Access management for wireless communication
22 claims: 20 independent, 2 dependent
- 1CLAIMS REIVINDICAÇÕES 1. Communication method, comprising:1. Método para comunicação, compreendendo: receber uma mensagem referente a uma solicitação por um terminal de acesso para acessar um ponto de acesso, em que a mensagem compreende um primeiro identificador associado ao terminal de acesso;receiving a message regarding a request by an access terminal to access an access point, where the message comprises a first identifier associated with the access terminal;- determinar um segundo identificador associado ao terminal de acesso com base no primeiro identificador;e determinar se o terminal de acesso tem 10 permissão para receber um serviço a partir do ponto de acesso com base no segundo identificador e em pelo menos um identificador associado ao ponto de acesso. - determining a second identifier associated with the access terminal based on the first identifier;and determining whether the access terminal is allowed to receive a service from the access point based on the second identifier and at least one identifier associated with the access point.
- 44/16 determinação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso. 4/16 determining whether the access terminal is allowed to receive service from the access point. em que pelo menos um identificador associado ao ponto de acesso é recebido a partir de um nó de rede. wherein at least one identifier associated with the access point is received from a network node. 17. Apparatus according to claim 15, in which the determination of whether the access terminal is allowed to receive service from the access point comprises:17. Aparelho, de acordo com a reivindicação 15, em que a determinação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso compreende: - enviar o segundo identificador e pelo menos um identificador associado ao ponto de acesso para um nó de rede;e - send the second identifier and at least one identifier associated with the access point to a network node;and - receber, a partir do nó de rede, uma indicação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso. - receive, from the network node, an indication of whether the access terminal is allowed to receive service from the access point. 18. Apparatus according to claim 10, in which the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service. 18. Aparelho, de acordo com a reivindicação 10, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 19. Communication apparatus, comprising: 19. Aparelho para comunicação, compreendendo: - a communication controller configured to receive a message referring to a request by an access terminal to access an access point, where the message comprises a first identifier associated with the access terminal;and an access controller configured to determine a second identifier associated with the access terminal based on the first identifier, and for - um controlador de comunicação configurado para receber uma mensagem referente a uma solicitação por um terminal de acesso para acessar um ponto de acesso, em que a mensagem compreende um primeiro identificador associado ao terminal de acesso;e um controlador de acesso configurado para determinar um segundo identificador associado ao terminal de acesso com base no primeiro identificador, e para
- 55/16 determinar se o terminal de acesso tem permissão para receber serviço do ponto de acesso com base no segundo identificador e em pelo menos um identificador associado ao ponto de acesso. 5/16 determine whether the access terminal is allowed to receive service from the access point based on the second identifier and at least one identifier associated with the access point. 20. Apparatus according to claim 19, wherein the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier. 20. Aparelho, de acordo com a reivindicação 19, em que o primeiro identificador compreende um identificador temporário e o segundo identificador compreende um identificador permanente. 21. Apparatus according to claim 19, wherein:21. Aparelho, de acordo com a reivindicação 19, em que: - o segundo identificador identifica pelo menos um grupo fechado de assinantes que o terminal de acesso pode acessar;e - the second identifier identifies at least one closed group of subscribers that the access terminal can access;and - at least one identifier associated with the access point comprises a closed group identifier of subscribers associated with the access point. - pelo menos um identificador associado ao ponto de acesso compreende um identificador de grupo fechado de assinantes associado ao ponto de acesso. 22. Apparatus according to claim 19, wherein: 22. Aparelho, de acordo com a reivindicação 19, em que: - a network node determines whether the access terminal is allowed to receive service from the access point;- um nó de rede realiza a determinação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso;- a mensagem compreende uma solicitação de um ponto de acesso para autenticação do terminal de acesso;e o controlador de comunicação é também configurado para enviar ao ponto de acesso, uma mensagem indicativa da determinação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso. - the message comprises a request from an access point for authentication of the access terminal;and the communication controller is also configured to send to the access point, a message indicating whether the access terminal is allowed to receive service from the access point. 23. Apparatus according to claim 19, wherein the access point determines whether the access terminal is allowed to receive service from the access point. 23. Aparelho, de acordo com a reivindicação 19, em que o ponto de acesso realiza a determinação de se o terminal de acesso tem permissão para receber serviço do ponto de acesso. 24. Computer program product, comprising: 24. Produto de programa de computador, compreendendo:
- 66/16 6/16 - a computer-readable medium comprising codes to make a computer:- um meio legível por computador compreendendo códigos para fazer com que um computador: receba uma mensagem referente a uma solicitação por um terminal de acesso para acessar um ponto de acesso, em que a mensagem compreende um primeiro identificador associado ao terminal de acesso;receive a message regarding a request by an access terminal to access an access point, where the message comprises a first identifier associated with the access terminal;determine a second identifier associated with the access terminal based on the first identifier;and determine if the access terminal is allowed to receive service from the access point based on the second identifier and at least one identifier associated with the access point. determine um segundo identificador associado ao terminal de acesso com base no primeiro identificador;e determine se o terminal de acesso tem permissão para receber serviço a partir do ponto de acesso com base no segundo identificador e em pelo menos um identificador associado ao ponto de acesso. 25. Computer program product according to claim 24, wherein the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier. 25. Produto de programa de computador, de acordo com a reivindicação 24, em que o primeiro identificador compreende um identificador temporário e o segundo identificador compreende um identificador permanente. 26. Communication method, comprising: 26. Método para comunicação, compreendendo: - receber uma solicitação de um ponto de acesso para autenticação de um terminal de acesso;e enviar, ao ponto de acesso, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir dos tem permissão para receber pelo - receiving a request from an access point for authentication from an access terminal;and send to the access point at least one identifier that identifies at least one set of access points from those allowed to receive at least 27. Method, according to which at least one closed group identifier of subscribers. 27. Método, de acordo que pelo menos um identificador de grupo fechado de assinantes. quais o terminal de acesso menos um serviço. which the access terminal minus a service. claim 26, in which it comprises an identifier com a reivindicação 26, em compreende um identificador 28. Method according to claim 26, also comprising determining at least one identifier based on a permanent identifier associated with the access terminal, the method also comprising determining the permanent identifier based on a temporary identifier associated with the access terminal. 28. Método, de acordo com a reivindicação 26, compreendendo também determinar pelo menos um identificador com base em um identificador permanente associado ao terminal de acesso, o método compreendendo também determinar o identificador permanente com base em um identificador temporário associado ao terminal de acesso.
- 77/16 7/16 29. The method of claim 28, wherein determining the permanent identifier comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node. 29. Método, de acordo com a reivindicação 28, em que a determinação do identificador permanente compreende enviar o identificador temporário a um nó de rede e receber o identificador permanente do nó de rede. 30. Method according to claim 26, also comprising receiving at least one identifier from a network node. 30. Método, de acordo com a reivindicação 26, compreendendo também receber pelo menos um identificador a partir de um nó de rede. 31. Method according to claim 26, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of:signaling, data access, registration, and service. 31. Método, de acordo com a reivindicação 26, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 32. Communication apparatus, comprising: 32. Aparelho para comunicação, compreendendo: - mecanismos para receber uma solicitação de um ponto de acesso para autenticação de um terminal de acesso;e - mechanisms for receiving a request from an access point for authentication of an access terminal;and - mecanismos para enviar, ao ponto de acesso, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir do qual o terminal de acesso tem permissão para receber pelo menos um serviço. - mechanisms for sending to the access point at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. 33. Apparatus according to claim 32, wherein at least one identifier comprises a closed subscriber group identifier. 33. Aparelho, de acordo com a reivindicação 32, em que pelo menos um identificador compreende um identificador de grupo fechado de assinantes. 34. Apparatus according to claim 32, also comprising mechanisms for determining at least one identifier based on a permanent identifier associated with the access terminal, and determining the permanent identifier based on a temporary identifier associated with the access terminal. 34. Aparelho, de acordo com a reivindicação 32, compreendendo também mecanismos para determinar pelo menos um identificador com base em um identificador permanente associado ao terminal de acesso, e determinar o identificador permanente com base em um identificador temporário associado ao terminal de acesso. 35. Apparatus according to claim 34, wherein determining the permanent identifier comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node. 35. Aparelho, de acordo com a reivindicação 34, em que a determinação do identificador permanente compreende enviar o identificador temporário a um nó de rede e receber o identificador permanente do nó de rede.
- 88/16 8/16 36. Apparatus according to claim 32, wherein the receiving mechanism is configured to receive at least one identifier from a network node. 36. Aparelho, de acordo com a reivindicação 32, em que o mecanismo para receber é configurado para receber pelo menos um identificador de um nó de rede. 37. Apparatus according to claim 32, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of:signaling, data access, registration, and service. 37. Aparelho, de acordo com a reivindicação 32, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 38. Communication apparatus, comprising: 38. Aparelho para comunicação, compreendendo: - a communication controller configured to receive a request from an access point for authentication of an access terminal;and an access controller configured to send to the access point at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. - um controlador de comunicação configurado para receber uma solicitação a partir de um ponto de acesso para autenticação de um terminal de acesso;e um controlador de acesso configurado para enviar, ao ponto de acesso, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir do qual o terminal de acesso tem permissão para receber pelo menos um serviço. 39. Apparatus according to claim 38, wherein at least one identifier comprises a closed subscriber group identifier. 39. Aparelho, de acordo com a reivindicação 38, em que pelo menos um identificador compreende um identificador de grupo fechado de assinantes. 40. Apparatus according to claim 38, wherein the access controller is also configured to determine at least one identifier based on a permanent identifier associated with the access terminal, and determine the permanent identifier based on a temporary identifier associated with the terminal access. 40. Aparelho, de acordo com a reivindicação 38, em que o controlador de acesso é também configurado para determinar pelo menos um identificador com base em um identificador permanente associado ao terminal de acesso, e determinar o identificador permanente com base em um identificador temporário associado ao terminal de acesso. 41. Apparatus according to claim 38, wherein the communication controller is also configured to receive at least one identifier from a network node. 41. Aparelho, de acordo com a reivindicação 38, em que o controlador de comunicação é também configurado para receber pelo menos um identificador a partir de um nó de rede. 42. Computer program product, comprising: 42. Produto de programa de computador, compreendendo:
- 99/16 9/16 - a computer-readable medium comprising codes to make a computer:- um meio legível por computador compreendendo códigos para fazer com que um computador: receba uma solicitação a partir de um ponto de acesso para autenticação de um terminal de acesso;e receive a request from an access point for authentication from an access terminal;and - envie, ao ponto de acesso, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir dos quais o terminal de acesso tem permissão para receber pelo menos um serviço. - send to the access point at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. 43. Computer program product according to claim 42, wherein at least one identifier comprises a closed subscriber group identifier. 43. Produto de programa de computador, de acordo com a reivindicação 42, em que pelo menos um identificador compreende um identificador de grupo fechado de assinantes. 44. Communication method, comprising: 44. Método para comunicação, compreendendo: - enviar, através de um ponto de acesso, uma solicitação para autenticação de um terminal de acesso;e - send, through an access point, a request for authentication of an access terminal;and - receber, em resposta à solicitação, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir dos quais o terminal de acesso tem permissão para receber pelo menos um serviço. - receive, in response to the request, at least one identifier that identifies at least a set of access points from which the access terminal is allowed to receive at least one service. 45. Method according to claim 44, further comprising determining whether the access terminal is allowed to receive service from the access point based on at least one identifier. 45. Método, de acordo com a reivindicação 44, compreendendo também determinar se o terminal de acesso tem permissão para receber serviço do ponto de acesso com base em pelo menos um identificador. 46. Method according to claim 45, wherein at least one identifier comprises a closed subscriber group identifier. 46. Método, de acordo com a reivindicação 45, em que pelo menos um identificador compreende um identificador de grupo fechado de assinantes. 47. Method according to claim 45, wherein: 47. Método, de acordo com a reivindicação 45, em que: - at least one identifier identifies a closed group of subscribers that the access terminal can access;and - pelo menos um identificador identifica um grupo fechado de assinantes que o terminal de acesso pode acessar;e
