Intelligent gateway method and system based on wireless network voice service quality guarantee
By combining dual authentication of WAPI authentication and SIP registration in wireless networks, voice communication devices are identified and high-priority resources are allocated, solving the problems of low efficiency and poor security of voice communication in wireless networks and realizing efficient and secure voice services.
Patent Information
- Application Number
- CN202510992084.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-07-18
AI Technical Summary
Existing wireless networks are prone to network freezes and disconnections when multiple terminals carry voice services concurrently in corporate offices or industrial parks. Furthermore, the security authentication process is complex, resulting in low voice communication efficiency and difficulty ensuring security.
The WAPI authentication mechanism is used in conjunction with SIP registration for dual identity authentication. Multi-dimensional feature information such as terminal hardware identification, organizational unit identification, and communication protocol are combined to identify voice communication devices and allocate high-priority wireless resources to them.
It improves the success rate of VoIP equipment access to the network, reduces the risk of illegal access, improves the quality and stability of voice communications, simplifies the terminal access process, and reduces operation and maintenance costs.
Smart Images

Figure CN120499664B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless communication technology, and in particular to an intelligent gateway method and system based on wireless network voice service quality assurance. Background Art
[0002] In the current field of wireless network communications, with the advancement of enterprise digital transformation and the popularization of smart devices, the requirements for network performance, security and voice communication quality are constantly increasing, but existing wireless communication methods have many shortcomings.
[0003] Traditional wireless networks, when running multiple voice services concurrently across multiple terminals in corporate offices or industrial parks, often experience network lag and disconnections, impacting voice communication efficiency. Furthermore, when multiple terminals simultaneously authenticate network access, authentication gaps can occur, making it difficult to effectively ensure voice service security.
[0004] Therefore, how to improve the efficiency of wireless network voice services and ensure the security of voice services has become an urgent problem to be solved. Summary of the Invention
[0005] The main purpose of this application is to provide an intelligent gateway method and system based on wireless network voice service quality assurance, aiming to solve the technical problem of how to improve the efficiency of wireless network voice services and ensure the security of voice services.
[0006] To achieve the above objectives, the present application proposes an intelligent gateway method based on wireless network voice service quality assurance, the method comprising:
[0007] In response to an access request from a terminal, performing security authentication on the terminal, wherein the security authentication is bound to a voice communication registration;
[0008] When the security authentication is passed, determining whether the terminal is a voice communication device based on the multi-dimensional feature information of the terminal;
[0009] When it is determined that the terminal is a voice communication device, a high-priority wireless resource is allocated to the terminal using a preset dynamic resource allocation technology.
[0010] In one embodiment, the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol and / or terminal organization unit identification.
[0011] In one embodiment, the step of performing security authentication on the terminal in response to the access request of the terminal includes:
[0012] In response to an access request from a terminal, performing voice registration authentication on the terminal based on session initiation protocol registration information of the terminal;
[0013] When the voice registration authentication is passed, sending the authentication request corresponding to the terminal to the authentication server, the authentication server performs wireless LAN authentication on the terminal upon receiving the authentication request, and feeds back the wireless LAN authentication result;
[0014] A security authentication result is determined based on the wireless local area network authentication result.
[0015] In one embodiment, after performing security authentication on the terminal in response to the access request of the terminal, the method further includes:
[0016] The session initiation protocol registration information of the terminal is sent to a wireless controller. When the wireless controller detects that the terminal has roamed to a new wireless access point, the wireless controller sends the session initiation protocol registration information to the new wireless access point, so that the new wireless access point reestablishes a voice session channel based on the session initiation protocol registration information.
[0017] In one embodiment, when determining that the terminal is a voice communication device, after allocating high-priority wireless resources to the terminal using a preset dynamic resource allocation technology, the method further includes:
[0018] The resource allocation policy corresponding to the terminal is sent to the integrated access device through a preset communication protocol. After receiving the resource allocation policy, the integrated access device adjusts the processing priority corresponding to the terminal in the current data routing policy.
[0019] In addition, to achieve the above-mentioned purpose, the present application also proposes an intelligent gateway system based on wireless network voice service quality assurance, the system comprising: a terminal and a wireless access point; the wireless access point is connected to the terminal;
[0020] The wireless access point is configured to perform security authentication on the terminal in response to an access request from the terminal, wherein the security authentication is bound to voice communication registration;
[0021] The wireless access point is configured to determine whether the terminal is a voice communication device based on the multi-dimensional feature information of the terminal after the security authentication is passed;
[0022] The wireless access point is further configured to allocate high-priority wireless resources to the terminal by using a preset dynamic resource allocation technology when determining that the terminal is a voice communication device.
[0023] In one embodiment, the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol and / or terminal organization unit identification.
[0024] In one embodiment, the system further comprises: an authentication server; the authentication server is connected to the wireless access point;
[0025] The wireless access point is further configured to perform voice registration authentication on the terminal based on the session initiation protocol registration information of the terminal in response to an access request of the terminal.
[0026] The wireless access point is further configured to send an authentication request corresponding to the terminal to the authentication server when the voice registration authentication is passed.
[0027] The authentication server is configured to perform wireless local area network authentication on the terminal and feed back a wireless local area network authentication result when the authentication request is received.
[0028] The wireless access point is further configured to determine a security authentication result based on the wireless local area network authentication result.
[0029] In an embodiment, the system further comprises a wireless controller, wherein the wireless controller is connected to the wireless access point.
[0030] The wireless access point is further configured to send the session initiation protocol registration information of the terminal to the wireless controller.
[0031] The wireless controller is configured to send the session initiation protocol registration information to a new wireless access point when detecting that the terminal roams to the new wireless access point, so that the new wireless access point reconstructs a voice session channel based on the session initiation protocol registration information.
[0032] In an embodiment, the system further comprises an integrated access device, wherein the integrated access device is connected to the wireless access point.
[0033] The wireless access point is further configured to send a resource allocation strategy corresponding to the terminal to the integrated access device through a preset communication protocol.
[0034] The integrated access device is further configured to adjust a processing priority corresponding to the terminal in a current data routing strategy after receiving the resource allocation strategy.
