Femtocell location verification method and apparatus, node, and storage medium
By performing location verification at the first point of access to the network via home base stations, the network threat issues of unauthorized base station access and the location verification window in existing technologies are resolved, thus achieving higher network security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-04-02
AI Technical Summary
In existing technologies, the location verification method for home base stations is "access first, verification later," which means that illegal base stations may pose a threat and impact on the network during the access and location verification window.
The location information of the home base station is obtained through the second node and verified with the pre-obtained contracted location information. This serves as the first checkpoint for accessing the core network, rejecting the access of base stations that fail the location verification.
To minimize the threat and impact of unauthorized base stations on the core network and improve network security.
Smart Images

Figure CN2025125869_02042026_PF_FP_ABST
Abstract
Description
A home base station location verification method, device, node and storage medium
[0001] Cross-reference to Related Applications
[0002] The present disclosure is based on and claims priority from Chinese Patent Application No. 202411390885.0, filed on September 30, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0003] The present disclosure relates to the field of network information security, and particularly relates to a home base station location verification method, device, node and storage medium. BACKGROUND
[0004] In the third generation partnership project (3GPP, 3rd Generation Partnership Project), Femto is referred to as Home (e) Node B (H(e)NB), i.e., a home base station. Operators need to restrict the use of Femto base stations (or home base stations) in specific locations due to considerations of security, regulation, and charging, etc.
[0005] Currently, the scheme adopted for location access restriction is that a Femto base station reports its location-related information to a security gateway, which forwards the information to a Femto network management system, and the Femto network management system performs location verification to achieve control of the access area of the Femto base station. The current solution is equivalent to a "verify after access" method, which allows the Femto base station to access the core network or the network management system through the security gateway first, and then the network management system performs location restriction verification and control. The disadvantage of this method is that if the location verification fails, since the Femto base station has already accessed the core network, the illegal Femto base station may pose a threat and impact on the network during the window period of access and location verification. SUMMARY
[0006] The present disclosure provides a home base station location verification method, device, node and storage medium.
[0007] The technical solution of the embodiments of the present disclosure is as follows:
[0008] In a first aspect, the embodiments of the present disclosure provide a home base station location verification method, which is applied to a second node, and the method comprises: obtaining first location information of a first node; performing location verification on the first node based on the first location information and pre-obtained first information to obtain a location verification result, wherein the first information represents a subscription location of the first node.
[0009] In some optional embodiments of the present disclosure, the method further comprises: obtaining the second information in a preconfigured manner, the second information comprising the first information; or receiving the second information sent by the third node, the second information comprising the first information.
[0010] In some optional embodiments of the present disclosure, the second information further comprises a verification policy, the verification policy comprising at least one of: a request frequency of the location information, a type of the location information, a location verification method.
[0011] In some optional embodiments of the present disclosure, before the first location information of the first node is obtained, the method further comprises: performing identity authentication with the first node, and / or establishing a secure tunnel with the first node.
[0012] In some optional embodiments of the present disclosure, before the first location information of the first node is obtained, the method further comprises: sending a first request to the first node to request the first location information of the first node, the first request comprising a type of the location information.
[0013] In some optional embodiments of the present disclosure, the first location information of the first node is obtained by: receiving a first message sent by the first node in an authentication process with the first node, the first message comprising the first location information and authentication information of the first node.
[0014] In some optional embodiments of the present disclosure, the first message comprises a notification payload, the notification payload comprising a message type field and a data field, a value of the message type field being used to indicate that the first message is used to transmit the location information, and the data field carrying the first location information.
[0015] In some optional embodiments of the present disclosure, the first location information comprises at least one of the following information of the first node: an Internet Protocol (IP) address, a first geographic location, a first identifier of an associated macro base station.
[0016] And / or, the first information comprises at least one of the following information of the first node: a second geographic location, a second identifier of an associated macro base station.
[0017] In some optional embodiments of the present disclosure, when the first location information is a first geographic location and the first information is a second geographic location, or when the first location information is a first identifier of an associated macro base station and the first information is a second identifier of the associated macro base station, the location verification of the first node based on the first location information and the preconfigured first information to obtain a location verification result comprises: comparing the first location information with the first information, and determining that the location verification is passed after the comparison is consistent.
[0018] In some optional embodiments of the present disclosure, when the first location information is an IP address and the first information is a second geographic location, the location verification of the first node based on the first location information and the preconfigured first information to obtain a location verification result comprises: querying a fourth node to obtain a geographic location corresponding to the IP address; and comparing the geographic location with the first information, and determining that the location verification is passed after the comparison is consistent.
[0019] In a second aspect, the embodiments of the present disclosure further provide a home base station location verification method, which is applied to a first node, and the method comprises: sending first location information to a second node, so that the second node performs location verification based on the first location information and pre-obtained first information, wherein the first information represents a subscription location of the first node.
[0020] In some optional embodiments of the present disclosure, before the first location information is sent to the second node, the method further comprises: performing identity authentication with the second node, and / or establishing a secure tunnel with the second node.
[0021] In some optional embodiments of the present disclosure, before the first location information is sent to the second node, the method further comprises: receiving a first request sent by the second node, to request the first location information of the first node, wherein the first request comprises a type of location information.
[0022] In some optional embodiments of the present disclosure, the first location information is sent to the second node, comprising: sending a first message to the second node during the identity authentication process with the second node, wherein the first message comprises the first location information and authentication information of the first node.
[0023] In some optional embodiments of the present disclosure, the first message comprises a notification payload, wherein the notification payload comprises a message type field and a data field, the value of the message type field is used to indicate that the first message is used to transmit location information, and the data field carries the first location information.
[0024] In some optional embodiments of the present disclosure, the first location information comprises at least one of the following information of the first node: an Internet Protocol (IP) address, a first geographic location, and a first identity of an associated macro base station.
[0025] In a third aspect, the embodiments of the present disclosure further provide a home base station location verification apparatus, which is applied to a second node, and comprises a first communication unit and a first processing unit.
[0026] The first communication unit is configured to obtain first location information of a first node.
[0027] The first processing unit is configured to perform location verification on the first node based on the first location information and first information obtained in advance, to obtain a location verification result, wherein the first information indicates a subscription location of the first node.