- 1010/16 10/16 - a determinação compreende determinar se pelo menos um identificador é compatível a um identificador de grupo fechado de assinantes associado ao ponto de acesso. - the determination comprises determining whether at least one identifier is compatible with a closed subscriber group identifier associated with the access point. 48. Method according to claim 44, wherein the request is sent based on a determination that the access terminal is not listed on a local access point's access list. 48. Método, de acordo com a reivindicação 44, em que a solicitação é enviada com base em uma determinação de que o terminal de acesso não está listado em uma lista de acesso local do ponto de acesso. 49. Method according to claim 44, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of:signaling, data access, registration, and service. 49. Método, de acordo com a reivindicação 44, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 50. Communication apparatus, comprising: 50. Aparelho para comunicação, compreendendo: at least one set of access points from which the access terminal is allowed to receive at least one service. pelo menos um conjunto de pontos de acesso a partir dos quais o terminal de acesso tem permissão para receber pelo menos um serviço. 51. Apparatus according to claim 50, also comprising mechanisms for determining whether the access terminal is allowed to receive service from the access point based on at least one identifier. 51. Aparelho, de acordo com a reivindicação 50, compreendendo também mecanismos para determinar se o terminal de acesso tem permissão para receber serviço do ponto de acesso com base em pelo menos um identificador. 52. Apparatus according to claim 51, wherein at least one identifier comprises a closed subscriber group identifier. 52. Aparelho, de acordo com a reivindicação 51, em que pelo menos um identificador compreende um identificador de grupo fechado de assinantes. 53. Apparatus according to claim 51, wherein: 53. Aparelho, de acordo com a reivindicação 51, em que: - at least one identifier identifies a closed group of subscribers that the access terminal can access;and - pelo menos um identificador identifica um grupo fechado de assinantes que o terminal de acesso pode acessar;e
- 1111/16 11/16 - a determinação compreende determinar se pelo menos um identificador é compatível a um identificador de grupo fechado de assinantes associado ao ponto de acesso. - the determination comprises determining whether at least one identifier is compatible with a closed subscriber group identifier associated with the access point. 54. Apparatus according to claim 50, in which the request is sent based on a determination that the access terminal is not listed in a local access list of the access point. 54. Aparelho, de acordo com a reivindicação 50, em que a solicitação é enviada com base em uma determinação de que o terminal de acesso não está listado em uma lista de acesso local do ponto de acesso. 55. Apparatus according to claim 50, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of:signaling, data access, registration, and service. 55. Aparelho, de acordo com a reivindicação 50, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 56. Communication apparatus, comprising: 56. Aparelho para comunicação, compreendendo: an access controller configured to send, through an access point, a request for authentication from an access terminal;and um controlador de acesso configurado para enviar, através de um ponto de acesso, uma solicitação para autenticação de um terminal de acesso;e - a communication controller configured to receive, in response to the request, at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. - um controlador de comunicação configurado para receber, em resposta à solicitação, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir dos quais o terminal de acesso tem permissão para receber pelo menos um serviço. 57. Apparatus according to claim 56, wherein the access controller is also configured to determine whether the access terminal is allowed to receive service from the access point based on at least one identifier. 57. Aparelho, de acordo com a reivindicação 56, em que o controlador de acesso é configurado também para determinar se o terminal de acesso tem permissão para receber serviço do ponto de acesso com base em pelo menos um identificador. 58. Apparatus according to claim 57, wherein: 58. Aparelho, de acordo com a reivindicação 57, em que: - at least one identifier identifies a closed group of subscribers that the access terminal can access;and - pelo menos um identificador identifica um grupo fechado de assinantes que o terminal de acesso pode acessar;e
- 1212/16 12/16 - a determinação compreende determinar se pelo menos um identificador é compatível a um identificador de grupo fechado de assinantes associado ao ponto de acesso. - the determination comprises determining whether at least one identifier is compatible with a closed subscriber group identifier associated with the access point. 59. Apparatus according to claim 56, wherein the request is sent based on a determination that the access terminal is not listed in a local access list of the access point. 59. Aparelho, de acordo com a reivindicação 56, em que a solicitação é enviada com base em uma determinação de que o terminal de acesso não está listado em uma lista de acesso local do ponto de acesso. 60. Computer program product, comprising:60. Produto de programa de computador, compreendendo: - a computer-readable medium comprising codes to make a computer: - um meio legível por computador compreendendo códigos para fazer com que um computador: - envie, através de um ponto de acesso, uma solicitação para autenticação de um terminal de acesso;e - send, through an access point, a request for authentication of an access terminal;and - receba, em resposta à solicitação, pelo menos um identificador que identifica pelo menos um conjunto de pontos de acesso a partir dos quais o terminal de acesso tem permissão para receber pelo menos um serviço. - receive, in response to the request, at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. 61. Computer program product according to claim 60, wherein the computer-readable medium also comprises codes to make the computer determine whether the access terminal is allowed to receive service from the access point based on at least one identifier. 61. Produto de programa de computador, de acordo com a reivindicação 60, em que o meio legível por computador compreende também códigos para fazer com que o computador determine se o terminal de acesso tem permissão para receber serviço do ponto de acesso com base em pelo menos um identificador. 62. Communication method, comprising: 62. Método para comunicação, compreendendo: - configurar um ponto de acesso com um primeiro identificador de um terminal de acesso;- configure an access point with a first identifier of an access terminal;- obtaining a second access terminal identifier based on the first identifier;- obter um segundo identificador do terminal de acesso com base no primeiro identificador;- receber uma mensagem solicitando acesso pelo terminal de acesso;e - receive a message requesting access through the access terminal;and - determinar, no ponto de acesso, se permite o acesso solicitado com base no segundo identificador. - determine, at the access point, whether the requested access is allowed based on the second identifier.
- 1313/16 13/16 63. Method according to claim 62, wherein the first identifier comprises a network address identity or an integrated service digital network number of the mobile station. 63. Método, de acordo com a reivindicação 62, em que o primeiro identificador compreende uma identidade de endereço de rede ou um número de rede digital de serviços integrados da estação móvel. 5 64. The method of claim 62, wherein the second identifier comprises an electronic serial number or an international mobile subscriber identity. 5 64. Método, de acordo com a reivindicação 62, em que o segundo identificador compreende um número de série eletrônico ou uma identidade internacional de assinante móvel. 65. Method according to claim 62, in which 10 obtain comprises:65. Método, de acordo com a reivindicação 62, em 10 que obter compreende: - enviar o primeiro identificador para um nó de rede;e - send the first identifier to a network node;and - receber o segundo identificador do nó de rede como resultado do envio do primeiro identificador. - receiving the second identifier of the network node as a result of sending the first identifier. 15 66. The method of claim 62, wherein determining comprises: 15 66. Método, de acordo com a reivindicação 62, em que determinar compreende: - enviar o segundo identificador para um nó de rede;e - send the second identifier to a network node;and - receber, como resultado do envio do segundo 20 identificador, uma indicação quanto a se permite o acesso solicitado. - receive, as a result of sending the second identifier, an indication as to whether the requested access is allowed. 67. Method according to claim 62, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group 67. Método, de acordo com a reivindicação 62, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo 25 consisting of: signage, data access, registration, and service. 25 consistindo de: sinalização, acesso a dados, registro, e serviço. 68. Communication apparatus, comprising: 68. Aparelho para comunicação, compreendendo: - mecanismos para configurar um ponto de acesso com um primeiro identificador de um terminal de acesso;- mechanisms for configuring an access point with a first identifier for an access terminal;30 - mechanisms for obtaining a second access terminal identifier based on the first identifier;30 - mecanismos para obter um segundo identificador do terminal de acesso com base no primeiro identificador;mecanismos para receber uma mensagem solicitando acesso pelo terminal de acesso;e mechanisms for receiving a message requesting access through the access terminal;and
- 1414/16 14/16 - mecanismos para determinar, no ponto de acesso, se permite o acesso solicitado com base no segundo identificador. - mechanisms for determining, at the access point, whether the requested access is allowed based on the second identifier. 69. Apparatus according to claim 68, wherein the first identifier comprises a network address identity or an integrated service digital network number of the mobile station. 69. Aparelho, de acordo com a reivindicação 68, em que o primeiro identificador compreende uma identidade de endereço de rede ou um número de rede digital de serviços integrados da estação móvel. 70. Apparatus according to claim 68, wherein the second identifier comprises an electronic serial number or an international mobile subscriber identity. 70. Aparelho, de acordo com a reivindicação 68, em que o segundo identificador compreende um número de série eletrônico ou uma identidade internacional de assinante móvel. 71. Apparatus according to claim 68, wherein obtaining comprises:71. Aparelho, de acordo com a reivindicação 68, em que obter compreende: enviar o primeiro identificador a um nó de rede;e send the first identifier to a network node;and - receber o segundo identificador do nó de rede como resultado do envio do primeiro identificador. - receiving the second identifier of the network node as a result of sending the first identifier. 72. Apparatus according to claim 68, wherein determining comprises: 72. Aparelho, de acordo com a reivindicação 68, em que determinar compreende: - enviar o segundo identificador a um nó de rede;e - send the second identifier to a network node;and - receber, como resultado do envio do segundo identificador, uma indicação quanto a se permite o acesso solicitado. - receive, as a result of sending the second identifier, an indication as to whether the requested access is allowed. 73. Apparatus according to claim 68, wherein the access point is restricted to not provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service. 73. Aparelho, de acordo com a reivindicação 68, em que o ponto de acesso é restrito para não prover, para pelo menos um outro terminal de acesso, pelo menos um do grupo consistindo de: sinalização, acesso a dados, registro, e serviço. 74. Communication apparatus, comprising: 74. Aparelho para comunicação, compreendendo: - a provisioning controller configured to configure an access point with a first identifier for an access terminal;- um controlador de aprovisionamento configurado para configurar um ponto de acesso com um primeiro identificador de um terminal de acesso;111 /// 1Í: 111///1Í: r · r· - '' and . s - '' e . s 71/ 71/ 111711111 /// 17 / d / ee 111711111///17 /d/ee 7iee7: eQ7f? 7 7iee7:eQ7f?7 111 lilll 111 lilll IHI IHI XÇfGi W XÇfGi W 111 111 1111117/1 ///: 71 sSiiweii // / p7ó sllil / lll / llll / :: ii / lie: e: eiili 1111117/1///:71 sSiiweii // /p7ó sllil /lll/llll/:: ii/lie :e:eiili 7:/://::::111171 >·>' 7:/://::::111171 >·>' dlz / silillill;'-e' x 7 dlz/sllilill ;'-e 'x 7 X-G ·£ XG · £ GGG :S:í GGG: S:í GG .$ jiiil7í7ii//idi7ii7j'e7:/7siieii7 i ,x x. x V le'77-elle >r gg GG. $ Jiiil7í7ii // idi7ii7j'e7: / 7siieii7 i, x x. xV le'77-elle> r gg 7 iliüeH iii 11 iSS 7 iliüeH iii 11 íjSS 117 / // ll / l 'd 117/ //ll/l 'd 17' /1117:11 17' /1117:11 7/117/7;7: 7: 71i7Í7Í7x //// jill77717iOll /////;7777;//// ii: dl7 / 71i by gg 7/117/7;7:7:71i7Í7Í7x////jill77717iOll/////;7777;////ii:dl7/71i de gg 71/ :///11: 71/ :///11: / llldll / lill /// /// li / lilll / llil flldl / / 1H17;/llldll/lill/// ///li/lilll/llil flldl/ /1H17;m /;m/;7. sei eisie iifsf / lis 77 7. sei eisie iifsf/lis 77 ® 7® 17 / Iz / sll / z / hei;Ϊ 7® 17 /Iz/sll/z/ei;1117 // 11717/7111: v. 1117//11717/7111 :v. i. ·:. '· .V i. ·:.'· .v 1 / iiiiiieilii le 1/ iiiiiieilii le 11111711177 11111711177 1111111717/117 lislo 1111111717/117 lislo 1:1::///:1171: 1:1::///:1171: 11111111 11111111 1:7111/7:1/1711177: 1:7111/7:1/1711177: 16/16 16/16 - determine, at the access point, if the requested access is allowed based on the second identifier. - determine, no ponto de acesso, se permite o acesso solicitado com base no segundo identificador. 79. Computer program product according to claim 78, wherein obtaining comprises: 79. Produto de programa de computador, de acordo com a reivindicação 78, em que obter compreende: 5 - send the first identifier to a network node;and 5 - enviar o primeiro identificador a um nó de rede;e - receber o segundo identificador a partir do nó de rede como resultado do envio do primeiro identificador. - receiving the second identifier from the network node as a result of sending the first identifier. 1/22 1/22 Ο CL Ο CL FIGURA 1 FIGURE 1 2/22 2/22 FIGURA 2 FIGURE 2 3/22 3/22 FIGURA 3 <\1 «ο FIGURE 3 <\ 1 «ο LLI Ο LLI Ο 4/22 4/22 FIGURA 4 FIGURE 4 5/22 5/22 FIGURA 5 FIGURE 5 6/22 6/22 FIGURA 6 FIGURE 6 7/22 7/22 FIGURA 7 FIGURE 7 8/22 8/22 FIGURA 8 FIGURE 8 9/22 9/22 FIGURA 9 FIGURE 9 10/22 10/22 FIGURA 10 FIGURE 10 11/22 11/22 12/22 12/22 FIGURA 12 FIGURE 12 13/22 13/22 FIGURA 13 FIGURE 13 14/22 14/22 FIGURA 14 FIGURE 14