[0035] The application provides a wireless network voice service quality guarantee-based intelligent gateway method and system. The method comprises the following steps: in response to a terminal access request, performing security authentication on the terminal, wherein the security authentication is bound with voice communication registration; when the security authentication is passed, judging whether the terminal is a voice communication device based on multi-dimensional feature information of the terminal; and when it is determined that the terminal is a voice communication device, allocating high-priority wireless resources to the terminal through a preset dynamic resource allocation technology. In the prior art, the authentication process of a wireless network on voice services is complex, the registration failure rate is high, and when multiple terminals are concurrent, voice data packets are prone to be delayed or discarded, resulting in poor call quality. In the application, the WAPI authentication mechanism is bound with SIP registration, and double identity authentication is performed when a VoIP device accesses the network. That is, the application supports access control based on terminal identity, such as MAC address + SIP account binding, to prevent illegal devices from accessing the network, thereby improving the VoIP device access success rate, reducing the risk of illegal access, and guaranteeing the safety of voice services. In addition, the application effectively identifies voice communication devices by combining terminal hardware identifiers, organizational unit identifiers and communication protocols and the like, and provides special and high-priority resource services for the voice communication devices, thereby avoiding voice delay, lag and the like caused by unreasonable resource allocation, improving voice service communication efficiency, and greatly improving the quality and stability of voice communication. BRIEF DESCRIPTION OF DRAWINGS
[0036] The accompanying drawings, which are incorporated into and form a part of the specification, illustrate preferred embodiments of the application and, together with the description, serve to explain the principles of the application.
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.
[0038] Figure 1 A flowchart of a first embodiment of the wireless network voice service quality guarantee-based intelligent gateway method of the application;
[0039] Figure 2 A flowchart of a second embodiment of the wireless network voice service quality guarantee-based intelligent gateway method of the application;
[0040] Figure 3 An intelligent gateway control flowchart of the second embodiment of the wireless network voice service quality guarantee-based intelligent gateway method of the application;
[0041] Figure 4 A first structure diagram of the wireless network voice service quality guarantee-based intelligent gateway system of the embodiment of the application;
[0042] Figure 5 This is a second structural diagram of the intelligent gateway system based on wireless network voice service quality assurance according to an embodiment of the present application.
[0043] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0044] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0045] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0046] The main solution of this application is: in response to the terminal's access request, the terminal is securely authenticated, where the security authentication is bound to the voice communication registration; when the security authentication passes, whether the terminal is a voice communication device is determined based on the terminal's multi-dimensional feature information; when the terminal is determined to be a voice communication device, high-priority wireless resources are allocated to the terminal through a preset dynamic resource allocation technology.
[0047] Currently, traditional wireless networks experience significant scheduling delays, unstable wireless links, and high packet loss rates when multiple terminals are connected concurrently. For example, in corporate offices or industrial parks, where a large number of devices are connected simultaneously, network lags and disconnections often occur, impacting voice communication efficiency. Furthermore, existing security authentication mechanisms are prone to authentication omissions when handling multiple terminals simultaneously accessing the network. Voice communication devices also suffer from high registration failure rates, resulting in high operational and maintenance costs and difficulties in ensuring the security of voice services.
[0048] In view of the problem in the prior art that the wireless network authentication process for voice services is complex, the registration failure rate is high, and voice data packets are easily delayed or discarded when multiple terminals are concurrent, resulting in poor call quality, this application first binds the WAPI authentication mechanism with the SIP registration, and performs dual identity authentication when the VoIP device joins the network. That is, this application supports access control based on terminal identity, such as MAC address + SIP account binding, to prevent illegal devices from accessing, thereby improving the success rate of VoIP equipment joining the network, reducing the risk of illegal access, and ensuring the security of voice services. In addition, this application effectively identifies voice communication devices by combining multiple identification elements such as terminal hardware identification, organizational unit identification and communication protocol, and provides them with dedicated, high-priority resource services, thereby avoiding voice delays, freezes and other problems caused by unreasonable resource allocation, improving the efficiency of voice service communication, and greatly improving the quality and stability of voice communication.
[0049] It should be noted that the execution entity of this embodiment can be an intelligent gateway system that provides quality-of-service voice services over a wireless network, or a computing service device with data processing, network communication, and program execution capabilities that provides a bridge for wireless communication-enabled terminal devices (such as mobile phones, laptops, and VoIP (Voice over Internet Protocol) phones) to access a wired network, such as a wireless access point (AP). This embodiment does not specifically limit this. This embodiment and the following embodiments will be described below using a wireless access point (AP) as the execution entity.
[0050] It is easy to understand that access points can create wireless local area networks (WLANs) through Wi-Fi (Wireless Fidelity) technology, receive wireless signals from terminal devices, and convert them into wired data streams for transmission to upper-layer networks (such as switches, routers, or smart gateways).
[0051] Based on this, the embodiment of the present application provides an intelligent gateway method based on wireless network voice service quality assurance, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the intelligent gateway method for ensuring quality of service of wireless network voice based on this application.
[0052] In this embodiment, the intelligent gateway method based on wireless network voice service quality assurance includes steps S10 to S30:
[0053] Step S10, in response to the access request of the terminal, performing security authentication on the terminal, wherein the security authentication is bound to the voice communication registration;
[0054] It's easy to understand that in existing wireless network communications, it's difficult to guarantee the quality of voice communication service. Issues such as unstable access to voice communication devices and the inability to allocate appropriate resources in a timely manner can lead to poor voice communication. To address this issue, in this embodiment, when an access point detects a terminal attempting to access the network, it receives the access request and immediately initiates a security authentication process for the terminal. The terminal can be a voice device such as a Wi-Fi-enabled VOIP phone or soft terminal.
[0055] In order to improve the security of terminal authentication, in this embodiment, the above-mentioned security authentication can be an authentication process that binds WAPI (Wireless LAN Authentication and Privacy Infrastructure) certificate authentication with voice communication registration, that is, during the WAPI authentication process, it will be considered whether the terminal is legally qualified to use voice communication services.