[0028] In a fourth aspect, the embodiments of the present disclosure further provide a home base station location verification apparatus, which is applied to a first node, and comprises a second communication unit configured to send first location information to a second node, so that the second node performs location verification based on the first location information and first information obtained in advance, wherein the first information indicates a subscription location of the first node.
[0029] In a fifth aspect, the embodiments of the present disclosure further provide a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the steps of the method in the first aspect or the second aspect.
[0030] In a sixth aspect, the embodiments of the present disclosure further provide a communication device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method in the first aspect or the second aspect when executing the program.
[0031] In a seventh aspect, the embodiments of the present disclosure further provide a computer program product, which comprises computer program instructions, and the computer program instructions enable a computer to execute the steps of the method in the first aspect or the second aspect.
[0032] The home base station position verification method, device, node and storage medium provided by the embodiments of the present disclosure are as follows: a second node obtains first position information of a first node; based on the first position information and first information obtained in advance, the first node is subjected to position verification to obtain a position verification result; the first information represents a subscription position of the first node. Since the second node is the first pass for the first node to access a core network, if the position verification of the first node by the second node fails, the first node will be rejected to access the core network, thereby minimizing the threat and influence of illegal base stations on the core network. BRIEF DESCRIPTION OF DRAWINGS
[0033] Fig. 1 is a schematic diagram of a network architecture to which the embodiments of the present disclosure are applied;
[0034] Fig. 2 is a schematic diagram of a home base station position verification method according to an embodiment of the present disclosure;
[0035] Fig. 3 is a schematic diagram of a message format in a home base station position verification method according to an embodiment of the present disclosure;
[0036] Fig. 4 is a schematic diagram of a home base station position verification method according to an embodiment of the present disclosure;
[0037] Fig. 5 is a schematic diagram of an interaction flow of a home base station position verification method according to an embodiment of the present disclosure;
[0038] Fig. 6 is a schematic diagram of an interaction flow of a home base station position verification method according to an embodiment of the present disclosure;
[0039] Fig. 7 is a schematic diagram of a structure of a home base station position verification device according to an embodiment of the present disclosure;
[0040] Fig. 8 is a schematic diagram of a structure of a home base station position verification device according to an embodiment of the present disclosure;
[0041] Fig. 9 is a schematic diagram of a hardware structure of a node according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0042] The present disclosure will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0043] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a Global System of Mobile communication (GSM) system, a Long Term Evolution (LTE) system or a 5G system, a 6G system, etc. Optionally, the 5G system or 5G network can also be referred to as a New Radio (NR) system or NR network.
[0044] Exemplarily, the communication system to which embodiments of the present disclosure apply can include network devices and terminal devices (also referred to as terminals, communication terminals, etc.); the network devices can be devices that communicate with the terminal devices. Among them, the network devices can provide communication coverage in a certain area range, and can communicate with terminals located in the area. Optionally, the network devices can be base stations in various communication systems, for example, evolved Node Bs (eNBs) in LTE systems, for example, gNBs in 5G or NR systems, for example, base stations in 6G systems.
[0045] It should be understood that the devices with communication functions in the network / system in the embodiments of the present disclosure can be referred to as communication devices. The communication devices can include network devices and terminals with communication functions, and the network devices and terminal devices can be the specific devices described above, which will not be described here again; the communication devices can also include other devices in the communication system, such as network controllers, mobile management entities, and other network entities, which are not limited in the embodiments of the present disclosure.
[0046] It should be understood that the terms "system" and "network" are often used interchangeably in this paper. The term "and / or" in this paper is only used to describe the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents an "or" relationship between the associated objects before and after it.
[0047] The terms "first", "second", and the like in the embodiments of the present disclosure are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0048] Figure 1 is a schematic diagram of a network architecture to which the embodiments of the present disclosure are applied; as shown in Figure 1, a Femto access network mainly comprises: an H(e)NB, a security gateway (S(e)GW, SeGW), a home base station gateway (H(e)NB GW), and a network management system. The H(e)NB is a user private device, which is connected to the security gateway through a public Internet Protocol (IP) network, or in other words, an insecure link exists between the H(e)NB and the security gateway, and the security gateway connects the H(e)NB to a core network. A user equipment (UE) is connected to the H(e)NB to access the network through the H(e)NB.
[0049] The H(e)NB can also be referred to as a home base station, a Femto, a NR Femto, etc.
[0050] The network management system is specifically a home base station network management system, which can be referred to as an H(e)MS, a Femto MS, a NR Femto MS, etc.
[0051] In other optional embodiments, other network elements can also be included in the network, such as an authentication, authorization, and accounting (AAA) server (AAA Server) / home subscriber server (HSS) shown in the figure, or network elements not shown in the figure can also be included, which will not be described herein.
[0052] The embodiments of the present disclosure provide a home base station location verification method. Figure 2 is a schematic diagram of a home base station location verification method according to an embodiment of the present disclosure; as shown in Figure 2, the method comprises:
[0053] Step 101: a second node obtains first location information of a first node;
[0054] Step 102: based on the first location information and first information obtained in advance, performing location verification on the first node to obtain a location verification result; the first information indicates a subscription location of the first node.
[0055] In the embodiment, the first node is a node or device connected with the terminal. For example, referring to the system architecture shown in FIG. 1, the first node can be a home base station (or NR Femto, H(e)NB, etc.). In addition, the first node can be connected with a second node through a link, and the second node is a gateway node. For example, referring to the system architecture shown in FIG. 1, the second node can be a security gateway (S(e)GW, SeGW). It can be understood that the second node is the first node accessing the core network, that is, the first node can interact with other nodes in the core network only after accessing the second node.
[0056] In the embodiment, the first location information is location information of a current location of the first node, and the first location information can directly or indirectly represent the current location or area of the first node.
[0057] In the embodiment, the first information represents a contract location of the first node. Optionally, the first information can directly represent the contract location of the first node, or can indirectly represent or approximately represent the contract location of the first node.
[0058] The technical solution of the embodiment of the disclosure verifies the location of the first node by the second node. Since the second node is the first node accessing the core network, if the location verification of the first node by the second node fails, the first node will be rejected to access the core network, thereby minimizing the threat and influence of illegal base stations on the core network.
[0059] In some optional embodiments of the disclosure, the method further includes: obtaining the second information by a preconfigured manner, and the first information includes the first information; or receiving the second information sent by a third node, and the first information includes the first information.
