Wireless local area network access gateway and method for ensuring network security therewith
    71.
    发明授权
    Wireless local area network access gateway and method for ensuring network security therewith 有权
    无线局域网接入网关及确保网络安全的方法

    公开(公告)号:US07224699B2

    公开(公告)日:2007-05-29

    申请号:US11261373

    申请日:2005-10-28

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    IPC分类号: H04L12/28 H04L12/66 G06F15/16

    摘要: A wireless local area network access gateway (WAG) includes a routing enforcement module and a charging module. The data packets sent via the WAG are outputted to the service authentication and authorization unit or packet data gateway (PDG) of WLAN or the WLAN UE after the forced route processing and collection of charging information. The WAG further includes a message filtering module for acquiring and storing packet filtering rules as well as discriminating, filtering and screening the data packets currently passing the WAG. Also disclosed is a method for ensuring network security by utilizing the WAG. With the disclosed WAG and method, data packets can be discriminated, filtered, and screened so as to prevent as much as possible illegal messages from interfering and threatening the network operation, prevent the transmission of illegal messages, improve the security of the network, and reduce the load of the network.

    摘要翻译: 无线局域网接入网关(WAG)包括路由执行模块和充电模块。 通过WAG发送的数据包在强制路由处理和收费计费信息之后被输出到WLAN或WL​​AN UE的服务认证和授权单元或分组数据网关(PDG)。 WAG还包括消息过滤模块,用于获取和存储分组过滤规则,以及鉴别,过滤和筛选当前通过WAG的数据分组。 还公开了通过利用WAG来确保网络安全性的方法。 利用所公开的WAG和方法,可以对数据分组进行鉴别,过滤和筛选,以便尽可能地防止非法消息干扰和威胁网络操作,防止非法消息的传输,提高网络的安全性,以及 减轻网络负载。

    Method for implementing roaming charging and system thereof
    72.
    发明申请
    Method for implementing roaming charging and system thereof 有权
    实施漫游充电的方法及其系统

    公开(公告)号:US20070111705A1

    公开(公告)日:2007-05-17

    申请号:US11589422

    申请日:2006-10-30

    IPC分类号: H04M11/00

    摘要: The present invention discloses a method for implementing roaming charging, including: a proxy CRF is configured in the PLMN; a terminal uses bearer resources or packet data services in the currently visited PLMN to provide information for selecting charging rules for the home CRF through the proxy CRF in the PLMN, the home CRF selects the charging rules according to the information and provides the charging rules for the TPF serving the current terminal. The present invention also provides a system for implementing roaming charging, which includes a TPF, a home CRF in the terminal's home PLMN and a proxy CRF in the PLMN other than the terminal's home PLMN. When the terminal is roaming and utilizing the bearer resources or packet data services in the currently visited PLMN, the problem of addressing among the functions when implementing the data flow based charging procedure based on FBC mechanism is solved.

    摘要翻译: 本发明公开了一种实现漫游计费的方法,包括:在PLMN中配置代理CRF; 终端使用当前访问的PLMN中的承载资源或分组数据业务,通过PLMN中的代理CRF提供用于选择归属CRF的计费规则的信息,归属CRF根据该信息选择计费规则,并提供用于 TPF服务于当前终端。 本发明还提供了一种用于实现漫游计费的系统,其包括TPF,终端的归属PLMN中的归属CRF和除终端的归属PLMN之外的PLMN中的代理CRF。 当终端漫游并利用当前访问的PLMN中的承载资源或分组数据业务时,解决了基于FBC机制实现基于数据流的计费过程时的功能之间的寻址问题。

    Method for releasing a service tunnel in a wireless local area network
    73.
    发明申请
    Method for releasing a service tunnel in a wireless local area network 有权
    一种用于在无线局域网中释放业务隧道的方法

    公开(公告)号:US20070019600A1

    公开(公告)日:2007-01-25

    申请号:US11481057

    申请日:2006-07-06

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    IPC分类号: H04Q7/24

    摘要: The present invention discloses a method for releasing a service tunnel in WLAN. This method comprises: an originating end point that desires to release a service tunnel in a WLAN sending a release tunnel request to a corresponding end point of the service tunnel; the corresponding end point returning a release acknowledgement to the originating end point, and releasing resources of the service tunnel, a Packet Data Gateway (PDG) sends a tunnel disconnection report to a service authentication and authorization unit, and upon receiving the tunnel disconnection report, the service authentication and authorization unit updates self-stored information related to the released service tunnel. The method in accordance with the present invention makes it possible to implement the release of a designated service tunnel and release or update the related resources and information in time.