[0056] Therefore, as an implementable method, in this embodiment, step S10 includes steps A1 to A3:
[0057] Step A1: In response to an access request from a terminal, performing voice registration authentication on the terminal based on the session initiation protocol registration information of the terminal;
[0058] Step A2: When the voice registration authentication is passed, sending an authentication request corresponding to the terminal to an authentication server. Upon receiving the authentication request, the authentication server performs wireless LAN authentication on the terminal and feeds back a wireless LAN authentication result.
[0059] Step A3: Determine a security authentication result based on the wireless local area network authentication result.
[0060] It's important to understand that when a VoIP terminal first accesses the network, it initiates a Session Initiation Protocol (SIP) registration request to the wireless access point. The wireless access point receives and processes the SIP registration request and records the terminal's SIP registration information, including key information such as the terminal's MAC (Media Access Control) address, SIP account, and registration status. This SIP registration information can be crucial data in a VoIP system, identifying each terminal's device identity, location, and session status.
[0061] In this case, the voice registration and authentication process may involve the access point obtaining the terminal's Session Initiation Protocol registration information, comparing it with a valid SIP account stored in advance on the SIP server on the current network, and finally verifying the terminal's identity based on the comparison result. If the SIP server detects that the terminal's corresponding SIP account is stored, the terminal is considered a valid voice communication user.
[0062] In this embodiment, only after verifying the validity of the SIP account of the terminal and ensuring that the terminal currently sending the access request is a legal voice communication user, a temporary authentication token can be generated. Then the access point encapsulates the SIP registration token, terminal MAC address, WAPI certificate and other information into an authentication request and sends it to the authentication server (such as a Radius server) connected to the access point for wireless LAN authentication, i.e. the above-mentioned WAPI authentication. The authentication server verifies the validity of the WAPI certificate of the terminal, and according to the authentication rules set by itself, such as checking whether the MAC address of the terminal is in the list of allowed access, whether the terminal meets the security policy of the network, etc., the terminal is comprehensively evaluated for security, and the authentication result (pass or reject) is fed back to the access point.
[0063] At this time, the access point can finally determine whether the security authentication of the terminal is passed according to the wireless LAN authentication result returned by the authentication server. Only when the terminal has passed both voice registration authentication and wireless LAN authentication, it is considered to be a legal and secure voice communication device, so as to allow it to access the network and use voice communication services, otherwise the terminal access is rejected.
[0064] In this embodiment, in view of the problem in the prior art that the security authentication and the voice registration process are independent, resulting in a high failure rate (up to 20%) of VoIP device registration and a complicated authentication process, the voice registration authentication and the wireless LAN authentication are combined to form a dual authentication mechanism. The dual authentication mechanism not only greatly enhances the security of the network, ensures that only legally authorized voice communication devices can access the network, and prevents the intrusion of illegal devices, but also reduces the security risks such as information leakage and malicious attacks in the voice communication process, and improves the registration success rate of voice communication devices, which can reduce the registration failure rate to below 5%, and simplifies the terminal access process and improves the operation and maintenance efficiency.
[0065] Step S20, when the security authentication is passed, judging whether the terminal is a voice communication device based on the multi-dimensional feature information of the terminal;
[0066] It is easy to understand that once the terminal passes the security authentication, the access point can further determine whether it belongs to a voice communication device according to the multi-dimensional feature information of the terminal, and then the subsequent reasonable resource allocation can be based on the device type of the terminal. Among them, the multi-dimensional feature information for identifying the device type of the terminal can include the type identification of the terminal, the hardware configuration, the installed communication software, etc. For example, by analyzing whether a specific voice communication client software is installed on the terminal, or whether the terminal has a hardware interface for voice input and output, etc., to determine whether it is a device suitable for voice communication.
[0067] Preferably, as an implementable method, in this embodiment, the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol and / or terminal organization unit identification.
[0068] It is understandable that in order to more accurately determine whether the terminal is a voice communication device so as to better allocate resources to it, this embodiment can make a voice communication device judgment based on the terminal hardware identification, terminal communication protocol and / or terminal organizational unit identification, providing a basis for subsequent QoS (Quality of Service) scheduling.
[0069] The terminal hardware identifier may be hardware feature information unique to the terminal device itself, such as a globally unique terminal MAC address, i.e., the physical address of the network device interface; a serial number (SN); or a Bluetooth communication address.
[0070] The terminal communication protocol mentioned above can be the communication protocol currently used by the terminal. Voice communication devices typically use specific voice communication protocols, such as SIP (Session Initiation Protocol). Therefore, the access point can determine whether the terminal is a voice communication device by detecting whether the communication protocol used by the terminal matches the voice communication protocol. For example, it can detect whether SIP signaling packets are sent and received during terminal communication, or by parsing data packets at the data link layer to check for registration behavior.
[0071] It should be noted that in this embodiment, terminal devices can be divided into different organizational units, each of which has a corresponding identifier, namely an organizational unit identifier (OU identifier). Therefore, if the organizational unit identifier of a terminal matches the organizational unit identifier of a known voice communication device, then the terminal can be considered a voice communication device.
[0072] For example, the process of determining whether a terminal device is a voice communication device in this embodiment may be as follows:
[0073] 1) Terminal hardware identification matching:
[0074] In this embodiment, a communication hardware identification library (e.g., a MAC address library) corresponding to voice communication devices can be pre-established. When a terminal attempts to access the network, the access point first performs an access detection to obtain basic terminal information. The access point then quickly matches the terminal's hardware identification with the communication hardware identification library. If a match is found, the device is identified as a VoIP device.
[0075] 2) OU Matching: In some large networks, VoIP devices may belong to specific departments or teams. If a MAC address match fails, the system further checks the terminal's OU. If the terminal belongs to a known VoIP device organizational unit, it is identified as a VoIP device.
[0076] 3) Terminal Organizational Unit Identifier Matching: If neither the terminal hardware identifier nor the OU identifier can determine the terminal type, the access point can further analyze the terminal's protocol behavior. By monitoring specific protocol behaviors such as SIP signaling packets, the access point can determine whether the terminal is a VoIP device.