[0060] In the embodiment, the second node obtaining the first information can include two ways: one way is to statically configure or store the first information in the second node by a preconfigured manner; and the other way is to dynamically send or configure the first information to the second node by a third node.
[0061] In the embodiment, the third node can be a home base station network management system (or can be referred to as H(e)MS, Femto MS, NR Femto MS), or can be other network elements of the core network, as long as the third node has a function of determining a corresponding geographical location by using an IP address, and the embodiment does not limit the third node.
[0062] In some optional embodiments, the second information further comprises a verification policy, and the verification policy comprises at least one of a request frequency of the location information, a type of the location information, and a location verification method.
[0063] In this embodiment, the verification policy is configured in a static pre-configuration manner or a dynamic manner, in addition to the subscription location of the first node (i.e., the first information).
[0064] In this embodiment, the request frequency of the location information can also be referred to as a frequency of requesting the first node to report the location information. As an implementation, the request frequency of the location information can comprise absolute time, for example, a plurality of time points. When the current time reaches each time point, the second node can request the first node to report the first location information by using an existing processing flow or a newly added processing flow. As another implementation, the request frequency of the location information can also comprise an initial time and a time interval, so as to determine a plurality of time points according to the initial time and the time interval, and request the first node to report the first location information.
[0065] In this embodiment, the type of the location information specifically represents a type of the first location information reported by the first node, and the first location information can directly or indirectly represent a geographic location or a region where the first node is located. In some optional embodiments, the type of the location information comprises at least one of an IP address, a geographic location, and an identifier of an associated macro base station.
[0066] The geographic location can be obtained by a satellite positioning manner, and can also be referred to as a satellite positioning location. The satellite positioning location can be specifically a location information obtained by using a Global Positioning System (GPS) positioning system, a Beidou satellite navigation positioning system, or the like. In other optional embodiments, the geographic location can also be obtained by using other positioning manners, which are not limited in this embodiment.
[0067] The identifier of the associated macro base station can be specifically an identifier of a macro base station closest to the first node, and can indirectly represent an approximate geographic location or a region where the first node is located.
[0068] In this embodiment, the position verification method is related to the type of the position information, and different types of position information have different position verification methods. For example, the type of the position information is a geographic position, and the first information is also a geographic position. The second node can directly compare the first position information with the first information for the type of the geographic position, so as to verify the position of the first node. For another example, the type of the position information is an IP address, and the first information is a geographic position. The second node needs to determine the geographic position corresponding to the IP address first, and then compare the geographic position with the first information, so as to verify the position of the first node. It can be understood that the position verification method is a processing method or process associated with the type of the position information.
[0069] In this embodiment, the second node can obtain the first position information of the first node in two ways. One is to perform the position verification of the first node by the second node after the authentication between the first node and the second node is completed, that is, the second node performs the authentication of the first node first, and then performs the position verification. The other is to perform the position verification simultaneously in the authentication process of the first node and the second node.
[0070] For the first implementation, in some optional embodiments, before the first position information of the first node is obtained, the method further includes: performing identity authentication with the first node, and / or establishing a secure tunnel with the first node.
[0071] In this embodiment, before the first position information of the first node is obtained by the second node, the identity authentication is performed between the second node and the first node, specifically, the identity of the first node is authenticated by the second node, and the identity of the second node is authenticated by the first node; and / or, a secure tunnel is established between the second node and the first node. For example, the secure tunnel can be an Internet Protocol Security (IPSec) tunnel.
[0072] In some optional embodiments, before the first position information of the first node is obtained, the method further includes: sending a first request to the first node to request the first position information of the first node, and the type of the position information is included in the first request.
[0073] In this embodiment, before the first position information of the first node is obtained by the second node, or in other words, after the identity authentication is performed between the second node and the first node, and / or the secure tunnel is established between the second node and the first node, the second node sends a first request to the first node to request the first position information of the first node. After receiving the first request, the first node sends the first position information to the second node.
[0074] The first request includes a type of location information configured in the verification policy, so that the second node can obtain the first location information of the corresponding type, and perform location verification on the first location information reported by the first node according to a location verification method configured in the verification policy.
[0075] In some optional embodiments of the second implementation, the obtaining of the first location information of the first node includes: receiving a first message sent by the first node in an authentication process with the first node, the first message including the first location information and authentication information of the first node.
[0076] In this embodiment, the second node can receive the first location information sent by the first node through an existing message in the authentication process with the first node. In this implementation, the first node can be pre-configured or set with a processing rule, that is, in the authentication process between the first node and the second node, the first location information of the first node is carried in a specified message according to the processing rule. In some optional embodiments, the authentication process between the second node and the first node includes authentication of the identity of the first node by the second node and authentication of the identity of the second node by the first node. In the above process, the first node needs to send its authentication information to the second node for authentication of the first node by the second node based on the authentication information of the first node, and the first location information of the first node can be carried in the message in which the first node sends the authentication information to the second node.
[0077] In this embodiment, the type of the first location information reported by the first node can be pre-agreed with the second node, or the second node can request and inform the type of the reported location information from the first node through an existing message in the authentication process with the first node.
[0078] In some optional embodiments, the authentication process between the second node and the first node can be based on the Internet Key Exchange version 2 (IKEv2, Internet Key Exchange version 2) protocol. In the IKEv2 handshake process, the first node actively reports the first location information. Specifically, when the first node initially accesses, after completing the IKE_SA_INIT process to establish a preliminary security association with the second node, the first node carries the first location information through an IKE_AUTH request in the IKE_AUTH stage. The first message in this embodiment can be specifically an IKE_AUTH request.
[0079] In some optional embodiments, the first message includes a notification payload, the notification payload including a message type field and a data field, a value of the message type field being used to indicate that the first message is used to transmit location information, and the data field carrying the first location information.
[0080] In the embodiment, the Notify Payload is one of the Payloads supported by the IKEv2, and is used to transfer informational data to the IKE peer. In the embodiment of the present disclosure, the first location information is carried by the Payload in the message. In the embodiment, the value of the Notify Message Type field of the Notify Payload is greater than 16383, which is used to represent the message transfer location information.