- 1515/22 15/22 1520Β 1520Β ΙΟ g ΙΟ g ω ω
- 1616/22 16/22 1606Α <0 1606Α <0 FIGURA 16 FIGURE 16
- 1717/22 17/22 1700 1700
- 1818/22 18/22 1800 1800 FIGURA 18 FIGURE 18 1900 1900 I MECANISMOS DE | I MECHANISMS OF | I DETERMINATION OF I I DETERMINAÇÃO DE I I IDENTIFICADORI 1 1906I I IDENTIFIER 1 1906I I _____ ΓΖΊ _____ J I_____ΓΖΊ_____ J FIGURA 19 FIGURE 19
- 1919/22 19/22 2000 2000 I MECANISMOS DE I MECHANISMS OF I DETERMINATION OF I 1 ALLOWED SERVICE 'I I DETERMINAÇÃO DE I 1 SERVIÇO PERMITIDO ' I 2006 1 2006 1 FIGURA 20 FIGURE 20 2100 2100 FIGURA 21 FIGURE 21
- 2020/22 20/22 2200 | _________ _ ______J 2200 |_________ _ ______J FIGURA 22 FIGURE 22 2300 2300 FIGURA 23 FIGURE 23 2400 2400 FIGURA 24 FIGURE 24
- 2121/22 21/22 2500 2500 FIGURA 25 FIGURE 25 2600 1 MECANISMOS DE I 1 DEFINIÇÃOI 2600 1 MECHANISMS OF I 1 DEFINITION J 2610I J 2610I L L FIGURA 26 FIGURE 26
- 2222/22 22/22 2700 2700 FIGURA 27 FIGURE 27 2800 2800 FIGURA 28 FIGURE 28
Independent claims20
430 paragraphs in 9 sections, as filed
(54) Title: ACCESS MANAGEMENT FOR WIRELESS COMMUNICATION (51) Int. Cl .: H04L 29/06; H04W 12/08 (30) Unionist Priority: 02/01/2008 US 61 / 025,686, 02/01/2008 US 61/025, 68606/10/2008 US 12 / 246,383, 02/01/2008 US 61/025, 68606/10/2008 US 12/246, 38308/10/2007 US 60 / 978,363, 02/01/2008 US 61 / 025,68606 / 10/2008 US 12/246, 38308/10/2007 US 60/978, 36313/06/2008 US 61 / 061,537 (73) Holder (s): QUALCOMM INCORPORATED (72) Inventor (s): RAJARSHI GUPTA; ANAND PALANIGOUNDER; FATIH ULUPINAR; GAVIN B. HORN; PARAG A. AGASHE; JEN MEI CHEN; MANOJ M. DESHPANDE; SRINIVASAN BALASUBRAMANIAN; SANJIV NANDA; OSOK SONG (74) Attorney (s): MONTAURY PIMENTA, MACHADO & LIOCE (86) International Application: PCT US2008079112 of 10/07/2008 (87) International Publication: WO 2009/048887 of 16/04/2009
<img file="BRPI0818609A2_D0001.tif" />
WIRELESS COMMUNICATION ACCESS MANAGEMENT
PRIORITY CLAIMS UNDER TITLE 35 OF THE CODE OF
UNITED STATES § 119
The present application claims the benefit and priority to the Provisional Patent Application assigned to the same applicant No. US 60 / 978,363, filed on October 8, 2007, and Attorney's Summary assigned No. 080042P1; Provisional Patent Application No. US 61 / 025,686, filed on February 1, 2008, and Attorney's Record assigned No. 080745P1; and Provisional Patent Application No. US 61 / 061,537, filed on June 13, 2008, and Attorney Summary assigned No. 08181 IP1, the description of which is incorporated herein by reference.
FUNDAMENTALS
Technical Field
The present application relates, in general, to wireless communications and, more particularly, but not exclusively, refers to the improvement of communications performance.
Introduction
Wireless communication systems are widely deployed to provide various types of communication (for example, voice, data, multimedia services, etc.) to multiple users. As the demand for speed services grows rapidly, there is an efficient and improved communication challenge.
high multimedia data in implementing robust systems with performance
In order to supplement base stations of the conventional mobile telephone network, base stations with small coverage (for example,
2/90 installed in a user's home). In some ways, these base stations can provide mobile units with more robust internal wireless coverage. These low coverage base stations are generically known as access point base stations, Home NodeBs, or femto cells. Typically, these low coverage base stations are connected to the Internet and the mobile operator's network via a DSL router or cable modem.
In some scenarios, base stations with low coverage can be deployed on an ad-hoc basis. Consequently, there may be problems associated with accessing these base stations. For example, access terminals may need to be configured to access their associated base stations. In addition, it may be desirable to prevent unauthorized access terminals from accessing certain base stations. Therefore, there is a need for improved access management for networks without
SUMMARY sampling document
The following is a summary of the description. One must understand the term aspects may refer to one of those contained in the or more aspects of any present aspects of the description.
The description refers, in some aspect, to the provision of communication nodes proportion of access management for wireless communication.
For example, identifiers can be assigned sets of nodes where identifiers can be used to control access to restricted access points that provide certain services only for defined sets of access terminals. In this document, a restricted access point can, for example, provide
3/90 certain services (for example, different billing, additional services, different quality of service) for the access terminals of one or more preferred users, but not for other users.
In some ways, provisioning a node may involve providing a unique identifier for a set of one or more nodes. For example, a unique identifier can be assigned to one or more restricted access points. Similarly, a unique identifier can be assigned to a set of access terminals that have been authorized to receive from one or more restricted access points. In some respects, a temporary identifier can be assigned to an access terminal through which access to the node can involve mapping the temporary identifier to a permanent identifier for the access terminal.
Through the use of these identifiers, a desired level of access control can be achieved although the nodes can be provisioned in an ad-hoc manner. In some ways, access control may be provided by a restricted access point. In some ways, access control can be provided by a network node. In some respects, access control can be provided through the cooperation of a restricted access point and a network node.
The description refers, in some aspects, to the provisioning of a node through a preferred visitor list. In some respects, a node can be provisioned through a standard preferred guest list that the node can use to obtain another preferred guest list for the purpose of accessing restricted access points. In some ways, a node can be
4/90 provided with a preferred visitor list through the use of an incoming load signal.
BRIEF DESCRIPTION OF THE DRAWINGS
These and other sample aspects of the description will be described in the detailed description and in the attached claims, and in the attached drawings, as follows:
Figure 1 is a simplified block diagram of various sampling aspects of a communication system;
Figure 2 is a flow chart of various sampling aspects of operations that can be used to provision network nodes and provide access control;
Figure 3 is a simplified diagram of various sample network node components;
<td>THE</td><td>Figure 4 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
<td>provision</td><td>a point of</td><td>access;</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>Figure 5 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
<td>provision</td><td>a terminal </td><td>access;</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>Figure 6 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
<td>provision</td><td>a terminal</td><td>access;</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>Figure 7 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
<td colspan="2">provide control of</td><td>access;</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>Figure 8 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
<td colspan="2">provide control of</td><td>access;</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>Figure 9 is</td><td>a flow chart</td><td>in</td><td>several</td><td colspan="2">aspects</td>
<td>samples</td><td>operations</td><td colspan="2">that can be</td><td colspan="2">maids</td><td>for</td>
provide access control;
5/90
Figure 10 is a flow chart of several aspects
<td>sample operations</td><td>that can</td><td>to be</td><td>maids</td><td>for</td>
<td>provide control of</td><td>access;</td><td></td><td></td><td></td>
<td>Figure 11 is</td><td colspan="2">a flow chart of</td><td colspan="2">various aspects</td>
<td>sample operations</td><td>that can</td><td>to be</td><td>maids</td><td>for</td>
<td>provide control of</td><td>access;</td><td></td><td></td><td></td>
<td>Figure 12 is</td><td colspan="2">a flow chart of</td><td colspan="2">various aspects</td>
<td>sample operations</td><td>that can</td><td>to be</td><td>maids</td><td>for</td>
<td>provision a terminal <</td><td>access;</td><td></td><td></td><td></td>
<td>Figure 13 is</td><td colspan="2">a flow chart of</td><td colspan="2">various aspects</td>
<td>sample operations</td><td>that can</td><td>to be</td><td>maids</td><td>for</td>
<td>provide control of</td><td>access;</td><td></td><td></td><td></td>
Figure 14 is a simplified diagram of a wireless communication system;
Figure 15 is a simplified diagram of a wireless communication system that includes femto nodes;
Figure 16 is a simplified diagram that illustrates wireless coverage areas;
Figure 17 is a simplified block diagram of various sampling aspects of communication components; and
Figures 18 to 28 are simplified block diagrams of various sampling aspects of devices configured to provide provisioning and / or access management as taught in this document.
According to common practice, several features illustrated in the drawings could not be drawn to scale. Consequently, the dimensions of the various resources can be arbitrarily expanded or reduced for the sake of clarity. In addition, some of the designs can be simplified for the sake of clarity. Therefore, the drawings may not describe all
6/90 components of a given device (eg device) or method.
Finally, similar numerical references can be used to denote similar features throughout the specification and figures.
DETAILED DESCRIPTION
Various aspects of the description are described below. It should be apparent that the teachings contained in this document can be incorporated in a wide variety of forms and that any specific structure, specific function, or both described in this document are merely representative. Based on the teachings contained in this document, an individual skilled in the art should assess that one aspect described herein can be independently implemented from any other aspects and that two or more of these aspects can be combined in various ways. For example, an apparatus can be implemented or a method can be practiced using any number of aspects presented in this document. In addition, this device can be implemented or such a method can be practiced using another structure, functionality, or structure and functionality in addition to one or more aspects presented in this document. In addition, an aspect may comprise at least one element of a claim.
Figure 1 illustrates several nodes in a sample communication system 100 (for example, a portion of a communication network). For purposes of illustration, various aspects of the description will be described in the context of one or more network nodes, access points, and access terminals that communicate with each other. It should be appreciated, however, that the lessons contained in this document may be applicable to other types of devices or other devices
7/90 similarly named using other terminology.
Access points
102 and 104 in system 100 provide one or more services (for example, network connectivity) to one or more network terminals (for example, access terminal 106 and / or 108) that can be installed or that can travel over a associated geographical area. In addition, access points 102 and 104 can communicate with one or more network nodes 110 for the purpose of facilitating extended area network connectivity. This network node can take many forms. For example, a network node can comprise a mobility manager or some other suitable network entity (for example, a core network entity).
Access points 102 and 104 can be restricted in some ways, so each access point provides certain services to certain access terminals (for example, access terminals 106 and 108), but not to other access terminals ( for example, a macro access terminal, not shown). For example, access points 102 and 104 may be restricted from providing other access terminals with at least one of them: registration, signaling, voice call, data access, or any other cellular service. Restricted access points can be deployed on an ad-hoc basis.
For example, a particular owner can install and configure their own restricted access point.
Figure 2 provides an overview of various operations that can be performed in order to facilitate the deployment of restricted access points and access terminals that are authorized to use these access points. In some ways, these operations can be employed to allow a restricted access node
8/90 determine your identity, determine the identity of access terminals that are allowed access (for example, connection to) a restricted access point, and confirm the identity of an access terminal (for example, an access terminal that is having access to the restricted access point). In some aspects, these operations can be employed in order to allow an access terminal to determine its identity, determine the identity of a restricted access point that the access terminal is allowed to access, translate the temporary identity of the access terminal into identity permanent access, and confirm the identity of an access point (for example, a restricted access point that the access terminal is trying to access).
<td></td><td>Per</td><td>reasons</td><td>in</td><td>convenience,</td><td>operations</td><td>gives</td>
<td>Figure 2</td><td>(or</td><td colspan="2">any</td><td>other operations</td><td>discussed</td><td>or</td>
<td>taught</td><td>at the</td><td>gift</td><td colspan="2">document) can be</td><td>described,</td><td>like</td>
being performed by specific components (for example, system components 100 and / or components of a system 300 as shown in Figure 3). It must be appreciated, however, that these operations can be performed by other types of components and can be performed using a different number of components. It should also be considered that one or more of the operations described here may not be used in a given implementation.