    摘要翻译: 本发明公开了一种在WLAN中释放业务隧道的方法。 该方法包括:发起端点,期望在WLAN中发布服务隧道,发送释放隧道请求到服务隧道的对应端点; 相应的终点返回发起端点的释放确认,释放业务隧道的资源,分组数据网关(PDG)向业务认证授权单元发送隧道断开报告,接收到隧道断线报告后, 服务认证和授权单元更新与发布的服务隧道相关的自存信息。 根据本发明的方法使得可以实现指定的服务隧道的释放,并及时释放或更新相关的资源和信息。

    Method for user terminal accessing home network quickly in wireless local area network
    75.
    发明申请
    Method for user terminal accessing home network quickly in wireless local area network 有权
    用户终端无线局域网快速接入家庭网络的方法

    公开(公告)号:US20060111107A1

    公开(公告)日:2006-05-25

    申请号:US11262510

    申请日:2005-10-28

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    IPC分类号: H04Q7/20

    CPC分类号: H04W48/18 H04L63/10 H04W84/12

    摘要: The present invention discloses a method for a user terminal in a Wireless Local Area Network (WLAN) quickly accessing its home network. Pre-store in each user terminal, respectively, the identifications of all the WLANs with direct connections to the home network of the corresponding user terminal. For a user terminal that is in an area covered by more than one WLAN, compare the identification of each of the detected WLANs with the WLAN identifications stored in the current user terminal. A successful matching between the identification of a detected WLAN and a pre-stored WLAN identification then means that the home network of the current user terminal is connected with the corresponding WLAN access network and can be accessed via this WLAN. If a plurality of detected WLAN identifications match the stored identifications, select in accordance with a pre-defined selecting rule one of the corresponding WLANs and get accessed via the selected WLAN. This method enables a user terminal covered by more than one WLAN to find quickly a WLAN access network directly connected with its home network and to access the home network via this WLAN.

    摘要翻译: 本发明公开了一种无线局域网(WLAN)中用户终端快速访问其归属网络的方法。 分别在每个用户终端中预先存储与相应用户终端的家庭网络直接连接的所有WLAN的标识。 对于在多于一个WLAN覆盖的区域内的用户终端,将每个检测到的WLAN的识别与存储在当前用户终端中的WLAN标识进行比较。 所检测到的WLAN的识别与预先存储的WLAN标识之间的成功匹配意味着当前用户终端的归属网络与相应的WLAN接入网络相连,并且可以经由该WLAN访问。 如果多个检测到的WLAN标识与所存储的标识匹配,则根据预定义的选择规则选择相应的WLAN中的一个,并经由所选择的WLAN被访问。 该方法使得由多于一个WLAN覆盖的用户终端能够快速地找到与其家庭网络直接相连的WLAN接入网络,并经由该WLAN接入家庭网络。

    Method for resolving and accessing selected service in wireless local area network
    76.
    发明申请
    Method for resolving and accessing selected service in wireless local area network 有权
    在无线局域网中解决和访问所选服务的方法

    公开(公告)号:US20060111082A1

    公开(公告)日:2006-05-25

    申请号:US11260866

    申请日:2005-10-27

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    IPC分类号: H04M1/66

    摘要: The present invention discloses a method for resolving and accessing a selected service in a Wireless Local Area Network (WLAN), wherein a service resolving unit is preconfigured for initial access, the method comprising: a WLAN user terminal sending a service establishing request to the service resolving unit; after receiving the service establishing request, the service resolving unit sending a service authentication and authorization request containing the user's subscription information to the service authentication authorization unit, which performs authentication and authorization to the requesting WLAN user terminal; then judging whether the authentication and authorization is successful, if yes, the service authentication authorization unit returning the address of the authorized destination device to the requesting WLAN user terminal so as to establish a service connection between the WLAN user terminal and the destination device; otherwise, the service authentication authorization unit returning the failure information of the service establishing request. With this method, the analytical access processing of the selected service can be simplified while the security and reliability of the network greatly enhanced.