[0081] FIG. 3 is a schematic diagram of the message format in the home base station location verification method according to the embodiment of the present disclosure. As shown in FIG. 3, the format of the Notify Payload includes the Notify Message Type field and the Notification Data field. When the value of the Notify Message Type field is greater than 16383 (which can be pre-agreed by the first node and the second node, or agreed by the protocol), the first location information of the first node is carried in the Notification Data field.
[0082] In some optional embodiments, the first location information includes, but is not limited to, at least one of the following information of the first node: an Internet Protocol (IP) address, a first geographical location, a first identity of an associated macro base station; and / or the first information includes at least one of the following information of the first node: a second geographical location, a second identity of an associated macro base station.
[0083] In the embodiment, the first geographical location is the current geographical location of the first node, and the second geographical location is the geographical location when the first node is subscribed. Both the first geographical location and the second geographical location can be obtained by satellite positioning, which can also be referred to as satellite positioning location. The satellite positioning location can be the location information obtained by using the GPS positioning system, the Beidou satellite navigation positioning system, etc. In other optional embodiments, the first geographical location can also be obtained by using other positioning methods, which are not limited in the embodiment.
[0084] In the embodiment, the first identifier of the associated macro base station can be specifically an identifier of a macro base station closest to the first node, and can indirectly represent an approximate geographic position or a region where the first node is currently located. The second identifier of the associated macro base station can be specifically an identifier of a macro base station closest to the first node when the first node is subscribed, and can indirectly represent an approximate geographic position or a region where the first node is located when the first node is subscribed.
[0085] In some optional embodiments of the present disclosure, when the first location information is a first geographic position and the first information is a second geographic position, or when the first location information is a first identifier of an associated macro base station and the first information is a second identifier of the associated macro base station, the position verification of the first node based on the first location information and the preconfigured first information to obtain a position verification result comprises: comparing the first location information with the first information, and determining that the position verification is passed after the comparison is consistent.
[0086] In the embodiment, when the first location information reported by the first node is a first geographic position, that is, when the type of the location information requested by the second node is a geographic position, or when the type of the location information is agreed between the second node and the first node, the type of the subscription position (that is, the first information) of the first node configured in the second node is also a geographic position. After the second node receives the first location information, the second node can directly compare the first location information with the second geographic position in the first information, and determine that the position verification of the first node is passed after the comparison is consistent. Correspondingly, after the comparison is inconsistent, it is determined that the position verification of the first node is not passed.
[0087] In the embodiment, when the first location information reported by the first node is a first identifier of an associated macro base station, that is, when the type of the location information requested by the second node is an identifier of an associated macro base station, or when the type of the location information is agreed between the second node and the first node, the type of the subscription position (that is, the first information) of the first node configured in the second node is also an identifier of an associated macro base station. After the second node receives the first location information, the second node can directly compare the first location information (that is, the first identifier of the associated macro base station) with the second identifier of the associated macro base station in the first information, and determine that the position verification of the first node is passed after the comparison is consistent. Correspondingly, after the comparison is inconsistent, it is determined that the position verification of the first node is not passed.
[0088] In some optional embodiments of the present disclosure, when the first location information is an IP address and the first information is a second geographical location, the location verification of the first node based on the first location information and the preconfigured first information comprises: querying a fourth node to obtain a geographical location corresponding to the IP address; and comparing the geographical location with the first information, and determining that the location verification is passed when the comparison is consistent.
[0089] In the present embodiment, when the first location information reported by the first node is an IP address, the first information of the first node configured in the second node (i.e., the second location information) is a second geographical location, and the second node needs to query a fourth node based on the IP address to obtain a geographical location corresponding to the IP address, and then compare the obtained geographical location with the second geographical location. When the comparison is consistent, it is determined that the location verification of the first node is passed. Correspondingly, when the comparison is inconsistent, it is determined that the location verification of the first node is not passed.
[0090] Optionally, the fourth node can be a home base station network management system (or H(e)MS, Femto MS, NR Femto MS, etc.).
[0091] In the present embodiment, the first location information reported by the first node includes but is not limited to at least one of the following: an Internet Protocol (IP) address, a first geographical location, and an identifier of an associated macro base station. When the first node reports multiple types of first location information, the second node can compare and verify the multiple types of first location information with the second location information of the same type respectively, or compare and verify the first location information after being processed with the second location information of the same type, to obtain a verification result, thereby improving the accuracy of location verification.
[0092] Based on the above embodiments, the present disclosure further provides a home base station location verification method. FIG. 4 is a flowchart of a home base station location verification method according to an embodiment of the present disclosure; as shown in FIG. 4, the method comprises:
[0093] Step 201: A first node sends first location information to a second node, so that the second node performs location verification based on the first location information and pre-obtained first information, wherein the first information represents a subscription location of the first node.
[0094] In the embodiment, the first node is a node or device connected with the terminal. For example, referring to the system architecture shown in FIG. 1, the first node can be a home base station (or NR Femto, H(e)NB, etc.). In addition, the first node can be connected with a second node through a link, and the second node is a gateway node. For example, referring to the system architecture shown in FIG. 1, the second node can be a security gateway (S(e)GW, SeGW). It can be understood that the second node is the first node to access the core network, that is, the first node can interact with other nodes in the core network only after accessing the second node.
[0095] In the embodiment, the first location information is the location information of the current location of the first node, and the first location information can directly or indirectly represent the current location or area of the first node.
[0096] In the embodiment, the first information represents the contract location of the first node. Optionally, the first information can directly represent the contract location of the first node, or can indirectly represent the contract location of the first node, or can approximately represent the contract location of the first node.
[0097] The technical solution of the embodiment of the disclosure verifies the location of the first node by the second node. Since the second node is the first node to access the core network, if the location verification of the first node by the second node fails, the first node will be rejected to access the core network, thereby minimizing the threat and influence of illegal base stations on the core network.
[0098] In the embodiment, the first node can send the first location information to the second node in two ways. One is to perform the location verification of the first node by the second node after completing the authentication between the first node and the second node, that is, to perform the identity authentication of the first node by the second node first, and then perform the location verification. The other is to perform the location verification simultaneously in the identity authentication process between the first node and the second node.
[0099] For the first implementation, before the first location information is sent to the second node, the method further includes performing identity authentication with the second node, and / or establishing a secure tunnel with the second node.
