile memory, such as random-access memory (RAM). Memory is any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. The memory in the embodiments of this application can also be a circuit or any other device capable of implementing storage functions, used to store program instructions and / or data.

[0307] In one possible implementation, the communication device 1700 can be applied to a terminal device. Specifically, the communication device 1700 can be a terminal device or an apparatus capable of supporting the terminal device and implementing the functions of the terminal device in any of the above embodiments. The memory 1703 stores the necessary computer programs, computer programs or instructions and / or data for implementing the functions of the terminal device in any of the above embodiments. The processor 1702 can execute the computer programs stored in the memory 1703 to complete the methods executed by the terminal device in any of the above embodiments. Applied to a terminal device, the communication interface in the communication device 1700 can be used to interact with network devices, sending information to or receiving information from network devices.

[0308] In one possible implementation, the communication device 1700 can be applied to an access network device. Specifically, the communication device 1700 can be an access network device or a device capable of supporting the access network device and implementing the functions of the access network device in any of the above embodiments. The memory 1703 stores the necessary computer programs, computer programs or instructions and / or data for implementing the functions of the access network device in any of the above embodiments. The processor 1702 can execute the computer program stored in the memory 1703 to complete the method executed by the access network device in any of the above embodiments. Applied to an access network device, the communication interface in the communication device 1700 can be used to interact with a terminal device, sending information to or receiving information from the terminal device; or, the communication interface in the communication device 1700 can be used to interact with a fixed-line gateway device, sending information to or receiving information from the fixed-line gateway device.

[0309] In one possible implementation, the communication device 1700 can be applied to a fixed-line gateway device. Specifically, the communication device 1700 can be a fixed-line gateway device or a device capable of supporting the fixed-line gateway device and implementing the functions of the fixed-line gateway device in any of the above embodiments. The memory 1703 stores the necessary computer programs, computer programs or instructions, and / or data for implementing the functions of the fixed-line gateway device in any of the above embodiments. The processor 1702 can execute the computer programs stored in the memory 1703 to complete the methods performed by the fixed-line gateway device in any of the above embodiments. Applied to a fixed-line gateway device, the communication interface in the communication device 1700 can be used to interact with access network devices, sending information to or receiving information from the access network devices.

[0310] Since the communication device 1700 provided in this embodiment can be applied to a terminal device to complete the method executed by the terminal device, or applied to a network device to complete the method executed by the network device, the technical effects it can achieve can be referred to the above method embodiments, and will not be repeated here.

[0311] In the embodiments of this application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0312] In the embodiments of this application, the memory can be non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or it can be volatile memory, such as random-access memory (RAM). The memory can also be any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. The memory in the embodiments of this application can also be a circuit or any other device capable of implementing storage functions, used to store computer programs, computer program or instruction and / or data.

[0313] Based on the above embodiments, this application also provides a computer program that, when run on a computer, causes the computer to execute commands from the perspective of a terminal device or a network device. Figure 6 , Figure 9 , Figure 10 , Figure 11 , Figure 14 The data transmission method provided in the illustrated embodiment.

[0314] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a computer, it causes the computer to perform the data transmission method provided in the above method embodiments from the perspective of a terminal device or a network device. The storage medium can be any available medium that can be accessed by a computer. For example, but not limited to, a computer-readable medium can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code having an instruction or data structure form and that can be accessed by a computer.

[0315] Based on the above embodiments, this application provides a communication system including a terminal device, an access network device, and a fixed network gateway device, wherein the terminal device, network device, and fixed network gateway device can implement the communication method provided in the above embodiments.

[0316] Based on the above embodiments, this application also provides a chip, which is used to read a computer program stored in a memory and implement the data transmission method provided in the above method embodiments from the perspective of a terminal device or a network device.

[0317] Based on the above embodiments, this application provides a chip system including a processor for supporting a computer device in implementing the functions involved in the terminal device, access network device, or fixed network gateway device in the above method embodiments. In one possible design, the chip system further includes a memory for storing necessary programs and data of the computer device. This chip system may be composed of chips or may include chips and other discrete components.

[0318] The technical solutions provided in this application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a terminal device, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital video discs (DVDs)), or semiconductor media, etc.

[0319] In the embodiments of this application, provided there is no logical contradiction, the embodiments may reference each other. For example, the methods and / or terms between method embodiments may reference each other, the functions and / or terms between device embodiments may reference each other, and the functions and / or terms between device embodiments and method embodiments may reference each other.

[0320] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0321] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0322] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0323] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A communication method characterized by comprising: The method comprises: An access network device acquires first information; wherein the access network device supports a third generation partnership project (3GPP) access type, and the first information is used to determine whether a first terminal device is allowed to acquire fixed network services provided by a first fixed network gateway device; The access network device establishes a user plane connection with the first terminal device through a 3GPP wireless access technology according to the first information; The access network device acquires user plane data of the first terminal device through the user plane connection, and sends the user plane data to the first fixed network gateway device through a connection between the access network device and the first fixed network gateway device, wherein the access network device and the first fixed network gateway device communicate through a first protocol.