[0077] It's easy to understand that in addition to the aforementioned step-by-step identification process of "MAC address matching → OU identifier verification → protocol behavior analysis," an access point can also identify a terminal as a voice communication device if it detects that any of these conditions are met. That is, to add a new voice device to the communication system, an operator can do so by adding the new device's MAC address to the communication hardware identifier library via the web interface, or by assigning a corresponding OU identifier to the new device. Furthermore, an access point can automatically identify a new voice device based solely on the device's protocol behavior (e.g., SIP signaling detection). Therefore, this embodiment not only improves recognition accuracy (false positive rate <0.5%) by combining multi-dimensional features, but also supports the dynamic addition of new voice device types, enhancing system adaptability.
[0078] In this embodiment, the VoIP terminal identification mechanism achieves rapid and accurate identification of VoIP devices by combining multiple identification factors such as terminal hardware identification, organizational unit identification and communication protocol. It can analyze and judge the terminal more accurately and comprehensively, reduce the possibility of misjudgment, make the identification of voice communication equipment more accurate, and provide a more reliable foundation for subsequent resource allocation.
[0079] Step S30: When it is determined that the terminal is a voice communication device, a high-priority wireless resource is allocated to the terminal by using a preset dynamic resource allocation technology.
[0080] It should be noted that if the access point determines that the terminal is a voice communication device, which can be identified as a VOIP terminal, it can use pre-defined dynamic resource allocation technology to allocate higher-priority wireless resources to the VOIP terminal to ensure smooth and stable communication. For example, based on factors such as the current network load and the terminal's real-time needs, the voice communication device can be dynamically allocated a wider channel, higher bandwidth, or more stable frequency band. This reduces conflicts with data services and prevents interference from other non-voice communication services, effectively ensuring low-latency and low-jitter transmission of VoIP services for VOIP terminals, thereby improving voice service quality.
[0081] Exemplarily, the above-mentioned preset dynamic resource allocation technology can be the Orthogonal Frequency Division Multiple Access (OFDMA) of Wi-Fi 6, which can divide the channel into multiple resource units (RU) and then allocate exclusive RUs to the voice terminal; and / or it can be MU-MIMO (Multi-User Multiple Input Multiple Output) technology, which can add the voice terminal to the downlink MU-MIMO transmission group and give priority to scheduling its data packets.
[0082] In summary, to address the existing issues of complex wireless network voice service authentication processes, high registration failure rates, and the tendency for voice packets to be delayed or discarded when multiple terminals are connected concurrently, resulting in poor call quality, this embodiment first binds the WAPI authentication mechanism with SIP registration, performing dual identity verification when VoIP devices join the network. Specifically, this embodiment supports terminal identity-based access control, such as MAC address + SIP account binding, to prevent unauthorized device access, thereby improving the success rate of VoIP device network access, reducing the risk of unauthorized access, and ensuring the security of voice services.
[0083] In addition, this embodiment effectively identifies voice communication equipment by combining multiple identification factors such as terminal hardware identification, organizational unit identification and communication protocol, and provides it with dedicated, high-priority resource services, thereby avoiding voice delays, freezes and other problems caused by unreasonable resource allocation, improving voice service communication efficiency, and greatly improving the quality and stability of voice communication.
[0084] This embodiment provides an intelligent gateway method for ensuring quality of voice service over a wireless network. The method includes: responding to a terminal's access request, performing voice registration authentication on the terminal based on the terminal's Session Initiation Protocol registration information; sending an authentication request corresponding to the terminal to an authentication server upon receiving the authentication request; and providing feedback on the wireless LAN authentication result; and determining a security authentication result based on the wireless LAN authentication result. After security authentication passes, determining whether the terminal is a voice communication device based on multi-dimensional feature information of the terminal; the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol, and / or terminal organizational unit identification. If the terminal is determined to be a voice communication device, high-priority wireless resources are allocated to the terminal using a pre-defined dynamic resource allocation technique. To address the existing issues of complex wireless network voice service authentication processes, high registration failure rates, and the potential for voice data packets to be delayed or discarded when multiple terminals are connected concurrently, resulting in poor call quality, this embodiment first binds the WAPI authentication mechanism with SIP registration to perform dual identity authentication when VoIP devices join the network. Specifically, this embodiment supports terminal identity-based access control, such as MAC address + SIP account binding, to prevent unauthorized device access, thereby improving the success rate of VoIP device network access, reducing the risk of unauthorized access, and ensuring voice service security. Furthermore, this embodiment effectively identifies voice communication devices by combining multiple identification factors, including terminal hardware identification, organizational unit identification, and communication protocol, and provides them with dedicated, high-priority resource services. This avoids voice delays and freezes caused by improper resource allocation, improves voice service communication efficiency, and significantly enhances the quality and stability of voice communications.
[0085] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction and will not be repeated later.
[0086] It's easy to understand that in wireless network communications, VoIP terminals (such as cordless phones and softphones) may roam between different access points (APs) as users move around. As user mobility increases, traditional wireless networks struggle with issues like voice interruptions and unstable network connections during roaming, making it difficult to meet real-time communication needs and impacting communication quality.
[0087] Therefore, based on the first embodiment, please refer to Figure 2 , Figure 2 This is a flow chart of a second embodiment of the intelligent gateway method for ensuring quality of service of wireless network voice service in this application. In this embodiment, step S10 further includes step S11:
[0088] Step S11: Send the session initiation protocol registration information of the terminal to a wireless controller. When the wireless controller detects that the terminal roams to a new wireless access point, the wireless controller sends the session initiation protocol registration information to the new wireless access point, so that the new wireless access point reestablishes the voice session channel based on the session initiation protocol registration information.
[0089] It should be noted that this embodiment attempts to connect several wireless access points to an intelligent wireless gateway, namely the wireless controller mentioned above. The wireless controller records and manages the SIP registration information of VoIP terminals and provides necessary information support during terminal roaming. In this case, the wireless controller can serve as the management and control center for the entire wireless network, responsible for coordinating and scheduling each wireless access point.