[0100] In the embodiment, before the first node sends the first location information to the second node, the second node performs identity authentication with the first node, specifically, the second node authenticates the identity of the first node, and the first node authenticates the identity of the second node; and / or, the second node and the first node establish a secure tunnel, for example, the secure tunnel can be an IPSec tunnel.
[0101] In some optional embodiments, before the first node sends the first location information to the second node, the method further comprises: receiving a first request sent by the second node, the first request being used to request the first location information of the first node, and the first request comprising a type of location information.
[0102] In this embodiment, before the first node sends the first location information to the second node, or in other words, after identity authentication between the second node and the first node, and / or after a secure tunnel is established between the second node and the first node, the second node sends a first request to the first node to request the first location information of the first node. After receiving the first request, the first node sends the first location information to the second node.
[0103] In this embodiment, the first request comprises a type of location information configured in the verification policy, so that the second node can obtain the first location information of the corresponding type, and perform location verification on the first location information reported by the first node according to the location verification method configured in the verification policy.
[0104] For the second implementation, the sending of the first location information to the second node comprises: sending a first message to the second node during identity authentication between the second node and the first node, the first message comprising the first location information and authentication information of the first node.
[0105] In this embodiment, the second node can send the first location information of the first node to the second node through an existing message in the authentication process between the first node and the second node. In this implementation, the first node can be pre-configured or set with a processing rule, i.e., in the authentication process between the first node and the second node, the first location information of the first node is carried in a specified message according to the processing rule. In some optional embodiments, the authentication process between the second node and the first node comprises authentication of the identity of the first node by the second node, and authentication of the identity of the second node by the first node. In the above process, the first node needs to send its authentication information to the second node, so that the second node can authenticate the first node based on the authentication information of the first node. Therefore, the first location information of the first node can be carried in the message in which the first node sends the authentication information to the second node.
[0106] In this embodiment, the type of the first location information reported by the first node can be pre-agreed with the second node; or the second node requests and informs the type of the reported location information from the first node through an existing message in the authentication process between the first node and the second node.
[0107] In some optional embodiments, the authentication procedure between the second node and the first node can be based on the IKEv2 protocol. In the IKEv2 handshake procedure, the first node actively reports the first location information. Specifically, when the first node initially accesses, after the first node and the second node complete the IKE_SA_INIT procedure to establish a preliminary security association, in the IKE_AUTH stage, the first node carries the first location information through an IKE_AUTH request. The first message in the embodiment can be specifically the IKE_AUTH request.
[0108] In some optional embodiments, the first message includes a message type field and a payload field, a value of the message type field is used to indicate that the first message is used to transmit location information, and the payload field carries the first location information.
[0109] In the embodiment, the notify payload (Notify Payload) is one of the payloads supported by the IKEv2, and is used to transmit informational data to an IKE peer. In the embodiment of the disclosure, the first location information is carried by the notify payload (Notify Payload) in the message. The value of the notify message type (Notify Message Type) field of the notify payload (Notify Payload) is 0-16383, which is reserved for reporting error information. In the embodiment of the disclosure, the value of the notify message type (Notify Message Type) field is greater than 16383, which is used to indicate that the message transmits location information. The format of the notify payload (Notify Payload) can refer to FIG. 3.
[0110] In some optional embodiments, the first location information includes at least one of the following information of the first node: an IP address, a first geographic location, a first identifier of an associated macro base station.
[0111] In the embodiment, the first geographic location is a geographic location where the first node currently locates, and the first geographic location can be obtained by a satellite positioning manner, which can also be called a satellite positioning location. The satellite positioning location can be specifically a location information obtained by using a GPS positioning system, a Beidou satellite navigation positioning system, or the like. In other optional embodiments, the first geographic location can also be obtained by using other positioning manners, which are not limited in the embodiment.
[0112] In the embodiment, the first identifier of the associated macro base station can be specifically an identifier of a macro base station closest to the first node, which can indirectly represent an approximate geographic location or a region where the first node currently locates.
[0113] The home base station location verification method of the embodiment of the present disclosure is described in detail below with specific examples. In the following examples, the first node is H(e)NB, NR Femto or home base station (only NR home base station (NR Femto) is taken as an example in the figure), the second node is security gateway (SeGW), and the third node is home base station network management system (only NR home base station network management (NR Femto MS) is taken as an example in the figure).
[0114] The embodiment of the present disclosure provides a home base station location verification method. In the example, the security gateway (SeGW) is taken as the verification node to implement the check on the location information of the NR Femto, instead of the Femto network management in the existing standard. Specifically, after the NR Femto and the security gateway complete the two-way authentication and establish the IPSec tunnel, the security gateway then checks the location of the NR Femto. After the location verification is passed, the security gateway forwards the subsequent signaling and service data from the NR Femto to the core network.
[0115] FIG. 5 is a schematic diagram of the interaction flow of the home base station location verification method of the embodiment of the present disclosure; as shown in FIG. 5, the method comprises:
[0116] Step 300a: The security gateway statically configures the subscription location information of the NR home base station (NR Femto) and the check policy.
[0117] Step 300b: The subscription location information and the check policy of the NR home base station (NR Femto) are dynamically issued by the NR home base station network management (NR Femto MS) or other core network elements.
[0118] In the example, the subscription location information of the NR home base station (NR Femto) can be equivalent to the second location information in the above embodiment. The check policy can specifically include at least one of the following: the request frequency of the location information, the type of the location information, and the location check method.
[0119] In the example, the subscription location information and the location check policy of the NR home base station (NR Femto) can be statically stored in the security gateway in a pre-configuration manner (see step 300a), or the subscription location information and the location check policy of the NR home base station (NR Femto) can also be sent to the security gateway in a dynamic configuration manner by the NR home base station network management (NR Femto MS) or other core network elements (see step 300b).
[0120] Step 301: The NR home base station (NR Femto) and the security gateway perform two-way identity authentication to establish the IPSec connection.
[0121] Step 302: The security gateway requests the NR Femto to report the location information according to the verification policy.
[0122] Here, the request message can include the type of the location information.
[0123] Step 303: The NR Femto sends a response message to the security gateway, and the response message includes the location information.
[0124] Here, the location information can be equivalent to the first location information in the above embodiment.
[0125] Step 304: The security gateway verifies the location of the NR Femto according to the verification policy.
[0126] Here, in the case that the location information reported by the NR Femto is an IP address, the security gateway interacts with the NR Femto MS to query the location information corresponding to the IP address.