Ά Figure 3 illustrates various sample components that can be incorporated into network node 110 (for example, a mobility manager, a mobile switchboard, or a service GPRS support node), access point 102, and the terminal access 106 in accordance with the teachings contained in this document. It should be assessed that the components illustrated for a given
9/90 nodes can also be incorporated into other nodes in a communication system. For example, access terminal 108 can include components similar to those described for access terminal 106 and access point 104 can include components similar to those described for access point 102.
network node 110, access point 102, and access terminal 106 include transceivers 302, 304, and 306, respectively, intended for communication with each other and with other nodes. Transceiver 302 includes a transmitter 308 that serves to send signals (e.g., messages) and a receiver 310 that serves to receive signals. Transceiver 304 includes a transmitter 312 that serves to transmit signals and a receiver 314 that serves to receive signals. Transceiver 306 includes a transmitter 316 that serves to transmit signals and a receiver 318 that serves to receive signals.
network node 110, access point 102, and access terminal 106 also include several other components that can be used in conjunction with the access provisioning and management nodes as taught in this document. For example, network node 110, access point 102, and access terminal 106 may include communication controllers 320, 322, and 324, respectively, which serve to manage communications with other nodes (for example, sending and receiving messages / referrals) and provide other related functionality as taught in this document. 0 network node 110, access point 102, and access terminal 106 can include provisioning controllers 326, 328, and 330, respectively, which serve to provision a node and provide other related functionality as taught herein. Network node 110, the point
Access 10/90 102, and access terminal 106 may include access controllers 332, 334, and 336, respectively, which serve to provide access management and provide other related functionality as taught herein. For purposes of illustration, all nodes are described in Figure 3 as having functionality related to provisioning and access control. In some implementations, however, one or more of these components may not be employed on a given node. The following discussion describes several different 'schemes (for example, in conjunction with different figures) that serve to provision network nodes and provide access control. For convenience, in these different schemes, network node 110, access point 102, and access terminal 106 can be termed as having different functionalities and can be termed as being representative of different types of nodes (for example, in different implementations the network node 110 can represent an SRNC, or an MME, or an AAA, etc.). It should be noted, however, that in a given implementation the network node 110, the access point 102, and the access terminal 106 can be configured in a specific way.
Referring again to Figure 2, as represented by block 202, each access terminal (for example, access terminal 106) in a system can be provisioned to allow communication with one or more access points (for example, access point 102). In the example in Figure 3, these operations can be performed, for example, through the operation of the provisioning controllers 326 and 330.
In some respects, an operator may assign a unique identifier to access terminal 106. In
11/90 some implementations, this identifier comprises a network access identifier (NAI) or a digital network number for integrated mobile station (MS) services
ISDN). Alternatively, the subscriber's identity, such as International Mobile Subscriber Identity (IMSI) can also be derived from a subscriber identity module, such as SIM, USIM, or
VSIM present at the access terminal.
In some cases, it is guaranteed that this identifier is already a domain of the operator (for example, the entire network provided by a cellular operator). In some implementations, such an identifier can be part of the session information for access terminal 106. For example, the identifier can be sent to network node 110 (for example, a session reference network controller,
SRNC) by the access terminal 106 when the access terminal 106 creates a session or the identifier can be promoted to the network node 110 from an authentication entity, accounting authorization (AAA) once a session is created.
some implementations, the
In a user in such a way that the user can, for example, configure his / her restricted access point (s) in order to provide an access service to one or more access terminals. In some implementations, an access terminal can be assigned a temporary identifier. For example, the network can assign permanent and temporary identifiers to access terminal 106 and maintain those identifiers on the network.
In addition, the network can send the way that the temporary identifier to the access terminal 106 of such access terminal
106 can use such that it accesses an access point.
access terminal 106 can also be provisioned with the identity of each access point (for example,
12/90 (access point 102) that access terminal 106 is allowed to access. As described in more detail later, this may involve, for example, sending access point identifiers to access terminal 106 (e.g., a push model) and / or allowing access terminal 106 to select access points to be accessed by access terminal 106 (for example, a pull model). 0 access terminal 106 can therefore maintain a list of authorized access points (for example, an exception list or a zone list of preferred users) that access terminal 106 can reference as it moves through various areas wireless coverage.
In some implementations, an access terminal 106 user may display the prompt to determine whether he or she wants to enable access terminal 106 to access an access point. In some implementations, access terminal 106 can automatically enable access to an access point. In some implementations, access terminal 106 can determine, based on configuration information at access terminal 106, whether to automatically enable access or require a user prompt to enable access. In some implementations, a user may decide to access or decide not to access one or more access terminals. In this case, a list of the allowed and / or rejected access terminal (s) can be maintained at the access terminal 106. In this way, access terminal 106 can prevent (e.g., automatically prevent) an attempt to access an access point in the list.
As represented by block 204, each restricted access point (for example, access point 102) in a system can be provisioned to allow
13/90 communication with one or more access terminals (for example, access terminal 106). In this example in Figure
3, these operations can be carried out, for example, through the operation of the provisioning controllers
326 and 328.
For example, you can assign a unique identifier to access point 102 or a set of access points (for example, access points 102 and 104). These unique identifiers are different from a unique device identifier that can be assigned to identify individual access terminals in a system. As described in more detail below, such an identifier may comprise, for example, a special type of network identifier (NID) or subnet identifier or an identifier assigned to a group of access terminals that have the same association properties. restricted (for example, a CSG). In some cases, the network may independently assign a unique identifier. In some cases, one or more access points may request an identifier (for example, by determining a proposed identifier and sending it to the network). In such cases, the network can determine whether the requested identifier is already in use by one or more other access points. If the requested identifier is already in use, the network can select another identifier (for example, a similar identifier) that is not in use by any other access point and send this identifier to the requested access point (s) ( s).
access point 102 can also be provisioned with one or more identifiers associated with each access terminal (for example, access terminal 106) that has allowed access to access point 102. As described in more detail below, this
14/90 may involve, for example, storing access terminal identifiers in a database managed by a network and / or storing access terminal identifiers in a local access list at access point 102.
In some implementations, the access control list for a given restricted access point can be managed at this restricted access point. For example, as discussed further according to Figure 13, a user can configure his access point using an access terminal (for example, a cell phone) or using a password protected web page hosted at the access point. Restricted access.
Alternatively, in some implementations, an access control list for each restricted access point on a network is managed on the network (for example, a core network). For example, as discussed further according to Figure 4, an access control list can be managed on a web page hosted by the network operator. Managing the access control list on the network can provide one or more advantages in some contexts. In some ways, this approach may allow for greater policy flexibility. For example, the operator can limit access to restricted access points if desired and the operator can check records (for example, for access terminals) on the same billing plan. In addition, the network can be more reliable than individual access points. Therefore, you can improve the reliability of the access control list. Likewise, since the access control list may not be sent to the restricted access point, there may be no need to provide a direct interface to the restricted access points (for example, application software, USB ports, and so on. against).
15/90
In addition, through the use of centralized access control lists, it may be easier to manage multiple restricted access points that belong to a common employer.
Once a restricted access point is provisioned, it can notify you of its assigned identifier over the air. For example, access point 102 may broadcast its identifier as part of its sector parameters, or in some other suitable way.
As represented by block 206, once an access terminal is provisioned, the access terminal can monitor signals (for example, pilot / signaling signals) with broadcast by nearby access points. As discussed in detail later, if access terminal 106 identifies signals from access point 102 (for example, in a scenario where access terminal 106 is allowed to access access point 102), the access terminal 106 can request access to this access point 102. The identification of an access point accessible by the access terminal 106 may involve, for example, comparing an identifier associated with the access point 102 with a trusted list 338 of authorized access points (for example, the list of exceptions) maintained by the terminal 106. In the example in Figure 3, these and other operations related to access can be performed, for example, through the operation of the access controller 336.
As represented by block 208, access point 102 and / or one or more network nodes (for example, network node 110) can determine whether to allow access terminal 106 to access access point 102. This control operation access may involve, for example, confirming the identity of access terminal 106 and comparing a
16/90 access terminal identifier 106 with a list of authorized access terminals maintained by access point 102 (for example, a local access list 340) and / or maintained by network node 110 (for example, a list of network database access 342). In the example of Figure 3, these and other operations related to access can be performed, for example, through the operation of the access controller 334 and / or the access controller 332.
With the previous overview in mind, additional details regarding provisioning and access control will be described with reference to Figures 4 to 13. Based on the teachings in this document, one or more operations described in conjunction with a given figure can be used according to the operations described in another figure. For convenience, these operations will be described with reference to the components in Figure 1. It must be appreciated that these operations can also be applicable to other nodes in a network.
Referring initially to Figure 4, there are several operations related to the provisioning of a restricted access point.
As represented by block 402, network node 110 assigns an identifier (for example, a unique identifier) to the restricted access point. In some cases, the identifier is guaranteed to be unique in an operator's domain (for example, the entire network is provided by a cellular operator). For example, a network entity can maintain an identifier database that is used to guarantee the uniqueness of any assigned identifier.
17/90 identifier can take several forms.
In some implementations, this identifier comprises a network identifier (for example, a femto network identifier,
FNID).
In some implementations, identifier may comprise a closed subscriber group identifier (CSG
ID). As mentioned earlier, a set of restricted access points (for example, associated with the same administrative domain) can share a common identifier (for example, a CSG ID). In some implementations, a set of FNIDs can be associated with a common CSG. For example, a CSG can be assigned to a company and different FNIDs can be assigned to different access points across the company (for example, in different buildings). In some implementations, additional identifiers can also be used that can be readable by users (for example, text-based).
unique identifier can be provisioned in several ways. For example, in some cases, an identifier is chosen and configured when a user activates a restricted access point. In this document, the identifier can be configured by an operator, at the point of purchase, or in some other way.
As represented by block 404, a list of access terminals that are allowed access to access point 102 (and, if applicable at any other access points in a defined set of access points) is generated. This access list can include, for example, access terminal identifiers as discussed in this document. Therefore, this identifier can identify an individual access terminal (for example, a NAI or IMSI or MS ISDN) or a set of one or more access terminals (for example, one or more
18/90 access associated with a given CSG). In addition, the access list can specify permissions (for example, conditions for access) associated with a particular access terminal.
In some implementations, the access list can be generated through the use of a 344 website (for example, accessible by a computer, a telephone, or some other suitable device). In this way, the owner or user of access point 102 can access the website for the purpose of adding, deleting, or editing access terminal entries in the access list. For example, in order to enable a home or visitor access terminal (for example, access terminal 108) to access access point 102, a user can add a permanent NAI from the access terminal to the access list via a web page. In this document, several naming conventions (for example, user-readable identifiers, such as Joe's phone and the like) can be associated with a unique access terminal identifier (for example, NAI or MS ISDN) and one or more of that identifiers can be displayed on the web page after they are added to the web page.
As represented by block 406, in some implementations, the access list is hosted by the network operator. For example, an operator can maintain a server for the access list website. In this way, the operator can approve any changes to the access list (for example, entries denied for access terminals from other operators).
As represented by block 408, the access list information can then be sent to each access point or to other network nodes that perform
19/90 access control associated with a given access list. For example, the server can push the access list information to the access point 102 or the access point 102 can pull the access list information from the server. As an example of a push model, the access list can be sent from the operator's website to a configuration server, which then sends the access list to access point 102. As another example, the access list can be sent from the operator's website via the Internet to the application software on access point 102. As an example of a pull model, access point 102 can query the server configuration to receive the latest version of the access list. This inquiry can occur, for example, whenever the access point 102 connects to the operator network (for example, it configures a new IPSec connection). Therefore, in the event that access point 102 goes offline for a period of time, it can be guaranteed that access point 102 receives the latest version of the access list when it reconnects to the network.
By maintaining the access list in a location other than access point 102, access point 102 is released from the burden of maintaining the access list. This approach can provide improved access list management as the access list can be updated even when access point 102 is offline. In addition, such an approach can simplify the management of an access list that is associated with more than one access point. For example, a single access list can be defined for a set of access points (for example, associated with a given CSG). In this case, access points can acquire the access list from a single source instead of needing to
20/90 coordinate with another source to manage (for example, update) the access list across all access points.
Use of a centralized access list can also facilitate the use of temporary identifiers. For example, access point 102 can use a given identifier for the duration that a given IPSec tunnel is established. When a new IPSec tunnel is established, the access list can be configured with a different set of identifiers. In this document, the new set of identifiers may or may not identify the same access terminals as the previous version of the access list.
As represented by block 410, access point 102 broadcasts its identifier (for example, FNID or CSG ID) over the air. In this way, any access terminals that enter the coverage area of access point 102 can identify access point 102 and determine whether they are allowed access to access point 102.
Referring now to Figures 5 and 6, various operations are described that can be used to provision an access terminal. In particular, these figures describe techniques for provisioning an access terminal with the identity of one or more restricted access points that the access terminal is allowed access to.