[0090] It should be understood that in this embodiment, each wireless access point can send the SIP registration information of each VoIP terminal that is first accessing the wireless network and undergoing security authentication through voice communication registration to the wireless controller. The wireless controller maintains a registration information table, indexed by terminal MAC address, and updates the registration status in real time. When a voice communication device moves within the wireless network coverage area, from the coverage area of one wireless access point to the coverage area of another, the wireless controller can monitor this roaming event in real time. This is because the wireless access point and the wireless controller continuously exchange information to inform the controller of changes in the status of the currently connected terminal.
[0091] Therefore, when the wireless controller detects that any terminal has switched access points, it can quickly send the SIP registration information of the roaming terminal directly to the new wireless access point, assisting the new wireless access point to quickly reestablish the SIP channel, avoid call drops, and ensure voice session continuity, thereby significantly improving user experience and network stability.
[0092] For example, when a VoIP terminal roams from its current AP to a new AP, the new AP detects the terminal's access request. Based on the terminal's MAC address and other identifying information, the new AP can initiate a request to the wireless controller, requesting the terminal's Session Initiation Protocol registration information to avoid re-registration and re-authentication. The wireless controller retrieves the corresponding Session Initiation Protocol registration information based on the terminal's MAC address in the request and quickly sends it to the new AP.
[0093] The new AP then uses the roaming terminal's Session Initiation Protocol registration information obtained from the wireless controller to help the terminal reestablish the SIP channel. Based on the roaming terminal's original parameters, it initiates a SIP re-INVITE request to the SIP server to reestablish the session connection, allowing the session channel to be reestablished within 50ms.
[0094] Understandably, during the SIP channel reestablishment process, the new AP may perform necessary signaling interactions with the current AP or wireless controller to ensure smooth SIP channel reestablishment. Once the SIP channel is successfully reestablished, the VoIP endpoint will be able to continue voice communication through the new AP, ensuring uninterrupted voice communication.
[0095] In the second feasible implementation method, if the terminal loses connection due to sudden conditions such as interference during roaming and a brief communication interruption occurs, the terminal voice communication software (which can be represented as DINLINK APP) in the terminal device connected to the wireless access point can automatically attempt to use cached data to achieve a brief continuation of the voice conversation and monitor the network status in real time. Once the signal is restored, the connection is immediately re-established to ensure that the user's call experience is not significantly affected.
[0096] It will be readily understood that in this embodiment, the wireless controller can also be equipped with real-time monitoring capabilities. Upon detecting a terminal connection interruption, it can quickly assess network conditions and determine whether it is a temporary interference or a device failure. If the interference is temporary, the wireless controller will automatically attempt to reconnect, using pre-defined policies such as switching channels or adjusting transmit power to restore the connection and strive to ensure the stability of the terminal's network connection. It can utilize cached voice data or retransmission mechanisms to try to resume interrupted voice conversations. If a device failure occurs, an early warning message can be sent to the control center.
[0097] In this implementation, the voice session persistence mechanism effectively ensures voice session continuity for VoIP terminals during roaming by recording Session Initiation Protocol registration information, roaming detection and SIP information acquisition, SIP channel reestablishment, and session persistence. This effectively resolves the voice interruption issue that may occur during roaming, improving the continuity and stability of voice communication. Users can enjoy uninterrupted, high-quality voice communication services regardless of their mobility within the wireless network environment, thereby enhancing user satisfaction and loyalty. Furthermore, this voice session persistence mechanism improves the stability and reliability of wireless networks in supporting VoIP services, providing higher-quality voice communication services for a variety of scenarios, including government and enterprise campuses, manufacturing, education, and rail transit.
[0098] In a feasible implementation manner, in this embodiment, step S30 may further include step S40:
[0099] Step S40: sending the resource allocation policy corresponding to the terminal to the integrated access device through a preset communication protocol. After receiving the resource allocation policy, the integrated access device adjusts the processing priority corresponding to the terminal in the current data routing policy.
[0100] It is easy to understand that based on the allocation of high-priority wireless resources to voice communication devices in Example 1, this embodiment can further optimize the processing priority of data transmission to improve overall communication quality. The above-mentioned preset communication protocol can refer to an internal protocol that is pre-set within the current wireless network and specifies rules and standards for transmitting information and instructions between different devices.
[0101] After allocating high-priority wireless resources to a terminal identified as a voice communication device, the access point generates a resource allocation policy (QoS policy) that includes the terminal's IP address, priority level, bandwidth quota, and other information. Based on this internal protocol, the access point can further transmit the resource allocation policy corresponding to the VOIP terminal to the Integrated Access Device (IAD). The IAD integrates and processes multiple communication services, playing a key role in routing and switching data transmission.
[0102] Therefore, in this embodiment, after receiving the resource allocation policy corresponding to a terminal, the integrated access device can adjust its current data routing policy based on the instructions therein, optimizing the processing priority of outbound voice packets and ensuring that voice data is transmitted first. Specifically, this increases the processing priority of data transmission requests and data packets from voice communication devices, allowing them to receive priority processing among numerous data transmission tasks. For example, when data from multiple terminals arrives simultaneously at the integrated access device, the device prioritizes the data from the voice communication devices and forwards it quickly, thereby reducing voice data transmission delays and ensuring smooth voice communication.
[0103] For example, in this embodiment, after allocating high-priority wireless resources to a VOIP terminal, the access point can synchronize the resource allocation policy to the IAD device via an internal protocol. Based on the resource allocation policy, the IAD can modify the DSCP (Differentiated Services Code Point) priority corresponding to the terminal's IP address to EF (Expedited Forwarding), ensuring that voice packets corresponding to the VOIP terminal receive priority routing. Furthermore, the egress router can also adjust the placement of marked packets from the VOIP terminal into a high-priority queue (PQ) or a low-latency queue (LLQ) for prioritized dispatch.