[0127] Here, the security gateway compares the obtained location information of the NR Femto with the subscribed location information, and determines that the location verification is passed in the case that the comparison is consistent; otherwise, determines that the location verification is failed.
[0128] Step 305: If the location verification fails, the security gateway returns a location verification failure response message to the NR Femto, and according to the local policy, can refuse to forward any subsequent message from the NR Femto, and reports to the NR Femto MS, etc.
[0129] The embodiment of the present disclosure also provides a home base station location verification method. The present example is that the security gateway is used as a verification node to verify the location information of the NR Femto, instead of the Femto MS in the existing standard. Specifically, if the IPSec is used for security protection between the NR Femto and the security gateway, in the IKEv2 handshake stage between the NR Femto and the security gateway, after the security gateway completes the identity verification of the NR Femto, the security gateway continues to verify the location of the NR Femto, and when both of them are verified, the IKEv2 handshake is successful, then the IPSec tunnel is established, and the security gateway accesses the core network.
[0130] Figure 6 is a schematic diagram of the interaction flow of the home base station location verification method according to the embodiment of the present disclosure; as shown in Figure 6, the method comprises:
[0131] Step 400a: the security gateway statically configures the subscription location information of the NR home base station (NR Femto) and the verification policy.
[0132] Step 400b: the security gateway dynamically issues the subscription location information of the NR home base station (NR Femto) and the verification policy through the NR home base station management (NR Femto MS) or other core network elements.
[0133] In this example, the subscription location information of the NR home base station (NR Femto) can be equivalent to the second location information in the above embodiment. The verification policy can specifically include at least one of the following: the request frequency of the location information, the type of the location information, and the location verification method.
[0134] In this example, the subscription location information of the NR home base station (NR Femto) and the verification policy can be statically stored in the security gateway in a pre-configuration manner (see step 400a), or the subscription location information of the NR home base station (NR Femto) and the verification policy can also be sent to the security gateway in a dynamic configuration manner through the NR home base station management (NR Femto MS) or other core network elements (see step 400b).
[0135] Step 401: the NR home base station (NR Femto) is securely started and device integrity is checked, and if the integrity check fails, the subsequent steps are not performed.
[0136] Step 402: the NR home base station (NR Femto) sends an IKE_SA_INIT request (IKE_SA_INIT request) to the security gateway to initiate the authentication of the NR home base station (NR Femto) by the security gateway.
[0137] Step 403: the security gateway sends an IKE_SA_INIT response (IKE_SA_INIT response) to the NR home base station (NR Femto) to request a digital certificate from the NR home base station (NR Femto).
[0138] The IKE_SA_INIT request and the IKE_SA_INIT response are based on the initial security link establishment procedure of the IKEv2 protocol. It can be understood that other information is also included in the IKE_SA_INIT request and the IKE_SA_INIT response. For details, refer to the initial security link establishment procedure based on the IKEv2 protocol, which will not be described here.
[0139] Step 404: In the first message (i.e., the first message) of the IKE_AUTH phase, the NR Femto sends an IKE_AUTH request message to the security gateway, and the message carries authentication information and location information.
[0140] Here, the NR Femto can carry ID in the IDi Payload of the request message, carry LOCATION_INFO in the Notify Payload, and carry authentication information in the AUTH Payload. The LOCATION_INFO can be the location information of the NR Femto.
[0141] Here, the authentication information can be the digital certificate of the NR Femto.
[0142] Here, the location information carried in the request message can be equivalent to the first location information in the above embodiment.
[0143] Step 405: The security gateway checks the authentication information of the NR Femto, for example, checks the digital certificate of the NR Femto to perform identity authentication.
[0144] Step 406: The security gateway checks the location of the NR Femto according to a check policy.
[0145] Here, in the case where the location information reported by the NR Femto is an IP address, the security gateway interacts with the NR Femto MS to query the location information corresponding to the IP address.
[0146] Here, the security gateway verifies the location of the NR Femto by comparing the LOCATION_INFO carried in the received Notify Payload with the locally stored subscription location information of the NR Femto. In the case of a consistent comparison, it is determined that the location verification is passed; otherwise, in the case of an inconsistent comparison, it is determined that the location verification is failed.
[0147] Step 407: If the verifications in steps 405 and 406 are both passed, the security gateway sends an IKE_AUTH response message to the NR Femto, carrying the authentication information of the security gateway, such as ID, digital certificate, SA, and other IKEv2 parameters, etc., and the IKEv2 negotiation is ended.
[0148] Step 408: The NR Femto verifies the authentication information of the security gateway, such as verifying the ID and digital certificate of the security gateway.
[0149] Based on the above embodiments, the embodiments of the present disclosure further provide a home base station location verification device, which is applied to a second node. FIG. 7 is a schematic diagram of a component structure of the home base station location verification device according to an embodiment of the present disclosure; as shown in FIG. 7, the device comprises a first communication unit 11 and a first processing unit 12; wherein,
[0150] The first communication unit 11 is configured to obtain first location information of a first node.
[0151] The first processing unit 12 is configured to perform location verification on the first node based on the first location information and first information obtained in advance, to obtain a location verification result; the first information indicates a subscription location of the first node.
[0152] In some optional embodiments of the present disclosure, the first processing unit 12 is further configured to obtain second information in a preconfigured manner, and the second information comprises second location information of the first node; or,
[0153] The first communication unit 11 is further configured to receive second information sent by a third node, and the second information comprises second location information of the first node.
[0154] In some optional embodiments of the present disclosure, the second information further comprises a verification policy, and the verification policy comprises at least one of the following: request frequency of location information, type of location information, and location verification method.
[0155] In some optional embodiments of the present disclosure, the first processing unit 12 is further configured to, before the first communication unit 11 obtains the first location information of the first node, perform identity authentication between the first communication unit 11 and the first node, and / or establish a secure tunnel between the first communication unit 11 and the first node.
[0156] In some optional embodiments of the present disclosure, the first communication unit 11 is further configured to, before obtaining the first location information of the first node, send a first request to the first node to request the first location information of the first node, wherein the first request comprises a type of location information.
[0157] In some optional embodiments of the present disclosure, the first communication unit 11 is configured to, in the authentication process with the first node, receive a first message sent by the first node, wherein the first message comprises the first location information and authentication information of the first node.