Figure 5 illustrates various operations that can be performed to push information from the access list to an access terminal (ie, a push model). In this example, it is assumed that a unique identifier has been assigned to the access terminal (for example, as discussed earlier).
21/90
As represented by block 502, at some point in time, an access terminal can be designated as having allowed access to one or more access points. For example, the owner of one or more access points can add a visiting access terminal to the access list associated with the access point (s), as previously discussed according to Figure 4.
As represented by block 504, the operator sends a message to the access terminal indicating that the access terminal has no access allowed to an access point or set of access points. This message may include an identifier associated with the access point (s) (for example, an FNID or CSG ID) as well as any limitations that may apply (for example, time limits for visitor access). This message can be sent, for example, when an access terminal identifier 108 is added to an access list associated with access point 102. This message can also be sent in several ways. For example, the network can send an SMS message, an application protocol message (for example, an open mobile alliance device management), a radio link message, a page, or some other type of message to the access terminal to conducting access point information (for example, an inquiry that asks access terminal 108 if it wants to access access point 102).
As represented by block 506, access terminal 108 can then inform the user of access terminal 108 that he is qualified to access the access point (s). For example, access terminal 108 may display an indication of the identity of the access point (s), or provide some other form of indication. This indication may include, for example, the
22/90 identifier assigned to the access point (s) or an alternative name (for example, user-readable identifiers, such as Sue's house or similar) that has been associated with the identifier.
As represented by block 508, the user can then determine whether to enable (for example, using an input device at the access terminal 108) the requested access to the access point (s). Based on the user's decision, access terminal 108 can update a list (for example, a list of exceptions), which it maintains, of access points that are allowed access (for example, enabled). As discussed later, access terminal 108 can use this list to determine which access points it can access as access terminal 108 moves across the network. In the present document, the user may not need to provide any additional access authorization in case the access terminal enters the coverage area of an access point in the list, since the access terminal can automatically remember this access point. In some implementations, the list of exceptions can be updated only after an approval has been received from the network operator.
In some implementations, access terminal 108 can send a message to the operator indicating the user's decision. In this way, the operator can decide to modify the access list for the access point (s), if desired.
By allowing an access terminal user to accept or reject access to an access point, you can prevent an access point user from unilaterally enabling an access terminal (for example, a neighbor's access terminal ) to access this
23/90 access point. Therefore, the user of an access terminal can be sure that their information will not be sent to an unauthorized access point.
In addition, this push model does not require the access terminal to be in the vicinity of an access point to add an access point to this list of exceptions. In addition, since the access terminal can receive the push message only when it has been added to an access list, the possibility of a user selecting the wrong access point (for example, an access point) can be reduced. access that the access terminal does not have allowed access).
Figure 6 illustrates various operations that can be performed to pull information from the access list to an access terminal (ie, a pull model). Again, it is assumed that a unique identifier has been assigned to the access terminal.
As represented by block 602, at some point in time, a user of an access terminal (e.g., access terminal 108) initiates a scan for nearby access points. Accordingly, access terminal 108 may include an input device that the user can control (for example, a menu option) to make receiver 318 monitor one or more channels for pilot signals or other signals from a access point.
As represented by block 604, access terminal 108 informs the user of any access points that have been detected as a result of the scan. For example, access terminal 108 may display an indication of the identity of the detected access point (s), or provide some other form of indication. Again, this indication may comprise a
24/90 identifier assigned to the access point (s), an alternative name, or some other appropriate information.
As represented by block 606, the user can decide to enable access to one or more detected access points. For example, the user can control an input device at access terminal 108 to select one or more access points that are displayed by access terminal 108.
The access terminal then attempts to access the selected access point, if desired. As discussed later, in case the user selects the wrong access point (for example, an access point where the access terminal is not allowed access), the access point can deny access. The access point can then relay that information to the access terminal (for example, in order to prevent this from happening again in the future).
As represented by block 608, in some implementations, access terminal 108 can update a list, which it maintains, of access points that are allowed access (for example, an exception list) based on the user's decision. In this way, access terminal 108 can remember a selected access point, such that user input is not required for future visits to this access point (for example, access terminal 108 can connect to the point access without the user having to start another scan).
As represented by block 610, in some implementations, a pull model can be employed to enable access terminal 108 to access an access point on a conditional basis (for example, pay per use use). For example, several access points (for example, owned by a common owner, such as a
25/90 hotel or other company) can report the same unique identifier (for example, FNID or CSG ID). When the access terminal is close to one of these access points and the user of access terminal 108 initiates a scan, the user can decide to connect to one of these access points (for example, access point 102). When access terminal 108 attempts to connect to access point 102, access point 102 may not check its local access control list to see if access terminal 108 is authorized for access, however, instead , allows access terminal 108 to make an initial connection. This initial connection may, however, involve redirecting the user to a web page through which access terminal 108 can only receive services from access point 102 if certain conditions are met (for example, if payment performed). Through the use of this model, any access terminal (as opposed to certain designated access terminals) can access the associated set of access points.
As mentioned earlier, an access point and / or a network node can control whether a given access terminal is allowed access to the access point. In some implementations, access control for a given restricted access point can be managed at this restricted access point. In some implementations, access control for a given restricted access point can be managed at this restricted access point with the aid of a centralized access control manager (for example, implemented on a network node). Figures 7 to 11 illustrate several techniques that can be used to control this access.
26/90
Referring, initially, to Figure várias, several operations are described referring to a scenario where an access point controls access to itself. In some respects, access granted by access point 5 may be conditional. For example, if the access point determines that access should not be granted for a given service, the requested access can be unilaterally denied. In determining a particular request, however, if the access point to which access should be granted service, the network access point must confirm whether the to be able to send access should be allowed.
In some implementations, an access point can control (for example, unilaterally) access to a local service. For example, an access terminal may attempt to gain access to a service provided on a local network associated with the access point. These services may include, for example, access to a local server (for example, to access audio, video, data or other content), access to a printer, and so on.
As represented by block 702 of Figure 7, at some point in time, an access terminal (for example, access terminal 108) initiates the establishment of a communication with a restricted access point (for example, access point 102) . According to this operation, access terminal 108 can attempt to open a session (or route) to access point 102. In addition, the associated session information can be stored on the network (e.g., network node 110). In order to facilitate the access point 102 to confirm the identity of the access terminal 108, in some cases, an identifier of the access terminal 108 may be part of the session information (for example, included in the context information for the Score
27/90 access). This identifier may comprise, for example, a permanent identifier (for example, NAI) as discussed in this document.
As represented by block 704, access point 102 can obtain information to confirm the identity of access terminal 108. For example, in some cases, access point 102 may receive an identifier (for example, a temporary identifier) or other appropriate information directly from access terminal 108 (for example, over the air). In some cases, the access point 102 the temporary terminal session information example, scenario, example, mentioned above.
access (by or permanent) from the SRNC) can be avoided to the permanent NAI)
In cases where you can retrieve including the example identifier, an identifier from the network network (by. Advantageously, in this last transmission of the identifier (by air.
if a temporary identifier is used (for example, a temporary NAI), access point 102 can cooperate with the network in order to guarantee the validity of the identifier. For example, in some implementations, access point 102 sends the temporary identifier to an AAA entity that authenticates the identifier. In some implementations, the access point
102 sends the temporary identifier to the network and receives the associated permanent identifier in response. In this case, the access point 102 can use the permanent identifier to authenticate the access terminal 108.
As represented by block 706, access point 102 compares the information from the access terminal (for example, a temporary or permanent identifier) with the information in its local access list (for example, represented by the local access list 340 in the
28/90
Figure 3). As discussed earlier, the local access list can be configured to include a unique identifier associated with access terminal 108 (for example, NAI, CSG ID, etc.).
As represented by block 708, access point 102 can then allow or reject requested access based on the comparison in block 706. In this document, access point 102 can send a rejection message to access terminal 108 and / or access point 102 can redirect access terminal 108 to a different access point (for example, by sending a redirect message that identifies the local macro access point).
As described later, in some implementations, access terminal 102 can cooperate with the network in order to authenticate access terminal 108. For example, in case the terminal is on the local access list, it sends a request to an access identifier does not provide restricted
<td colspan="4">., access point 102 can</td>
<td>at the</td><td>network,</td><td>such</td><td>as a</td>
<td colspan="2">authentication,</td><td>etc,</td><td>. , To the</td>
<td>(per</td><td>example,</td><td>one</td><td>AAA femto</td>
AAA entity that access points implemented, for example, as a stand-alone entity or incorporating a corresponding functionality in a traditional network AAA entity). In the present document, the network node can maintain an access control list for access point 102 that the network node uses to authenticate access terminal 108 (for example, in a manner similar to that described above). In addition, if applicable, the network node can cooperate with another network node (for example, an AAA entity for access terminal 108) in order to derive a permanent identifier associated with access terminal 108 from the identifier that was sent to access point 102 by the
V
29/90 access terminal 108.
The access point
102 it can then allow requested access based on a response it receives from the indicative network node if access terminal 108 is authorized to access access point 102. According to the teachings contained in this document, access control functions can be performed at the access point or at another network entity, such as a communication port, mobile switching center (MSC), GPRS support node of service (SGSN), packet data service node (PDSN), or MME in various implementations.
Referring now to Figure 8, various operations are described for a scenario where the network sends a list of access terminal identifiers (for example, the access point's access list) to an access point, such that the access point can determine whether to grant a request for access from an access terminal. In this example, the operations of blocks 802 and 804 can be similar to the operations of blocks 702 and 704 described earlier. In this scenario, however, access point 102 may not retrieve session information in some cases.
As represented by block 806, access point 102 sends a request to the network (e.g., a network node 110) to authenticate access terminal 108. In case the access point 102 obtained the session information (for example, including access terminal identifier information, such as an MS ISDN, CSG ID or ou), the access point 102 can send this information to network node 110 together with the request (for example, included in the request message). In some implementations, this operation may involve a request for the list of the
<img file="BRPI0818609A2_D0002.tif" />
30/90 access terminal. In practice, access point 102 can request this list at various times (for example, when the access point is turned on or connected to a network, when an access terminal periodically attempts to access the access point 5, and so on). onwards).
As represented by block 808, network node 110 obtains an identifier associated with access terminal 108. This identifier can comprise, for example, a list of identifiers that indicates one or more 10 access groups associated with the access terminal. For example, the identifier may comprise a list of closed subscriber groups of which access terminal 108 consists of a member, a list of access terminals that are allowed access to access point 102 (for example, an access list access point 102), or a list of access point identifiers that access terminal 108 can access. The determination of the identifier by the network node 110 may comprise, for example, receiving the identifier from another network node (e.g., an HSS) or obtaining the identifier from a local database. In some implementations, the determination of the identifier may involve the determination of a permanent identifier, as discussed in this document (for example, based on a temporary identifier received). Network node 110 sends the identifier or identifiers obtained in block 808 to access point 102 in block 810.
As represented by block 812, access point 102 can then determine whether to allow or deny the requested access based on the received identifier (s). For example, the access point can compare the received identifier (for example, a CSG ID) indicative of the sets to which the access terminal 108 belongs,
31/90
V to information (for example, a CSG ID) in the local access list of access point 102 which is indicative of the pools to which access point 102 belongs. 0 access point
102 can then allow or deny the requested access based on this comparison.
Referring now to Figure 9, several operations are described referring to a scenario where a network controls access to an access point. In this example, the operations of blocks 902, 904, and 906 can be similar to the operations of blocks 802, 804, and 806 described earlier. Again, access point 102 may not retrieve session information in some cases. In addition, in some cases, access point 102 may send its list of local access to the network for use in the authentication operation.
As represented by block 908, in implementations that use temporary identifiers to identify one or more nodes (for example, access terminals), network node 110 (for example, a AAA femto) can determine a permanent identifier associated with the terminal access 108 based on a temporary identifier associated with access terminal 108. For example, access point 102 can obtain a temporary identifier from the access terminal (for example, in block 902) or from session information (for example, in block 904). In that case, access point 102 can send a temporary identifier (for example, a
Temporary NAI) for access terminal 108 next to an identifier (for example, FNID) from access terminal 102 30 to network node 110 according to the request in block 906.
As discussed earlier, according to Figure 7, network node 110 can then cooperate with another network node>
32/90 in order to derive a permanent identifier of the access terminal 108 from the temporary identifier.
As represented by block 910, network node 110 determines whether to allow access terminal 108 to access access point 102. For example, network node 110 can compare an access terminal identifier 108 (for example, an NAI , a CSG ID, etc.) with an access list of access point 102. In this document, the access list can be the local list obtained from access point 102 or it can be an access list maintained by the network (for example, based on information obtained from an exception list, as discussed previously). The network node 110 can then determine whether to allow or deny the requested access based on this comparison.