[0104] It should be noted that the DSCP priority mentioned above is a 6-bit field used to mark the transmission priority of data packets in IP networks and is located in the ToS (Type of Service) field of the IP packet header. Compared to existing QoS policies, this embodiment proposes a cross-device QoS policy synchronization mechanism. By modifying DSCP through the IAD, end-to-end IP layer priority data transmission is achieved. This mechanism is compatible with all IP devices and matches all AP-IAD-public network links, ensuring that voice packets receive priority during any network congestion. Experimental comparisons have shown that existing wireless network voice transmission solutions without DSCP marking have voice delays >100ms (with jitter 30ms+), while this embodiment achieves delays ≤30ms and jitter ≤5ms. Therefore, this embodiment ensures the transmission quality of critical services (such as VoIP) through a cross-device, hierarchical scheduling mechanism based on DSCP priority, ensuring that voice data is prioritized.
[0105] Furthermore, policy synchronization between the access point and the integrated access device may be delayed, resulting in delayed voice packet priority marking. Therefore, in this embodiment, a real-time message queue (such as MQTT) can be used to transmit QoS policies to the integrated access device, and a policy version number and timeout retransmission mechanism can be configured to ensure policy synchronization delays of less than 10ms, thereby preventing impacts on voice continuity.
[0106] This implementation addresses the existing disconnect between wireless resource allocation and wired routing policies, which can result in voice data packets being delayed at the egress and a lack of end-to-end QoS assurance. By implementing a cross-device QoS policy synchronization mechanism, this implementation further optimizes the data transmission process for voice communication devices, ensuring that voice data is prioritized and transmitted throughout the entire network link. This improves the overall communication quality and service level of the wireless network, providing a more stable and reliable network environment for voice communication devices and meeting user demands for high-quality voice communication.
[0107] This embodiment discloses sending a terminal's SIP registration information to a wireless controller. Upon detecting that the terminal has roamed to a new wireless access point, the wireless controller then sends the SIP registration information to the new wireless access point, enabling the new wireless access point to reestablish a voice session channel based on the SIP registration information. The voice session persistence mechanism proposed in this embodiment effectively ensures voice session continuity for VoIP terminals during roaming by recording Session Initiation Protocol registration information, performing roaming detection and SIP information acquisition, and then reestablishing the SIP channel and maintaining the session. This effectively resolves the issue of voice interruptions that can occur during roaming, thereby improving the continuity and stability of voice communications.
[0108] This embodiment also discloses transmitting the resource allocation policy corresponding to a terminal to an integrated access device via a preset communication protocol. Upon receiving the resource allocation policy, the integrated access device adjusts the processing priority corresponding to the terminal in the current data routing policy. This embodiment further optimizes the data transmission process for voice communication devices, ensuring that voice data is preferentially processed and transmitted throughout the entire network link. This improves the overall communication quality and service level of the wireless network, providing a more stable and reliable network environment for voice communication devices and meeting user demands for high-quality voice communication.
[0109] For example, in order to help understand the technical concept or technical principle of the intelligent gateway method based on wireless network voice service quality assurance after combining this application with the above-mentioned application 1 and application 2, please refer to Figure 3 , Figure 3 This is a schematic diagram of the intelligent gateway control flow of the second embodiment of the intelligent gateway method for ensuring quality of service of wireless network voice based on this application, as follows:
[0110] like Figure 3 As shown, the control flow of this application begins with system initialization, with the terminal initiating an access request. After wireless access point detection, security authentication is performed in conjunction with voice communication registration. This security authentication process involves SIP registration information and WAPI certificates. This application binds WAPI authentication with SIP registration, supporting terminal identity-based access control and enhancing network security.
[0111] If authentication fails, access is denied. If authentication passes, the terminal's multi-dimensional feature information is used to determine the voice communication device. This paper proposes an innovative VoIP terminal identification mechanism that quickly determines VoIP devices based on multiple features, providing an accurate basis for QoS scheduling.
[0112] If the terminal is a voice communication device, high-priority resources are allocated; otherwise, regular resources are allocated. This dynamic QoS priority scheduling can be combined with Wi-Fi 6 technology to provide high-priority resources for real-time services and optimize network performance.
[0113] The access point then synchronizes the corresponding resource allocation policy to the integrated access device for further optimization of resource scheduling, enabling policy interaction and routing / queuing strategy optimization between the AP and IAD, ensuring efficient voice data transmission. This application proposes a QoS guarantee mechanism that integrates the collaborative work of the IAD gateway and Wi-Fi access points. Through intelligent scheduling, access management, and real-time monitoring, it improves the stability and availability of VoIP voice services in wireless environments.
[0114] Finally, the access point can also connect to a wireless controller and perform terminal roaming detection based on the wireless controller. When it detects that a terminal has roamed to a new wireless access point, the wireless controller sends the terminal's SIP registration information to the new wireless access point to assist in quickly reestablishing the voice conversation channel. In other words, this application utilizes the wireless controller to record Session Initiation Protocol registration information to assist in reestablishing the SIP channel when the terminal roams, thus avoiding dropped calls.
[0115] If no terminal roaming is detected, the existing data transmission continues and the resources are released after the communication ends.
[0116] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the intelligent gateway method for ensuring quality of service of wireless network voice based on this application. More simple transformations based on this technical concept are all within the scope of protection of this application.
[0117] This application also provides an intelligent gateway system based on wireless network voice service quality assurance, please refer to Figure 4 , Figure 4 This is a first structural diagram of an intelligent gateway system based on wireless network voice service quality assurance according to an embodiment of the present application. In this embodiment, the intelligent gateway system based on wireless network voice service quality assurance includes: a terminal 401 and a wireless access point 402; the wireless access point 402 is connected to the terminal 401;
[0118] The wireless access point 402 is configured to perform security authentication on the terminal 401 in response to an access request from the terminal 401, wherein the security authentication is bound to the voice communication registration;
[0119] The wireless access point 402 is configured to determine whether the terminal 401 is a voice communication device based on the multi-dimensional feature information of the terminal 401 after the security authentication is passed;
[0120] The wireless access point 402 is further configured to allocate high-priority wireless resources to the terminal 401 by using a preset dynamic resource allocation technology when determining that the terminal 401 is a voice communication device.