    摘要翻译: 本发明公开了一种在无线局域网(WLAN)中解决和访问所选服务的方法,其中业务分解单元被预配置用于初始接入,所述方法包括:WLAN用户终端向业务发送业务建立请求 解析单位 在接收到服务建立请求之后,服务解析单元向服务认证授权单元发送包含用户订阅信息的服务认证和授权请求,对请求的WLAN用户终端进行认证授权; 然后判断认证和授权是否成功,如果是,则服务认证授权单元将授权的目的地设备的地址返回给请求的WLAN用户终端,以在WLAN用户终端和目的设备之间建立业务连接; 否则,服务认证授权单元返回服务建立请求的故障信息。 通过这种方法,可以简化所选服务的分析访问处理,同时网络的安全性和可靠性大大提高。

    Method of user access authorization in wireless local area network

    公开(公告)号:US20060109826A1

    公开(公告)日:2006-05-25

    申请号:US11260865

    申请日:2005-10-27

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    IPC分类号: H04L9/32 H04Q7/24

    摘要: The present invention discloses a method of user access authorization in wireless local area networks. The method comprises: when a Wireless Local Area Network (WLAN) user terminal is accessing a WLAN operational network, the WLAN operational network, while authenticating this WLAN user terminal, judging whether to allow this WLAN user terminal to access according to authorization conditions having an impact on the access of this WLAN user terminal, if yes, the WLAN operational network will determine the access rules of this WLAN user terminal according to the said authorization conditions; otherwise, the WLAN operational network will notify the WLAN user terminal about the failure. By adopting the method of the present invention, different users can be controlled to access the network according to different authorization conditions, and be restricted by different access rules after getting accessed. As a result, the access control capability of a wireless local area network is enhanced and the working efficiency of the network is improved.

    WLAN service system and method for charging based on user data flow
    78.
    发明申请
    WLAN service system and method for charging based on user data flow 审中-公开
    WLAN业务系统和用户数据流量计费方法

    公开(公告)号:US20050276271A1

    公开(公告)日:2005-12-15

    申请号:US11143912

    申请日:2005-06-02

    申请人: Wenlin Zhang

    发明人: Wenlin Zhang

    摘要: The invention discloses a WLAN service system for charging based on the user data flow, and the system includes: a WLAN user equipment, a WLAN access network, a Packet Data Gateway and a charging service unit that generates charging information and is connected with the Packet Data Gateway; the invention also discloses a charging method based on the user data flow, and in this method a Packet Data Gateway takes statistic for the current user data flow to obtain original data flow information that is then transmitted to the charging service unit; having received the original charging related information, the charging service unit generates charging information that is then transferred to a charging system. With this system and method, packet data passing through the Packet Data Gateway can be charged based on the data flow.

    摘要翻译: 本发明公开了一种基于用户数据流量进行计费的WLAN业务系统,该系统包括:WLAN用户设备,WLAN接入网,分组数据网关和计费业务单元,生成计费信息,并与分组 数据网关 本发明还公开了一种基于用户数据流的计费方法,并且在该方法中,分组数据网关对当前用户数据流进行统计以获得原始数据流信息,然后将其发送给计费服务单元; 已经接收到原始计费相关信息,计费服务单元产生然后传送到计费系统的计费信息。 利用该系统和方法,可以基于数据流来对通过分组数据网关的分组数据进行计费。

    Method, a system and a terminal for realizing presenting information interaction of the wireless LAN users
    79.
    发明申请
    Method, a system and a terminal for realizing presenting information interaction of the wireless LAN users 审中-公开
    方法,系统和终端,用于实现无线局域网用户的信息交互

    公开(公告)号:US20050265296A1

    公开(公告)日:2005-12-01

    申请号:US11124600

    申请日:2005-05-05

    摘要: A method for implementing presence information interaction of WLAN (Wireless Local Area Network) subscriber and the system and terminal thereof, wherein, the method comprises setting one or more than one presence information monitoring unit, detecting the presence information by the presence information monitoring unit, and transmitting this presence information to a PRESENCE service system. The system thereof comprises a presence information monitoring unit, a WLAN network and PRESENCE service system, wherein input of the presence information monitoring unit is connected with WLAN network and the output is connected with PRESENCE service system. The terminal thereof also comprises a presence information monitoring unit, which is connected with PRESENCE service system through WLAN.

    摘要翻译: 一种用于实现WLAN(无线局域网)用户及其系统及其终端的在线信息交互的方法,其中,所述方法包括:设置一个或多于一个存在信息监视单元,由所述在场信息监视单元检测所述存在信息, 并将该呈现信息发送到PRESENCE服务系统。 其系统包括存在信息监控单元,WLAN网络和PRESENCE服务系统,其中存在信息监视单元的输入与WLAN网络连接,并且输出与PRESENCE服务系统连接。 其终端还包括通过WLAN与PRESENCE服务系统连接的存在信息监控单元。