2. The method of claim 1, wherein, The first information is used to indicate that the type of the first terminal device is a target type and / or to indicate that the first terminal device is allowed to acquire fixed network services provided by the first fixed network gateway device; wherein the target type includes one or more of a home gateway, a home terminal, and a customer terminal device.

3. The method of claim 2, wherein, The first information is from the first terminal device, and the first information indicates that the type of the first terminal device is a target type.

4. The method of claim 2, wherein, The first information is preconfigured in the access network device or the first information is from the first fixed network gateway device; wherein the first information includes subscription data information corresponding to the first terminal device, and the subscription data information is used to determine whether the first terminal device is allowed to acquire fixed network services provided by the first fixed network gateway device.

5. The method according to any one of claims 1 to 4, characterized in that, Before the access network device acquires the user plane data of the first terminal device through the user plane connection, the method further comprises: The access network device sends second information to the first fixed network gateway device, wherein the second information is used to request to establish a connection between the first terminal device and the first fixed network gateway device; The access network device receives third information from the first fixed network gateway device, wherein the third information indicates that the connection between the first terminal device and the first fixed network gateway device is successfully established.

6. The method of claim 5, wherein, The method further comprises: The access network device performs a user plane connection management process according to the third information; wherein the user plane connection management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources, or releasing user plane resources.

7. The method of claim 6, wherein, The third information includes at least one of the following: Identification information of the first terminal device; Authentication information of the first terminal device, wherein the authentication information is used to indicate that the first terminal device is authenticated through a fixed network corresponding to the first fixed network gateway device; Subscription data information of the first terminal device, wherein the subscription data information includes one or more of fixed network service information, quality of service (QoS) information, and priority information; Security context information of the first terminal device, wherein the security context information is used to establish a secure connection between the access network device and the first terminal device.

8. The method of any one of claims 1-4, wherein, Before the access network device establishes the user plane connection with the first terminal device according to the first information, the method further comprises: The access network device establishes a connection with at least one fixed network gateway device, and the at least one fixed network gateway device includes the first fixed network gateway device.

9. The method of any one of claims 1-4, wherein, Before the access network device establishes a user plane connection with the first terminal device according to the first information, the method further includes: The access network device obtains fourth information from the first terminal device, and the fourth information is used to determine security context information of the first terminal device; The access network device establishes a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device according to the fourth information.

10. The method of claim 9, wherein, The fourth information includes a first sequence number corresponding to the security context information of the first terminal device; The access network device establishes a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device according to the fourth information, including: The access network device obtains security context information and an identifier set of at least one terminal device, and the identifier set includes a first sequence number set used to indicate the security context information of the at least one terminal device, and the first sequence number set includes the first sequence number; The access network device obtains the security context information of the first terminal device from the security context information and the identifier set of the at least one terminal device according to the first sequence number; The access network device establishes a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device.

11. The method of claim 10, wherein, The identifier set further includes a second sequence number set; After the access network device establishes a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device, the method further includes: Replacing the first sequence number with a second sequence number in the second sequence number set, and sending the second sequence number to the first terminal device, and the second sequence number is used to indicate the security context information of the first terminal device.

12. The method of claim 9, wherein, The fourth information further includes identifier information of a fixed network of the first fixed network gateway device.

13. The method of claim 9, wherein, Before the access network device obtains the fourth information, the method further includes: The access network device sends at least one of the following information: Capability information of the access network device, and the capability information indicates that the access network device supports fixed network transmission; Identifier information of a fixed network supported by the access network device, and the fixed network supported by the access network device includes a fixed network corresponding to the first fixed network gateway device; Network priority information, and the network priority information is used to indicate a priority of a mobile operator to which the access network device belongs.

14. The method of claim 9, wherein, Before the access network device obtains the fourth information, the method further includes: The access network device obtains information sent by the first terminal device and used to indicate that a type of the first terminal device is a target type and / or identifier information of a fixed network requested to be accessed by the first terminal device; The access network device determines, according to the type of the first terminal device and / or the identification information of the fixed network network requested to be accessed by the first terminal device, that the access network device supports fixed network transmission of the first terminal device.

15. The method of any one of claims 1-4, wherein, The first protocol is an Ethernet carrying PPP protocol or an Ethernet carrying IP protocol.

16. A communications device, characterized by The application is applied to an access network device supporting a third generation partnership project (3GPP) access type, and includes: A communication module is configured to acquire first information, the first information being used to determine that a first terminal device is allowed to acquire fixed network services provided by a first fixed network gateway device; A processing module is configured to establish a user plane connection with the first terminal device through a 3GPP wireless access technology according to the first information; The communication module is further configured to acquire user plane data of the first terminal device through the user plane connection and send the user plane data to the first fixed network gateway device through a connection between the access network device and the first fixed network gateway device, the access network device and the first fixed network gateway device communicating through a first protocol.