[0158] In some optional embodiments of the present disclosure, the first message comprises a notification payload, wherein the notification payload comprises a message type field and a data field, the value of the message type field is used to indicate that the first message is used to transmit location information, and the data field carries the first location information.
[0159] In some optional embodiments of the present disclosure, the first location information comprises at least one of the following information of the first node: an IP address, a first geographic location, and a first identifier of an associated macro base station; and / or the first information comprises at least one of the following information of the first node: a second geographic location and a second identifier of an associated macro base station.
[0160] In some optional embodiments of the present disclosure, in the case that the first location information is a first geographic location and the first information is a second geographic location, or in the case that the first location information is a first identifier of an associated macro base station and the first information is a second identifier of an associated macro base station, the first processing unit 12 is configured to compare the first location information with the first information, and determine that the location verification is passed after the comparison is consistent.
[0161] In some optional embodiments of the present disclosure, in the case that the first location information is an IP address and the first information is a second geographic location, the first processing unit 12 is configured to query a fourth node through the first communication unit 11 to obtain a geographic location corresponding to the IP address; compare the geographic location with the first information, and determine that the location verification is passed after the comparison is consistent.
[0162] In the embodiments of the present disclosure, the first processing unit 12 in the device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU) or a field-programmable gate array (FPGA) in actual application; and the first communication unit 11 in the device can be implemented by a communication module (including a basic communication suite, an operating system, a communication module, a standardized interface and a protocol, etc.) and a transceiving antenna in actual application.
[0163] The embodiments of the present disclosure further provide a home base station location verification device, which is applied to a first node. FIG. 8 is a schematic diagram of a component structure of the home base station location verification device according to an embodiment of the present disclosure; as shown in FIG. 8, the device comprises a second communication unit 21 configured to send first location information to a second node, so that the second node performs location verification based on the first location information and first information obtained in advance, wherein the first information represents a subscription location of the first node.
[0164] In some optional embodiments of the present disclosure, the device further comprises a second processing unit 22 configured to perform identity authentication between the second communication unit 21 and the second node and / or establish a secure tunnel between the second communication unit 21 and the second node before the second communication unit 21 sends the first location information to the second node.
[0165] In some optional embodiments of the present disclosure, the second communication unit 21 is further configured to receive a first request sent by the second node to request the first location information of the first node before sending the first location information to the second node, wherein the first request comprises a type of location information.
[0166] In some optional embodiments of the present disclosure, the second communication unit 21 is configured to send a first message to the second node in the identity authentication process between the second communication unit 21 and the second node, wherein the first message comprises the first location information and authentication information of the first node.
[0167] In some optional embodiments of the present disclosure, the first message comprises a notification payload, wherein the notification payload comprises a message type field and a data field, the value of the message type field is used to indicate that the first message is used to transmit location information, and the data field carries the first location information.
[0168] In some optional embodiments of the present disclosure, the first location information comprises at least one of the following information of the first node: an IP address, a first geographic location, and a first identity of an associated macro base station.
[0169] In the embodiments of the present disclosure, the second processing unit 22 in the device can be implemented by a CPU, a DSP, an MCU or an FPGA in actual application; and the second communication unit 21 in the device can be implemented by a communication module (including a basic communication suite, an operating system, a communication module, a standardized interface and a protocol, etc.) and a transceiving antenna in actual application.
[0170] It should be noted that the home base station location verification device provided by the above embodiments is only used for example to illustrate the division of the above program modules when the home base station location verification is performed. In actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the home base station location verification device and the home base station location verification method provided by the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be described here.
[0171] The embodiments of the present disclosure further provide a node, which can be the first node or the second node in the above embodiments. Fig. 9 is a schematic diagram of the hardware composition structure of the node according to the embodiments of the present disclosure. As shown in Fig. 9, the node comprises a memory 32, a processor 31 and a computer program stored in the memory 32 and executable on the processor 31, and the processor 31 implements the steps of the home base station location verification method applied to the first node or the second node according to the embodiments of the present disclosure when executing the program.
[0172] Optionally, the node can further comprise at least one network interface 33. Each component in the node is coupled together through a bus system 34. It can be understood that the bus system 34 is used to realize the connection and communication between the components. The bus system 34 comprises a data bus, a power supply bus, a control bus and a state signal bus. However, in order to clearly illustrate, all kinds of buses are marked as the bus system 34 in Fig. 9.
[0173] It can be appreciated that the memory 32 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a Read Only Memory (ROM), a Programmable Read-Only Memory (PROM), an Erasable Programmable Read-Only Memory (EPROM), an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Ferromagnetic Random Access Memory (FRAM), a Flash Memory, a magnetic surface memory, an optical disc, or a Compact Disc Read-Only Memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a Random Access Memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDR SDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 32 described in the embodiments of the present disclosure is intended to include, but not limited to, these and any other suitable types of memory.
[0174] The method disclosed in the embodiments of the present disclosure can be applied to the processor 31 or implemented by the processor 31. The processor 31 can be an integrated circuit chip having a processing capability of signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the processor 31 or the instruction in the form of software. The processor 31 described above can be a general processor, DSP, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The processor 31 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present disclosure. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, the execution can be directly completed by the hardware decoding processor or by the combination of hardware and software modules in the decoding processor. The software module can be located in the storage medium, which is located in the memory 32. The processor 31 reads the information in the memory 32 and combines the hardware to complete the steps of the above method.
[0175] In exemplary embodiments, the node can be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors (Microprocessor), or other electronic elements, for executing the above-mentioned methods.
[0176] In exemplary embodiments, the embodiments of the present disclosure also provide a computer-readable storage medium, such as the memory 32 including a computer program, which can be executed by the processor 31 of the node to complete the steps of the above-mentioned method. The computer-readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc. The storage medium can also be various devices including one or any combination of the above storage medium.
[0177] The computer-readable storage medium provided by the embodiments of the present disclosure has a computer program stored thereon, which is executed by the processor to implement the steps of the method for verifying the location of the first node or the home base station of the first node.
[0178] The embodiment of the present application further provides a computer program product, comprising a computer program, which can be executed by a node (such as the processor 31 of the node) to complete the steps of any of the foregoing home base station location verification methods.
[0179] The methods disclosed in the several method embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments.