As represented by block 912, the network node 110 sends an indication of this determination to the access point 102. The access point 102 can then allow or reject the requested access based on the indication received (block 914). Advantageously, in implementations like these, the access point 102 does not need to be aware of the real identity of the access terminals that access point 102 accesses. In addition, the access control list for access point 102 does not need to be sent to access point 102. In this implementation, access control is fully performed on the transparent network node at the access point.
Various techniques can be used to manage access terminal identifiers on a network. As mentioned earlier, an access point can store the valid identifier (for example, NAI) used by an access terminal. In some implementations, this identifier may remain valid for a period of time.
33/90 set time. In the present document, if an access terminal revisits an access point within the time period (that is, the access terminal has the same identifier during this time), the access point can accept the access terminal without obtaining authorization from the network (for example, AAA femto). In some implementations, an operator can choose whether to use a temporary identifier or a permanent identifier for access terminals. If a permanent identifier is used, permanent identifiers can be stored at the access points (for example, in the local access list 340), in such a way that the access point can independently authenticate the access terminals. If a temporary identifier is used, the operator can control the frequency at which access points check with the network (for example, AAA femto) in order to check the identifiers stored in the local access list 340.
Figure 10 illustrates an example of access control operations that can be performed and an implementation that uses long-term evolution (LTE) or other similar technology. In this example, the network (for example, the core network opposite the radio access network) controls whether an access terminal is allowed access to an access point. In addition, techniques are described for provisioning access terminals and access points with CSG subscription information (for example, compatible information), enforcing access control (for example, for idle or active mode), modifying the provisioning of a access point or access terminal, and enforce a CSG list when an access terminal performs operations, such as initialization, trekking area update, and handover.
34/90
The network (for example, a home subscription server, HSS or a CSG subscription server) can maintain CSG subscription information for access terminals and restricted access points on the network. In a similar manner as described earlier, an operator can provide a web server that enables a user to manage CSG subscription information for their restricted access point (s). For example, a user can modify his subscription information (for example, MS ISDNs) 10 using a website. The network can then approve changes (for example, access terminal entries) made by the user and the web server can send subscription information to the network (for example, HSS). In this document, MS ISDN can be converted to an IMSI. The network can then send the CSG information (for example, a unique CSG identifier) to the corresponding restricted access point (s). In addition, the network can send CSG subscription information to an MME when an associated access terminal is registered with the MME.
Likewise, as previously described, provisioning an access terminal (for example, with a list of unique CSG IDs) can be approved by the owner of the access terminal. In addition, operator 25 can also approve the provisioning of the access terminal. In this document, a given CSG ID can be associated with a set of one or more access terminals that are authorized to receive at least one service from a set of at least one restricted access point. In other words, the set of access terminals and the set of access points are all associated with a common CSG ID. It should also be assessed that a given access terminal or
35/90 access can also be associated with multiple CSGs.
In some respects, the network (for example, the HSS) can maintain information indicative of the mapping between an access terminal identifier and the CSG
Subscribed ID. In addition, to the MME, the MME can relay them to the desired ones.
Again, access can be pulling.
example, terminal on one more CSG
In the last one to involve once retrieving points from the HSS is connected to restricted access CSG information, provisioning a push model
For example, access to a new subscription
IDs) and case, and the terminal if terminal or a model in the first case, the network (by can send an SMS message when informing the access terminal the user accepts or rejects the subscription.
the user can initiate an access displays a list of the next (for example, readable CSG IDs manually scan access points by user or other types of point identifiers so that the user can select one or depart
10, on access
According to the same point at the access point of access point), from such more entries the one represented by the block in time, the terminal is restricted access. Per
108 determine which of
1002 Figure access example, even if in the vicinity of the access point 102 associated point
108 102 access to the terminal can send an initiate when it finds it (for example, where an access CSG 108 warns you), appropriate message to the access point
As represented by
ID which is also the registration access terminal or other
102.
block 1004, access point 102 sends a request to the network (for example, one or more network nodes 110) to authenticate the access terminal
36/90
108. In this document, network node (s) 110 may comprise a mobility management entity (MME) or some other suitable network entity or entities. Access point 102 can also send an identifier (for example, a CSG ID associated with access point 102) to network node 110 according to the request (for example, included in the request message). In addition, the request may include information received from access terminal 108 (for example, in block 1002).
As represented by block 1006, network node 110 obtains context information associated with access terminal 108 (for example, from a previous MME to access terminal 108 or from the HSS). This context information can include, for example, a set of identifiers associated with access terminal 108. For example, context information can include a list of all CSG IDs associated with access terminal 108. In some implementations, network node 110 can maintain its own list of CSG IDs for each of its restricted access points. In this case, network node 110 can update its list when an entry is changed on the web server.
As represented by block 1008, network node 110 determines whether access terminal 108 is allowed access to access point 102. For example, network node 110 determines whether an access point identifier 102 (for example, a CSG to which access point 102 belongs) is found in a list of identifiers associated with access terminal 108 (for example, indicative of all CSGs to which access terminal 108 belongs).
»
<img file="BRPI0818609A2_D0003.tif" />
The determination of block 1008 can be carried out on several network nodes. For example, in some implementations, this determination can be made in an MME that obtains and / or maintains the identifiers associated with access point 102 and access terminal 108.
In some implementations, this determination can be made on another network node, such as an HSS. For example, MME can send a request to HSS to determine whether access terminal 108 is authorized to access access point 102. According to this request, MME can send information (for example, identifiers, such as IMSI and CSG ID) to the HSS in some cases. Likewise, in some cases, the HSS can obtain and maintain such information within itself. After determining whether access is allowed, the HSS sends a corresponding response back to the MME.
As represented by block 1010, the MME sends a response to the access point 102 based on the determination of the MME or based on the determination of another network node (for example, an HSS). Based on this response, access point 102 can then allow or deny access through access point 108.
Figure 11 illustrates operations that can be employed according to a handover operation. For example, access terminal 108 can be served initially by access point 104 and, at a last point in time, access terminal 108 handovered access point 102 and then served by that node.
As represented by block 1102, the network (for example, an HSS) can maintain context information for each access terminal in the system. As mentioned earlier, this context information can include a list (for example, a list of
38/90 exceptions) indicative of all access sets (for example, CSGs) to which access terminal 108 belongs.
As represented by block 1104, the network (for example, an MME) seeks the context for a given access terminal and provides the context to a restricted access point when the access terminal becomes active at the restricted access point. Referring to the example in Figure 3, when access terminal 108 becomes active (for example, powered on) at access point 104, network node 110 can send context information to access terminal 108 at the point access 104. In this way, the access terminal 108 can initially be served by the access point 104.
As represented by block 1106, at some point in time, access terminal 108 handovered access point 102. For example, if access terminal 108 moves away from access point 104, the measurement records of the access terminal 108 may indicate that the signal strength of the signals that are received from the access point 102 is now greater than the signal strength of the signals received from the access point 104. In this case, the network can initiate a handover from access point 104 to access point 102.
As represented by blocks 1106 and 1108, according to this handover, the access point 104 (ie, the originating access point) can receive an identifier associated with the target access point (ie, the access point 102) such as, for example, a CSG ID. For example,
<td colspan="7">this information can be received from the terminal</td>
<td>access</td><td> 108</td><td>0 points</td><td>access</td><td colspan="2">104 can,</td><td>So,</td>
<td>to determine</td><td>if</td><td>the terminal</td><td>access</td><td> 108</td><td>has</td><td>access</td>
<td>authorized</td><td>to</td><td>point of</td><td>access 102</td><td>with</td><td>base</td><td>in this</td>
<td colspan="2">identifier.</td><td>For example,</td><td colspan="4">access point 104 can</td>
39/90 compare the identifier to a list that specifies the access points that access terminal 108 is allowed to access (for example, an exception list, such as a CSG ID list from the context information for the access terminal 108).
As represented by block 1110, if access terminal 108 does not have authorized access to access point 102 (for example, the CSG ID of access point 102 is not in the CSG ID list of access terminal 108), 10 the operation handover may not be performed. For example, access point 102 can send a message to network node 110 to complete the handover operation. In addition, or alternatively, access point 102 may send a rejection and / or redirect message to access point 108 (for example, as discussed earlier).
As represented by block 1112, the handover operation can continue if access terminal 108 has authorized access to access point 102 (for example, the CSG ID of access point 102 is in the CSG ID list of access terminal 108 ). Consequently, the network (e.g., MME) can send the context information to the access terminal 108 to the access point 102 or the access point 102 can receive this information from the access point 104.
As represented by block 1114, access point 102 can determine whether access terminal 108 has authorized access to access point 102. For example, similarly as discussed earlier, access point 102 can compare its identifier (for example , a CSG ID) with a list specifying the access points that access terminal 108 is allowed to access (for example, a CSG ID list from the context information for access terminal 108).
40/90
As represented by block 1116, in some implementations, access point 102 can send a request to the network (for example, MME) to confirm that the handover should be performed (for example, according to a 5 switching request) ). For example, as discussed earlier, access point 102 can send a request (for example, which optionally includes an identifier associated with access terminal 108 and CSG ID to the access point, if necessary 10) to network node 110 in order to determine whether access terminal 108 should be allowed access to access point 102.
In situations where an access terminal needs to access the target access point without prior handover preparation (for example, during a radio link), a target access point can seek the context of the access terminal from the access point of source. As mentioned earlier, this context includes a CSG list of the access terminal. Therefore, target access point 20 can determine whether the access terminal is allowed access to the target access point.
As represented by block 1118, based on the determination in block 1114 (and, optionally, in block
1116), the handoff is allowed or rejected. If handover 25 is allowed, then access point 102 becomes the service access point for access terminal 108. Conversely, if handover is not allowed, the handover can be terminated (for example, as discussed previously in conjunction with block 1110).
Referring now to Figure 12, in some implementations, a restricted access point can be used to provision an access terminal. For purposes of illustration, the following examples describe examples where a
41/90 access terminal is provisioned (for example, configured) with a preferred visitor list (PRL).
It should be noted, however, that an access terminal can be provisioned with other types of information in accordance with the teachings contained in this document.
As represented by block 1202, access terminals on a network (for example, any access terminals that can access a restricted access point) can originally be configured with a standard PRL 10 (for example, the list comprises or specifies a configuration pattern). For example, access terminal 106 can be configured by the network operator when access terminal 106 is purchased by a user. This PRL can specify, for example, a standard system identifier (SID), a standard network identifier (NID), and a standard frequency for initial acquisition of any restricted access points that may be deployed on the network. In this document, all previous access terminals can be configured using the standard PRL. In this way, each access terminal can locate and access a restricted access point for provisioning operations. In (e.g.,
SID and / or NID) can correspond to one or more access points associated with a top priority.
For example, the access terminal can be configured to search (for example, search first) for a specific preferred access point or for specific preferred access points (for example, home access points).
In some respects, the parameters of the
Standard PRL can be reserved for operations related to restricted access points. For example, the default SID can be reserved for restricted access points by the operator
42/90 network. Through the use of this SID, it is possible to prevent access terminals that are not configured to access restricted access points (for example, access terminals configured only for use in a macro network) from attempting to register with the restricted access points. .
In addition, the
Default NID can be reserved for startup procedures related to restricted access points. Likewise, the standard frequency can be defined as a common frequency to be used by the 10 restricted access points in the network to transmit signals intended for provisioning procedures. In some cases, the standard frequency can be equal to an operational frequency of macro access points or an operational frequency of a restricted access point 15.
The standard PRL can also include information for macro system selection. For example, the standard PRL may include identifiers and frequencies that can be used to access points of macro access on the network.
As represented by block 1204, the restricted access points in the system (for example, access point
102) are configured to transmit an incoming load signal. In some respects, this incoming load may comprise temporary signaling that is used in conjunction with the provisioning provided by the access point
102. In this document, the input load signaling may have been broadcast according to the generic parameters
PRL discussed earlier (for example, signaling can comprise or specify a standard configuration).
For example, incoming load signaling (for example, a standard signaling)
43/90 standard frequency, and can include the standard SID and standard NID (for example, sent in overhead messages).
Input load signaling can be transmitted at a very low strength power level that is much less than signal transmission power during normal access point operations (for example, when the access point is configured in a operation (such as normal operating mode). For example, the transmission power of the incoming load signaling can result in a coverage range (for example, radius) for the incoming load signaling in the order of one meter or less.
In some implementations, access point 102 can transmit incoming load signals when the access point is in a provisioning mode (for example, configuration or initialization). In some implementations, a user can use an input device to put access point 102 into configuration mode when the user wants to initially provision or reprovision access terminal 106. For example, an access terminal can be provisioned when an access point is first installed, when the access terminal is initially purchased, or when the PRL of an access terminal has been updated by a macro network (for example, together with a change in the visitor list, international travel, and so on) that resulted in the PRL being provisioned by the access point (as discussed earlier) being overwritten.
