Abstract:
The invention provides methods and devices for reporting and parsing the errors of a packet based on IPSec protocol family in a communication network. Concretely, the reserved field in ICMP security failure message is used to denote the error type at the second level of the error in the packet. With the aid of the solution provided by the invention, it is possible to report the error types for a tunnel packet which has an error in detail. And the source termination device can ascertain the error types of a tunnel packet, so as to eliminate the error.
Abstract:
With migration of network technology and more and more requirements of user equipment for accessing to Internet, the network security faces more and more severe situation. There is provided a method for distributed security control in communication network system and the device thereof in order to improve security and operatability of network operator. In the method, firstly the network controller establishes a network security control mechanism, which is used for a second network device to check the validity of the data package from the user equipment; secondly, the network controller sends the network security control mechanism to the second network devices; lastly, the second network device checks the validity of the data package from the user equipment according to the network security control mechanism, and discards the data package if the data package is invalid. With the present invention, security and operatability of the communication network may be improved greatly, particularly, the functionality of address anti-spoofing can be implemented in the network with a WLAN architecture in centralized control.
Abstract:
The present invention provides a method and apparatus of providing network services to a mobile user equipment, where the mobile user equipment is connected to a fixed access network via a Femtocell base station and thus connected to the mobile core network. The mobile core network provides an access token to a Femtocell base station. The Femtocell requests the fixed access network with the access token to perform network resource configuration for the mobile user equipment. The mobile user equipment establishes a network service connection based on the network resource configuration. In this way, technically, it may be guaranteed that the mobile user equipment can be legal listened. Dependent on different service attributes of the mobile user equipment, different network access manners may be implemented, such that operators of mobile and fixed access networks may reasonably commercially apportion the charges based on their respective network resource occupation situations.
Abstract:
The present invention proposes a method for controlling the uplink transmission of the multicast IP packet sourced from the UE in field of IP packet transmission in access network. According to the technical solution of the present invention, the access devices receives IP packet from the UE, checks the IP packet and determines whether the IP packet is multicast IP packet that is allowed to be accessed. If the access device determines that the IP packet is multicast IP packet that is allowed to be accessed, then it sends the multicast IP packet in multicast form. Via the present invention, the access device can allow the uplink valid multicast IP packet to pass, preferably, determines and intercepts the malicious attacks via multicast IP packet, so as to ensure the DSL access device's support for mobile IPv4, so as to keep the uninterrupted connection of the service to the user when the user moves between different subnets.
Abstract:
An exemplary technique is provided for communication in a personal area network. The technique includes transmitting, to a personal area network coordinator, joint information of a sensor device indicated by reserved bits and includes a type, a channel access rate, and a latest node buffer occupation rate of the sensor device; receiving, from the personal area network coordinator, information regarding adjusted active duration and duty cycle of the communication of the sensor device; and performing further communication based upon the adjusted active duration and duty cycle. Also, the technique includes receiving, from a sensor device, joint information indicated by reserved bits and includes a type, a channel access rate, and a latest node buffer occupation rate of the sensor device; adjusting an active duration and a duty cycle of the communication of the sensor device; and transmitting information regarding the adjusted active duration and duty cycle to the sensor device.
Abstract:
The present invention relates to a Femtocell providing services to a UE, and it proposes a method for authenticating a UE registered in a first operating domain of a communication network (e.g. a mobile core network), when the UE requests the service provided by a second operating domain (e.g. a fixed access network, a backhaul network). An authentication server in the first operating domain allocates the needed information to access the service provided by the second operating domain for the UE, and stores. After receiving the needed information, the UE sends an authentication request message to an authentication server in the second operating domain, wherein the authentication server in the second operating domain forwards the authentication request message to the authentication server in the first operating domain.
Abstract:
A method for configuring, in a preset node within an anycast group, non-preset nodes within the group and a control device therefor are provided. The method comprises: generating one or more address configuration messages based on the predetermined configuration address information; and sending to each of non-preset nodes within the anycast group the address configuration message corresponding to the non-preset node. A method for assistant configuration of non-preset nodes within an anycast group and an assistance control device therefor are also provided.