[0180] The features disclosed in the several product embodiments provided by the present application can be combined arbitrarily without conflict to obtain new product embodiments.
[0181] The features disclosed in the several method or device embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments.
[0182] In the several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other manners. The embodiments described above are only schematic. For example, the division of units is only a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling, direct coupling or communication connection between the components can be indirect coupling or communication connection through some interfaces, or electrical, mechanical or other forms.
[0183] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed on a plurality of network units; some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0184] In addition, each functional unit in each embodiment of the present disclosure can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in the form of hardware, or in the form of hardware plus software function units.
[0185] Those skilled in the art can understand that all or part of the steps of the foregoing method embodiments can be completed by a program instruction related hardware, and the foregoing program can be stored in a computer readable storage medium, and the program is executed to perform the steps of the foregoing method embodiments; and the foregoing storage medium includes a mobile storage device, a ROM, a RAM, a magnetic disk or an optical disk, and various media that can store program codes.
[0186] Alternatively, the above-mentioned integrated unit of the present disclosure, if implemented in the form of a software function module and sold or used as an independent product, can also be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present disclosure can be embodied in the form of a software product in essence or in the form of a part of the prior art that contributes to the present disclosure. The computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the methods described in various embodiments of the present disclosure. The aforementioned storage medium includes mobile storage devices, ROM, RAM, magnetic disks or optical disks, and various media that can store program codes.
[0187] The above is only a specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present disclosure, which should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A method for verifying a location of a home base station, the method being applied to a second node, the method comprising: obtaining first location information of a first node; performing a location check on the first node based on the first location information and pre-obtained first information to obtain a location check result, wherein the first information indicates a subscribed location of the first node. The method further comprises: obtaining second information in a preconfigured manner, wherein the second information comprises the first information; or receiving second information sent by a third node, wherein the second information comprises the first information. The second information further comprises a check policy, wherein the check policy comprises at least one of a request frequency of location information, a type of location information, and a location check method. Before the obtaining of the first location information of the first node, the method further comprises: performing identity authentication with the first node, and / or establishing a secure tunnel with the first node. Before the obtaining of the first location information of the first node, the method further comprises: sending a first request to the first node to request the first location information of the first node, wherein the first request comprises a type of location information. The obtaining of the first location information of the first node comprises: receiving a first message sent by the first node in an authentication process with the first node, wherein the first message comprises the first location information and authentication information of the first node. The first message comprises a notification payload, wherein the notification payload comprises a message type field and a data field, a value of the message type field is used to indicate that the first message is used to transmit location information, and the data field carries the first location information. The first location information comprises at least one of an Internet Protocol (IP) address, a first geographical location, and a first identifier of an associated macro base station of the first node; and / or the first information comprises at least one of a second geographical location and a second identifier of the associated macro base station. In a case where the first location information is the first geographical location and the first information is the second geographical location, or in a case where the first location information is the first identifier of the associated macro base station and the first information is the second identifier of the associated macro base station, the performing of the location check on the first node based on the first location information and the pre-obtained first information to obtain the location check result comprises: comparing the first location information with the first information, and determining that the location check is passed after the comparison is consistent. In a case where the first location information is the IP address and the first information is the second geographical location, the performing of the location check on the first node based on the first location information and the pre-obtained first information to obtain the location check result comprises: querying a fourth node to obtain a geographical location corresponding to the IP address; comparing the geographical location with the first information, and determining that the location check is passed after the comparison is consistent. 11.A method for verifying a location of a home base station, the method being applied to a first node, the method comprising: 2. The method of claim 1, wherein, 3. The method of claim 2, wherein, 4. The method according to any one of claims 1 to 3, wherein, 5. The method of claim 4, wherein, 6. The method according to any one of claims 1 to 3, wherein, 7. The method of claim 6, wherein, 8. The method according to any one of claims 1 to 3, wherein, 9. The method of claim 8, wherein, 10. The method of claim 8, wherein, sending first location information to a second node, for the second node to perform location verification based on the first location information and first information obtained in advance, the first information indicating a subscription location of the first node.
12. The method of claim 11, wherein, Before the sending of the first location information to the second node, the method further comprises: performing identity authentication with the second node, and / or establishing a secure tunnel with the second node.
13. The method of claim 12, wherein, Before the sending of the first location information to the second node, the method further comprises: receiving a first request sent by the second node, for requesting the first location information of the first node, the first request including a type of location information.
14. The method of claim 11, wherein, The sending of the first location information to the second node comprises: sending a first message to the second node in the identity authentication with the second node, the first message including the first location information and authentication information of the first node.
15. The method of claim 14, wherein, The first message includes a notification payload, the notification payload including a message type field and a data field, a value of the message type field being used to indicate that the first message is used to transmit location information, and the data field carrying the first location information.
16. The method of claim 11, wherein, The first location information includes at least one of the following information of the first node: an Internet Protocol (IP) address, a first geographical location, and a first identity of an associated macro base station.
17. A home base station location verification apparatus, the apparatus being applied to a second node, the apparatus comprising: a first communication unit and a first processing unit; wherein the first communication unit is configured to obtain first location information of a first node; the first processing unit is configured to perform location verification on the first node based on the first location information and first information obtained in advance, and obtain a location verification result, the first information indicating a subscription location of the first node.
18. A home base station location verification apparatus, the apparatus being applied to a first node, the apparatus comprising: a second communication unit configured to send the first location information to a second node, for the second node to perform location verification based on the first location information and first information obtained in advance, the first information indicating a subscription location of the first node. 19.A computer readable storage medium having stored thereon a computer program which, when executed by a processor, implements the steps of the method of any one of claims 1 to 10; or which, when executed by a processor, implements the steps of the method of any one of claims 11 to 16. 20.A communication device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method of any one of claims 1 to 10 when executing the program; or the processor implements the steps of the method of any one of claims 11 to 16 when executing the program. 21.A computer program product comprising computer program instructions which cause a computer to perform the steps of the method of any one of claims 1 to 10; or which cause a computer to perform the steps of the method of any one of claims 11 to 16.
Citation Information
Patent Citations
Household miniature base station access control method and system
CN101335984A
Femtocell position verification method and device, node and storage medium
CN119325090A
Method, apparatus and system for transmitting location information
WO2012065846A1
Home base station location information
WO2013167589A1