As represented by block 1206, when the access terminal 106 provisioned by the standard PRL is placed next to the restricted access point 102 that operates in a provisioning mode, the access terminal 106
44/90 can receive the incoming load signal transmitted by access point 102. In response, access terminal 106 can send a message to access point 102 to start provisioning operations. In some implementations, this message may include the PRL currently used by the access terminal 106. In some implementations, an access terminal 106 user can initiate provisioning by selecting an appropriate resource on the access terminal (for example, by dialing a defined number).
As represented by block 1208, access point 102 (for example, provisioning controller 328) can define a new PRL for access terminal 106 (for example, for normal mobile operations). The new PRL can include macro system information as in the standard PRL, but the standard PRL initialization information can be removed. In its place, the new PRL information can be added (for example, the list comprises or specifies a new configuration). In some respects, the new PRL information may be specific to access point 102 (for example, the new PRL may be different from the PRL provisioned by other access points). For example, a new PRL can specify the SID that is reserved for all restricted access points as discussed earlier, an NID that is unique to access point 102 (for example, a femto NID, FNID), and a frequency parameter indicating the operational frequency of the access point 102. This frequency parameter can be the same or different from the standard frequency. In some respects, the new PRL information (for example, SID and / or NID) may correspond to one or more access points associated with a top priority. For example, access terminal 106 can be configured to
45/90 search (for example, search first) for a specific preferred point or access points (for example, home access points).
Access point 102 can obtain macro system PRL information in several ways. In some implementations, access point 102 may request this PRL information from the macro access point (for example, via network node 110 or over the air). In some implementations, access point 102 can receive this PRL information from an access terminal (for example, access terminal 108). For example, access point 102 may include an over-the-air function. In this document, access point 102 can send a message (for example, an SSPR configuration request) to request the current PRL from the access terminal (which can include the current macro PRL information, as discussed earlier) and the access terminal. access can respond by sending your current PRL over the air to access point 102.
Since access point 102 defines a new PRL, access point 102 sends (e.g., pushes) the PRL to access terminal 106. For example, access point 102 can send a PRL to the access terminal over the air (for example, through OTASP or OTAPA).
Advantageously, by provisioning the access terminal 106 through the access point 102 as discussed earlier, the network operator does not need to maintain information specific to the access terminal (for example, PRL information). It may be desirable, however, to configure access point 102 so that it regularly updates the PRL of the access terminal. For example, the PRL can be updated every night and sent to access terminal 106 over the air. Furthermore, with
46/90 the purpose of preventing an access point from a set of related access points from overwriting the provision of PRL information by another access point in the set, each access point can be configured to simply update the current terminal's PRL information access. For example, access point 102 can query access terminal 106 for its current PRL information, so access point 102 will add its own PRL system information to the current PRL of access terminal 106, instead of overwriting the current PRL information.
As represented by block 1210, since the access terminal 106 is provisioned with the new PRL information, the access terminal 106 will use this information to identify the access points that it can access. For example, in case the access terminal 106 determines that the access point 102 is in the vicinity (for example, after the access point has been configured for a normal operating mode), the access terminal 106 may give preference to be served by access point 102 as opposed to any other access points (e.g., a macro access point) that are detected by access terminal 106.
Referring now to Figure 13, various techniques are described that serve to control restricted access (for example, association) at an access point. In this example, an access point can be configured with a local list of access terminals that are allowed access to one or more services provided by the access point. The access point can then grant or deny access based on the local list. Advantageously, in some respects, this scheme can enable the owner of an access point to provide temporary service to terminals.
47/90 accessing visitors (for example, adding / deleting these access terminals to / from the list) without involving a network operator.
As represented by block 1302, a restricted access point (for example, access point 102) is configured by an access list (for example, represented by the local access list 340 in Figure 3).
For example, the owner of the access point
102 you can configure a list of identifiers (for example, phone numbers) of access terminals allowed to use one that has or more services provided by the access point
102.
In some implementations, control over which access terminals can access access point 102 may therefore depend on the access point owner
102 rather than a network operator.
Access point 102 can be provisioned in several ways. For example, the owner can use a web interface hosted by access point 102 to configure access point 102.
In addition, different access terminals can provide different levels of access. For example, visiting access terminals can provide temporary access based on several criteria. Likewise, in some implementations, a home access terminal may be providing a better quality of service than a visitor access terminal. In addition, some access terminals (for example, visiting access terminals) can provide access to certain services (for example, local services, such as a multimedia server or some other type of information server) without involving authentication by an operator network. Similarly, in
48/90 In some cases, the local access list 340 can be used as an initial temporary replacement at access point 102, whereby an authentically current one (for example, for a phone call) can be performed over the network in order to prevent network security from being compromised.
As represented by block 1304, access point 102 can send the access terminal identifier information that has been configured (for example, local access list 340) in block 1302 to a network database (for example, central of home location authentication / registration,
AC / HLR) and requests other identification information associated with the corresponding access terminals. For example, access point 102 can send a telephone number from access terminal 106 to network node 110 (for example, which comprises an HLR database) and receive an electronic serial number (ESN) or an international identity from the mobile subscriber (IMSI) that is assigned to access terminal 106 from network node 110.
As represented by block 1306, access point 102 can report your identifying information (for example, as discussed in this document). For example, access point 102 can warn SID and FNID information, as discussed earlier.
As represented by block 1308, an access terminal that is provisioned to access access point 102 can determine that it is in the vicinity of access point 102 upon receipt of the notified identification information. For example, access terminal 106 can be provisioned with a PRL through access point 102, as discussed earlier, or access terminal 106 can be provisioned with a PRL.
49/90
PRL that includes the restricted access point SID, a wildcard NID, and one or more operational frequencies that are used by access point 102, or access terminal 106 can be provisioned in some other way that allows it to identify the point 102 (for example, provisioned with a preferred user zone list). Access terminal 106 may then attempt to register with access point 102 as a result of receiving a different SID (for example, which may represent a different zone from the macro zone for a zone-based registration). Therefore, in some cases, the access terminal may automatically attempt to access access point 102. In other cases, however, a user can control whether access terminal 106 accesses access point 102 (for example, the user provides entry via an input device in response to an indication of detected access points issued by the access terminal 106). According to this record, access terminal 106 can send its identifier (for example, its ESN, IMSI, etc.) to access point 102 (for example, through an access channel).
As represented by blocks 1310 and 1312, access point 102 determines whether access terminal 106 is allowed access to access point 102. For example, access point 102 can determine whether the identifier received from access terminal 106 it is listed in the local access list 340. It should be noted that authentication information other than ESNs and IMSIs can be used in different implementations. For example, access point 102 can receive information from the call's originating number through idle messages and use this information for authentication (for example, to be compared to a calling number received from the
50/90 access terminal 106 via a registration message or in some other way).
As represented by block 1314, if access terminal 106 is not allowed access (for example, if the identifier received from the access terminal is not in the local access list 340), access point 102 may deny access. For example, access point 102 can send a registration rejection message to access terminal 106. In addition or alternatively, access point 102 can send a service redirect message to access terminal 106. This message can include, for example, information (for example, SID, NID, operational frequency) that identifies an alternative access point (for example, a macro LAN) that access terminal 106 can access.
As represented by block 1316, if access terminal 106 is allowed access (for example, if the identifier received from the access terminal is in the local access list 340), access point 102 can grant access to certain services. For example, as discussed earlier, access point 102 can grant access to local services provided by a local network.
In addition or alternatively, access point 102 can pass registration information to network node 110 (for example, the macro network HRL) for authentication and registration of access terminal 106. Network node 110 can then reply with a registration acceptance or rejection message. In response, access point 102 can send a message corresponding to access terminal 106. If authorized, access point 106 then obtains the requested service from access point 102 (e.g., network access).
51/90
It should be appreciated that the prior techniques can be implemented in various ways according to the teachings contained in this document. For example, authentication information that is different from the information specifically mentioned above (for example, ESNs, IMSIs, CSG IDs) can be used in an apparatus or method practiced based on the teachings contained in this document.
In some respects, the teachings contained in this document can be employed in a network that includes macro-scale coverage (for example, an extended-area cellular network, such as a 3G network, typically referred to as a macro cellular network or a WAN) and smaller scale coverage (for example, a home or business network environment, typically referred to as a LAN). As an access terminal moves over a network, the access terminal can be served at certain locations by access points that provide macro coverage while the access terminal can be served at other locations by access points that provide smaller scale coverage.
In some ways, smaller coverage nodes can be used to provide incremental capacity growth, built-in coverage, and different services (for example, for a more robust user experience). In the discussion of this document, a node that provides coverage in a relatively larger area can be called a macro node. A node that provides coverage in a relatively smaller area (for example, a residence) can be referred to as a femto node. A node that provides coverage in an area that is smaller than a macro area and larger than a femto area can be termed as a pico52 / 90 node (for example, providing coverage in a commercial building).
A cell associated with a macro-node, a femto node, or a peak node can be referred to as a macro-cell, a femto cell, or a peak-cell, respectively. In some implementations, each node can be associated with (for example, divided into) one or more cells or sectors.
In various applications, another terminology can be used to refer to a macro-node, a femto node, or a peak-node. For example, a macro node can be configured or named as an access node, base station, access point, eNodeB, macro cell, and so on. Likewise, a femto node can be configured or named as a Home NodeB, Home eNodeB, access point base station, femto cell, and so on.
Figure 14 illustrates a wireless communication system 1400 configured to support a number of users, in which the lessons contained in this document can be implemented. The system 1400 provides communication for multiple cells 1402, such as, for example, macrocells 1402 A - 1402G, each cell being served by a corresponding access point 1404 (for example, access points 1404A - 1404G). As shown in Figure 14, access terminals 1406 (for example, access terminals 1406A - 1406L) can be dispersed in various locations throughout the system over time. Each access terminal 1406 can communicate with one or more access points 1404 on a direct link (FL) and / or a reverse link (RL) at any given time, depending on whether access point 1406 is active and whether the same is found in a smooth handoff, for example. The 1400 wireless communication system can provide service to a large geographic region. For example, macro cells 1402A-1402G
53/90 can cover some blocks in a neighborhood or several kilometers in the rural environment.
Figure 15 illustrates an exemplary communication system 1500 where one or more femto nodes are deployed in a networked environment. Specifically, the 1500 system includes multiple femto nodes 1510 (for example, femto nodes 1510A and 1510B) installed in a relatively small scale network environment (for example, in one or more 1530 user homes). Each femto node 1510 can be coupled to an extended area network 1540 (for example, the Internet) and a mobile operator core network 1550 through a DSL router, cable modem, wireless link, or other means of communication. connectivity (not
As will be discussed later, each femto node 1510 can be configured to serve associated access terminals 1520 (for example, access terminal 1520A) and, optionally, extraneous access terminals 1520 (for example, access terminal 1520B). In other words, access to femto nodes 1510 can be restricted, so a given access terminal 1520 can be served by a set of femto node (s) (for example, home) designated 1510, however, it may not be served by none of the non-designated femto nodes 1510 (for example, a neighboring femto node 1510).
Figure 16 illustrates an example of a coverage map 1600 where several tracking areas 1602 (or routing areas or local areas) are defined, each of which includes several macro coverage areas 1604. In this document, the associated coverage areas tracking areas 1602A, 1602B, and 1602C are outlined by wide lines and macro coverage areas 1604 are represented by hexagons. Tracking areas 1602 also include femto coverage areas 1606. In this
54/90 example, each of the femto coverage areas 1606 (for example, femto coverage area 1606C) is described in a macro coverage area 1604 (for example, macro coverage area 1604B). It should be noted, however, that a femto coverage area 1606 may not be entirely within a macro coverage area 1604. In practice, a large number of femto coverage areas 1606 can be defined by a given tracking area 1602 or macro coverage area 1604. Likewise, one or more peak coverage areas (not shown) can be defined in a given tracking area 1602 or in a macro coverage area 1604.
Referring again to Figure 15, the owner of a femto node 1510 can subscribe to a mobile service, such as, for example, a 3G mobile service, offered by the core network of the mobile operator 1550. In addition, a access terminal 1520 may be able to operate both in macro environments and in smaller scale network environments (for example, residential). In other words, depending on the current location of the access terminal 1520, the access terminal 1520 can be served by a macro cell access point 1560 associated with the core network of the mobile operator 1550 or by any of a set of femto nodes 1510 (for example, femto nodes 1510A and 1510B that reside in a home of the corresponding user 1530). For example, when a subscriber is not at home, it is served by a standard macro access point (for example, access point 1560) and when the subscriber is at home, it is served by a femto node (for example , node 1510A). In this document, it should be assessed that a femto 1510 node can be backwards compatible with existing 1520 access terminals.