[0121] It is understandable that in this embodiment, the DWS2000HID indoor wireless access point can be preferably used as the above-mentioned wireless access point 402. The DWS2000HID is based on the Wi-Fi 6 standard and provides a wireless access rate of up to 2.976Gbps; supports FAT / FIT working modes, and can be plug-and-play with a wireless controller in FIT mode; has a gigabit uplink, and realizes wireless and wired high-speed transmission conversion through one 1G SFP port and two adaptive Ethernet electrical ports; supports multiple secure access and authentication and billing mechanisms, such as Portal / Web authentication, MAC address authentication, etc., to ensure network security; a single radio frequency supports up to 16 SSIDs to achieve refined wireless user management.
[0122] As a possible implementation method, in this embodiment, the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol and / or terminal organization unit identification.
[0123] As an implementation method, in this embodiment, the system further includes: an authentication server 403; the authentication server 403 is connected to the wireless access point 402;
[0124] The wireless access point 402 is further configured to respond to an access request from the terminal 401 and perform voice registration authentication on the terminal 401 based on the session initiation protocol registration information of the terminal 401;
[0125] The wireless access point 402 is further configured to send an authentication request corresponding to the terminal 401 to the authentication server 403 when the voice registration authentication is passed;
[0126] The authentication server 403 is configured to perform wireless LAN authentication on the terminal 401 upon receiving the authentication request and to feed back a wireless LAN authentication result;
[0127] The wireless access point 402 is further configured to determine a security authentication result based on the wireless local area network authentication result.
[0128] As an implementation method, in this embodiment, the system further includes: a wireless controller 404; the wireless controller 404 is connected to the wireless access point 402;
[0129] The wireless access point 402 is further configured to send the session initiation protocol registration information of the terminal 401 to the wireless controller 404;
[0130] The wireless controller 404 is configured to send the session initiation protocol registration information to the new wireless access point 402 when detecting that the terminal 401 roams to the new wireless access point 402, so that the new wireless access point 402 reestablishes the voice session channel based on the session initiation protocol registration information.
[0131] It is understandable that at this time, the wireless access point 402 is connected to the wireless controller 404 via a wired network. The wireless access point 402 uploads the collected terminal information and network status data to the wireless controller 404, and the wireless controller 404 uniformly manages and configures the wireless access point 402.
[0132] It will be readily understood that in this embodiment, the wireless controller 404 is preferably the DWS6000 Intelligent Wireless Gateway. The DWS6000 Intelligent Wireless Gateway integrates the functions of an enterprise-class gateway, a professional wireless controller 404, and a Portal authentication system. It can manage up to 300 APs, automatically adjusting AP channels and balancing load. It also features high-performance NAT and VPN (IPSec and L2TP) functions to ensure remote access security. It supports multiple authentication methods, such as Portal, account, and SMS authentication, enabling integrated wired and wireless authentication management. A visual monitoring interface provides real-time monitoring of network status, providing data support for network optimization.
[0133] As an implementation method, in this embodiment, the system further includes an integrated access device 405; the integrated access device 405 is connected to the wireless access point 402;
[0134] The wireless access point 402 is further configured to send the resource allocation policy corresponding to the terminal 401 to the integrated access device 405 via a preset communication protocol;
[0135] The integrated access device 405 is further configured to adjust the processing priority corresponding to the terminal 401 in the current data routing policy after receiving the resource allocation policy.
[0136] It is easy to understand that for VoIP services, terminal 401 exchanges voice data with integrated access device 405 based on wireless access point 402 and wireless controller 404. Integrated access device 405 and wireless access point 402 work together through QoS policy synchronization mechanism to ensure voice transmission quality.
[0137] During the security authentication process, identity authentication and data exchange are performed between the terminal 401, the wireless access point 402, the wireless controller 404, and the authentication server 403 to ensure that a legitimate device can access the network.
[0138] The system also includes terminal voice communication software 406, which can be represented as the DinLink app. Terminal 401 and wireless access point 402 can connect directly or through terminal voice communication software 406. This software provides enterprise IPPBX (Internet Protocol Private Branch Exchange) users with features such as pop-up notifications for incoming calls, click-to-dial, a corporate address book, voicemail, and call log viewing. Terminal voice communication software 406 supports WebRTC (Web Real-Time Communication) for voice / video calls and provides a voice conference room to meet employee collaboration and conferencing needs. It supports multiple languages and offers secure communication, utilizing WSS (WebSocket Secure) for encrypted transmission.
[0139] At the same time, the terminal voice communication software 406 is connected to the wireless access point 402 via a wireless network. The user can initiate a communication request through the terminal voice communication software 406, and the data is transmitted to the wireless controller 404 via the wireless access point 402, and then processed and forwarded by the wireless controller 404.
[0140] Therefore, refer to Figure 5 The system architecture of this embodiment is described in detail. Figure 5 This is a second structural diagram of the intelligent gateway system based on wireless network voice service quality assurance according to the embodiment of the present application. Figure 5 As shown, terminal 401 (including VoIP devices) can connect to wireless controller 404 via wireless access point 402. Wireless access point 402 collaborates with integrated access device 405 to ensure VoIP service quality and interacts with authentication server 403 for security authentication. Terminal voice communication software 406 communicates with terminal 401 and wireless access point 402 to implement enterprise communication functions. The overall operation of the system is achieved through specific data exchange between various devices and modules.
[0141] In this embodiment, in order to solve the problems of existing wireless network communication technologies in terms of stability, security, user management, system integration and deployment, a high-performance, highly reliable, and easy-to-manage wireless network communication is achieved to meet the needs of multiple scenarios such as government and enterprise parks, manufacturing, education, and rail transit. The proposed system integrates integrated access device 405 and wireless access point 402 to work together, combined with Wi-Fi 6's OFDMA / MU MIMO technology, to achieve dynamic QoS priority scheduling, allocate high-priority resources to real-time services such as VoIP, ensure low-latency and low-jitter transmission, and improve voice quality and overall network performance. The WAPI authentication mechanism is also bound to SIP registration, supporting identity access control based on terminal 401, such as MAC+SIP account binding, to improve the security of VoIP device access and reduce the risk of registration failure.