17. The communication apparatus of claim 16, wherein, The first information is used to indicate that the type of the first terminal device is a target type and / or to indicate that the first terminal device is allowed to acquire fixed network services provided by the first fixed network gateway device; and the target type includes one or more of a home gateway, a home terminal, and a customer terminal device.

18. The communication apparatus of claim 17, wherein, The first information is from the first terminal device, and the first information indicates that the type of the first terminal device is a target type.

19. The communication apparatus of claim 17, wherein, The first information is preconfigured in the access network device or the first information is from the first fixed network gateway device; and the first information includes subscription data information corresponding to the first terminal device, the subscription data information being used to determine that the first terminal device is allowed to acquire fixed network services provided by the first fixed network gateway device.

20. The communication apparatus of any of claims 16-19, wherein, Before the communication module acquires the user plane data of the first terminal device through the user plane connection: The communication module is further configured to send second information to the first fixed network gateway device, the second information being used to request to establish a connection between the first terminal device and the first fixed network gateway device; The communication module is further configured to receive third information from the first fixed network gateway device, the third information indicating that the connection between the first terminal device and the first fixed network gateway device is successfully established.

21. The communication apparatus of claim 20, wherein: The processing module is further configured to perform a user plane connection management process according to the third information; and the user plane connection management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources, or releasing user plane resources.

22. The communication apparatus of claim 20, wherein, The third information includes at least one of the following: Identification information of the first terminal device; Authentication information of the first terminal device, the authentication information being used to indicate that the first terminal device is authenticated through a fixed network corresponding to the first fixed network gateway device. The subscription data information corresponding to the first terminal device, the subscription data information including one or more of fixed network service information, quality of service (QoS) information, and priority information; The security context information of the first terminal device, the security context information being used to establish a secure connection between the access network device and the first terminal device.

23. The communication apparatus of any of claims 16-19, wherein, The access network device establishes a connection with at least one fixed network gateway device, the at least one fixed network gateway device including the first fixed network gateway device.

24. The communication apparatus of any of claims 16-19, wherein, Before the processing module establishes a user plane connection with the first terminal device according to the first information: The communication module is further configured to obtain fourth information from the first terminal device, the fourth information being used to determine the security context information of the first terminal device; The processing module is further configured to establish a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device according to the fourth information.

25. The communications apparatus of claim 24, wherein The fourth information includes a first sequence number corresponding to the security context information of the first terminal device; and the processing module is further configured to: obtain, through the communication module, security context information and an identifier set of at least one terminal device, the identifier set including a first sequence number set used to indicate the security context information of the at least one terminal device, the first sequence number set including the first sequence number; obtain the security context information of the first terminal device from the security context information and the identifier set of the at least one terminal device according to the first sequence number; and establish a secure connection between the access network device and the first terminal device by using the security context information of the first terminal device.

26. The communications apparatus of claim 25, wherein The identifier set further includes a second sequence number set; The processing module is further configured to replace the first sequence number with a second sequence number in the second sequence number set after the secure connection between the access network device and the first terminal device is established by using the security context information of the first terminal device; and The communication module is further configured to send the second sequence number to the first terminal device, the second sequence number being used to indicate the security context information of the first terminal device.

27. The communications apparatus of claim 24, wherein The fourth information further includes identifier information of a fixed network corresponding to the first fixed network gateway device.

28. The communications apparatus of claim 24, wherein Before obtaining the fourth information, the communication module is further configured to send at least one of the following information: capability information of the access network device, the capability information indicating that the access network device supports fixed network transmission; identifier information of a fixed network supported by the access network device, the fixed network supported by the access network device including the fixed network corresponding to the first fixed network gateway device; network priority information, the network priority information being used to indicate a priority of a mobile operator to which the access network device belongs.

29. The communication apparatus of claim 24, wherein before obtaining the fourth information, the communication module is further configured to obtain information sent by the first terminal device and / or identifier information of a fixed network requested to be accessed by the first terminal device, the information being used to indicate that a type of the first terminal device is a target type. The processing module is further configured to determine, according to a type of the first terminal device and / or identification information of a fixed network network requested to be accessed by the first terminal device, that the access network device supports fixed network transmission of the first terminal device.

30. The communication apparatus of any of claims 16-19, wherein, The first protocol is an Ethernet carrying PPP protocol or an Ethernet carrying IP protocol.

31. A communications device, characterized by The communication device comprises a processor and a memory, the memory and the processor are coupled, and the processor is configured to execute the method in any one of claims 1 to 15.

32. A computer-readable storage medium, comprising: The computer readable storage medium comprises instructions which, when executed on a computer, cause the computer to perform the method in any one of claims 1 to 15.

33. A computer program product comprising instructions, wherein: The instructions, when executed on a computer, cause the computer to perform the method in any one of claims 1 to 15.

Citation Information

Patent Citations

  • Method, device and system for network access

    CN109391940A

  • Network access method, device and system

    WO2015035640A1