[0142] At the same time, the wireless controller 404 and the wireless access point 402 cooperate to support multi-SSID, multi-level and multi-service fine management, and implement different access control permissions, rate limits and authentication and billing strategies based on MAC addresses and IP addresses, flexibly meeting the needs of different users. Figure 5 As shown, the wireless controller 404 may also be connected to the integrated access device 405 to synchronize communication information between the wired network and the wireless network.
[0143] In summary, the intelligent wireless gateway system proposed in this embodiment integrates multiple functions and, together with AP products, forms an integrated, centrally managed wireless network system. The APs offer zero-configuration plug-and-play functionality, reducing investment and maintenance costs while improving deployment efficiency. It also supports multiple authentication methods, remote deployment across public networks, and intelligent switching of operating modes, adapting to complex network environments and diverse application scenarios, such as remote branch office networking and wireless coverage in diverse indoor environments.
[0144] Although the figure shows an intelligent gateway device based on wireless network voice service quality assurance with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or have instead.
[0145] The intelligent gateway system based on wireless network voice service quality assurance provided by this application utilizes the intelligent gateway method based on wireless network voice service quality assurance in the above-mentioned embodiments, and can solve the technical problems of intelligent gateways based on wireless network voice service quality assurance. Compared with the existing technology, the beneficial effects of the intelligent gateway system based on wireless network voice service quality assurance provided by this application are the same as the beneficial effects of the intelligent gateway method based on wireless network voice service quality assurance provided by the above-mentioned embodiments. Other technical features of the intelligent gateway system based on wireless network voice service quality assurance are the same as those disclosed in the above-mentioned embodiments and are not further described here.
[0146] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0147] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0148] In addition, the above are only some embodiments of the present application and do not limit the scope of the present application. All equivalent structural transformations made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the scope of protection of the present application.
Claims
1. An intelligent gateway method based on wireless network voice service quality assurance, characterized in that: The method comprises: In response to an access request from a terminal, performing security authentication on the terminal, wherein the security authentication is bound to a voice communication registration; After the security authentication is passed, determining whether the terminal is a voice communication device based on the multi-dimensional feature information of the terminal; the multi-dimensional feature information includes: terminal hardware identification, terminal communication protocol and / or terminal organization unit identification; When it is determined that the terminal is a voice communication device, high-priority wireless resources are allocated to the terminal using a preset dynamic resource allocation technology; the preset dynamic resource allocation technology includes: Wi-Fi 6's orthogonal frequency division multiple access and / or multi-user multiple input multiple output technology; The step of performing security authentication on the terminal in response to the access request of the terminal includes: In response to an access request from a terminal, performing voice registration authentication on the terminal based on session initiation protocol registration information of the terminal; When the voice registration authentication is passed, sending the authentication request corresponding to the terminal to the authentication server, the authentication server performs wireless LAN authentication on the terminal upon receiving the authentication request, and feeds back the wireless LAN authentication result; Determining a security authentication result based on the wireless local area network authentication result; After allocating high-priority wireless resources to the terminal by using a preset dynamic resource allocation technology when the terminal is determined to be a voice communication device, the method further includes: The resource allocation policy corresponding to the terminal is sent to the integrated access device through a preset communication protocol. After receiving the resource allocation policy, the integrated access device adjusts the processing priority corresponding to the terminal in the current data routing policy.
2. The intelligent gateway method based on wireless network voice service quality assurance according to claim 1, characterized in that: After performing security authentication on the terminal in response to the access request of the terminal, the method further includes: The session initiation protocol registration information of the terminal is sent to a wireless controller. When the wireless controller detects that the terminal has roamed to a new wireless access point, the wireless controller sends the session initiation protocol registration information to the new wireless access point, so that the new wireless access point reestablishes a voice session channel based on the session initiation protocol registration information.
3. An intelligent gateway system based on wireless network voice service quality assurance, characterized in that: The system includes: a terminal and a wireless access point; the wireless access point is connected to the terminal; The wireless access point is configured to perform security authentication on the terminal in response to an access request from the terminal, wherein the security authentication is bound to voice communication registration; The wireless access point is configured to determine, after the security authentication is passed, whether the terminal is a voice communication device based on multi-dimensional feature information of the terminal; the multi-dimensional feature information includes: a terminal hardware identifier, a terminal communication protocol, and / or a terminal organization unit identifier; The wireless access point is further configured to allocate high-priority wireless resources to the terminal by using a preset dynamic resource allocation technology when determining that the terminal is a voice communication device; the preset dynamic resource allocation technology includes: orthogonal frequency division multiple access and / or multi-user multiple input multiple output technology of Wi-Fi 6; The system further includes: an authentication server; the authentication server is connected to the wireless access point; The wireless access point is further configured to, in response to an access request of a terminal, perform voice registration authentication on the terminal based on the session initiation protocol registration information of the terminal; The wireless access point is further configured to send an authentication request corresponding to the terminal to the authentication server when the voice registration authentication is passed; The authentication server is configured to perform wireless local area network authentication on the terminal upon receiving the authentication request and to feed back a wireless local area network authentication result; The wireless access point is further configured to determine a security authentication result based on the wireless local area network authentication result; The system further comprises an integrated access device; the integrated access device is connected to the wireless access point; The wireless access point is further configured to send the resource allocation policy corresponding to the terminal to the integrated access device via a preset communication protocol; The integrated access device is further configured to adjust the processing priority corresponding to the terminal in the current data routing policy after receiving the resource allocation policy.
4. The intelligent gateway system based on wireless network voice service quality assurance according to claim 3, characterized in that: The system further comprises: a wireless controller; the wireless controller is connected to the wireless access point; The wireless access point is further configured to send the session initiation protocol registration information of the terminal to the wireless controller; The wireless controller is configured to, when detecting that the terminal roams to a new wireless access point, send the session initiation protocol registration information to the new wireless access point, so that the new wireless access point reestablishes a voice session channel based on the session initiation protocol registration information.
Citation Information
Patent Citations
Method and enterprise network system for realizing voice services in long term evolution enterprise network
CN103491641A
Method and system for controlling quality of service per subscriber in wireless LAN and access point therefor
KR1020120079279A