55/90
You can implant a femto 1510 node in a single frequency or, alternatively, in multiple frequencies. Depending on the particular configuration, the single frequency or one or more of the multiple frequencies may overlap one or more frequencies used by a macro access point (for example, 1560 access point).
In some respects, an access terminal 1520 can be configured to connect to a preferred femto node (for example, the home femto node of the access terminal 1520) when such connectivity is possible. For example, when the access terminal 1520 is in the user's home 1530, it may be desirable for the access terminal 1520 to communicate only with the home femto node 1510.
In some respects, if access terminal 1520 operates on a macro cellular network 1550, but does not reside in your most preferred network (for example, as defined in a preferred visitor list), access terminal 1520 may continue to search for most preferred network (for example, the preferred femto node 1510) using a Better System Re-selection (BSR), which may involve a periodic scan of available systems to determine if the best systems are currently available, and subsequent efforts to join those preferred systems. Through the acquisition entry, the access terminal 1520 can limit the search for a specific band and channel. For example, the search for the most preferred system can be repeated periodically. Upon discovering a preferred femto node 1510, access terminal 1520 selects femto node 1510 to stay connected in its coverage area.
56/90
A femto knot can be restricted in some ways.
For example, a particular femto node can only provide certain services to certain access terminals. In deployments with an allegedly restricted (or closed) membership, a given access terminal can only be served by the macro cellular mobile network and a defined set of femto nodes (for example, femto nodes 1510 residing in the corresponding user's home 1530) . In some implementations, a node may be restricted so as not to provide at least one node with at least one between: signaling, data access, registration, pagination, or service.
In some respects, a restricted femto node (which can also be referred to as a closed group subscriber household NodeB) consists of a node that provides service to a restricted provisioned set of access terminals. This set can be temporarily or permanently extended as needed. In some respects, a closed group of subscribers (CSG) can be defined as the set of access points (for example, femto nodes) that share a common access control list for access terminals. A restricted access point can include a CSG that allows multiple access terminals to connect to it. A single access terminal may have the ability to connect to multiple restricted access points. A channel in which all femto nodes (or all restricted femto nodes) in a region operate can be referred to as a femto channel.
Therefore, there can be several relationships between a given femto node and a given access terminal.
For example, from the perspective of an access terminal, an open femto node can refer to a femto node with no restricted association (for example, the femto node allows
57/90 access to any access terminal). A restricted femto node can refer to a femto node that is restricted in some way (for example, restricted to association and / or registration). A home femto node can refer to a femto node in which the access terminal has authorized access and operation (for example, permanent access is provided for a defined set of one or more access terminals). A visiting femto node can refer to a femto node in which an access terminal has temporarily authorized access or operation. A strange femto node may refer to a femto node in which the access terminal has no authorized access or operation, except for perhaps emergency situations (for example, calls to 911).
From a restricted femto node perspective, a home access terminal can refer to an access terminal that has authorized access to the restricted femto node (for example, the access terminal has permanent access to the femto node). A visiting access terminal can refer to an access terminal that has temporary access to the restricted femto node (for example, based, in a limited way, on the deadline, usage time, bytes, connection count, or some other criterion or criteria). A strange access terminal can refer to an access terminal that is not allowed to access the restricted femto node, except for perhaps emergency situations, for example, such as calls to 911 (for example, an access terminal that does not have credentials or permission to register with the restricted femto node).
For convenience, the description in this document describes several features in the context of a femto node. It should be considered, however, that a peak-knot can provide the same or similar functionality for a larger coverage area. For example,
58/90 a peak-node can be restricted, a household peak-node can be defined by a given access terminal, and so on.
A wireless multiple access communication system can simultaneously support communication to multiple wireless access terminals. As mentioned earlier, each terminal can communicate with one or more base stations through direct and reverse link transmissions. The direct link (or downlink) refers to the communication link from the base stations to the terminals, and the reverse link (or uplink) refers to the communication link from the terminals to the base stations. This communication link can be established through a single input and single output system, a multiple input and multiple output system (MIMO), or some other type of system.
A MIMO system employs multiple (N<sub>T</sub>) transmission and multiple antennas (N<sub>R</sub>) receiving antennas for data transmission. A MIMO channel formed by the NT transmission and N reception antennas<sub>R</sub> can be decomposed into independent N channels<sub>s</sub>, which are also called as spatial channels, where N<sub>s</sub> 1 min {N<sub>T</sub>, N<sub>R</sub>). Each of the independent channels Ns corresponds to a dimension. The MIMO system can provide improved performance (for example, better transmission capacity and / or greater reliability) if the additional dimensions created by the multiple transmit and receive antennas are used.
A MIMO system can support time division duplexing (TDD) and frequency division duplexing (FDD). In a TDD system, the forward and reverse link transmissions are in the same frequency region, in such a way that the principle of reciprocity allows the estimation of the direct link channel from the
59/90 reverse link channel. This allows the access point to extract a beamform gain transmitted over the direct link when multiple antennas are available at the access point.
The teachings contained in this document can be incorporated into a node (for example, a device) that employs several components intended for communication with at least one other node. Figure 17 describes several sample components that can be used to facilitate communication between nodes. Specifically, Figure 17 illustrates a wireless device 1710 (for example, an access point) and a wireless device 1750 (for example, an access terminal) from a MIMO 1700 system. In device 1710, there are provided traffic data for a series of data streams from a 1712 data source to a 1714 transmission (TX) data processor.
In some respects, each data stream is transmitted by a respective transmission antenna. The TX 1714 data processor formats, encodes, and merges traffic data for each data stream based on a particular coding scheme selected so that this data stream provides encrypted data.
The encoded data for each data stream can be multiplexed with pilot data using OFDM techniques. Pilot data typically consists of a known data pattern that is processed in a known manner and can be used in the receiving system to estimate the channel response. The multiplexed pilot and encoded data for each data stream is then modulated (that is, mapped by symbols) based on a particular modulation scheme (for example, BPSK, QSPK, M-PSK, or M-QAM) selected so that the data flow
60/90 provide modulation symbols. The rate, encoding and modulation of data for each data stream can be determined by instructions carried out by a 1730 processor. A 1732 data memory can store program code, data, and other information used by the 1730 processor or other components of the 1710 device.
The modulation symbols for all data streams are then provided to a MIMO TX 1720 processor, which can additionally process the modulation symbols (for example, for OFDM). Then, the MIMO TX 1720 processor provides N modulation symbol streams<sub>T </sub>to the N<sub>T</sub> 1722A to 1722T (XCVR) transceivers. In some ways, the MIMO TX 1720 processor applies beamforming weights to the symbols in the data streams and the antenna from which the symbol is transmitted.
Each 1722 transceiver receives and processes its respective symbol stream in order to provide one or more analog signals, and other conditions (for example, amplify, filter, and upwardly convert) the analog signals in order to provide a modulated signal suitable for transmission over the MIMO channel. The modulated signals N<sub>T</sub> from 1722A to 1722T transceivers are then transmitted from Ν antennas<sub>τ</sub> 1724A to 1724T, respectively.
In the 1750 device, the modulated signals transmitted are received by N antennas<sub>R</sub> 1752A to 1752R and the signal received from each 1752 antenna is provided to a respective transceiver (XCVR) 1754A to 1754R. Each 1754 transceiver conditions (for example, filters, amplifies, and downwards converts) a respective received signal, digitizes the conditioned signal to provide
61/90 samples, and further processes the samples to provide a corresponding received symbol stream.
Then, a 1760 receiving data processor (RX) receives and processes the received symbol streams N<sub>R</sub> from N transceivers<sub>R</sub> 1754 based on a particular receiver processing technique to provide N = detected symbol streams. Then, the RX 1760 data processor demodulates, deinterleaves, and decodes each detected symbol stream in order to retrieve traffic data into the data stream. Processing by the RX 1760 data processor is complementary to that performed by the MIMO TX 1720 processor and the TX 1714 data processor on the 1710 device.
A 1770 processor periodically determines which pre-coding matrix to use (discussed later). The 1770 processor formulates a reverse link message comprising a matrix index portion and a rating value portion. A 1772 data memory can store program code, data, and other information used by the 1770 processor or other components of the 1750 device.
The reverse link message can comprise several types of information regarding the communication link and / or the received data flow. The reverse link message is then processed by a TX 1738 data processor, which also receives traffic data for a series of data streams from a 1736 data source, modulated by a 1780 modulator, conditioned by 1754A transceivers. the 1754R, and transmitted back to the 1710 device.
In device 1710, modulated signals from device 1750 are received by antennas 1724, conditioned by transceivers 1722,
62/90 demodulated by a demodulator (DEMOD)
1740, processed by a data processor
RX 1742 for the purpose of extracting the reverse link message transmitted by the device
1750. So, the processor
1730 determines which matrix to use to determine the beamforming weights, then processes the extracted message.
The Figure also illustrates that the communication components can include one or more components that perform access control operations, as taught in this document. For example, a 1790 access control component can cooperate with the processor
1730 and / or other components of the 1710 device to send / receive signals to / from another device (e.g., 1750 device) as taught herein. Similarly, a 1792 access control component can cooperate with the processor
1770 and / or other components of the 1750 device to send / receive signals to / from another device (e.g., 1710 device). It should be appreciated that for each 1710 and 1750 device the functionality of two or more components described can be provided by a single component. For example, a single processing component can provide the functionality of the 1790 access control component and the 1730 processor and a single processing component can provide the functionality of the 1792 access control component and the 1770 processor.
The teachings contained in this document can be incorporated into various types of communication systems and / or system components. In some respects, the teachings contained in this document can be used in a multiple access system capable of
63/90 to support communication with multiple users by sharing available system resources (for example, specifying one or more between: bandwidth, transmission power, encoding, interleaving, and so on). For example, the teachings contained in this document can be applied by any combination of the following technologies: Code Division Multiple Access (CDMA), Multi-carrier CDMA (MCCDMA), Broadband CDMA (W-CDMA), systems High Speed Packet Access (HSPA, HSPA +), Time Division Multiple Access (TDMA) systems,
Frequency Division Multiple Access (FDMA), FDMA systems with Single Carrier (SC-FDMA),
Multiple Access by Orthogonal Frequency Division (OFDMA), or other multiple access techniques. A wireless communication system that employs the teachings contained in this document can be designed to implement one or more standards, such as IS-95, cdma2000,
IS-856, W-CDMA, TDSCDMA, and other standards. A CDMA network can implement a radio technology, such as Universal Terrestrial Radio Access (UTRA), cdma2000, or some other technology. UTRA includes W-CDMA and Low Chip Rate (LCR). Cdma2000 technology covers IS-2000 standards,
IS-95 and IS-856.
A TDMA network can implement radio technology, such as the Global System for
Communications
(GSM).
An OFDMA network can implement radio technology, such as
UTRA
Developed (E-UTRA),
IEEE 802.11, IEEE 802.16,
IEEE
802.20, Flash-OFDM®, etc. UTRA, E-UTRA, and GSM are part of the Universal Mobile Telecommunications System (UMTS). The teachings contained in this document can be implemented in a 3GPP Long Term Evolution system
64/90 (LTE), an Ultra-Mobile Broadband (UMB) system, and other types of systems. The LTE system consists of a launch of UMTS that uses E-UTRA. Although certain aspects of the description can be described using 3GPP terminology, it should be understood that the lessons contained in this document can be applied to 3GPP technology (Rel99, Rel5, Rel6, Rel7), as well as 3GPP2 technology (IxRTT, IxEV-DO RelO, RevA, RevB) and other technologies.
The teachings contained in this document can be incorporated (for example, implemented or carried out by) on a variety of devices (for example, nodes). In some respects, a node (for example, a wireless node) implemented in accordance with the teachings contained in this document may comprise an access point or an access terminal.
For example, an access terminal may comprise, be implemented as, or known as, user equipment, a subscription station, a subscription unit, a mobile station, a mobile, a mobile node, a remote station, a remote terminal, a user terminal, a user agent, a user device, or some other terminology. In some implementations, an access terminal may comprise a cell phone, a cordless phone, a session initiation protocol (SIP) phone, a local wireless mesh station (WLL), a personal digital assistant (PDA), a portable device having a wireless capability, or some other suitable processing device connected to a wireless modem. Consequently, one or more aspects taught in this document can be incorporated into a phone (for example, a cell phone or a smart phone),
65/90 a computer (for example, a laptop), a portable communication device, a portable computing device (for example, a personal data assistant), an entertainment device (for example, a music player, a device video player, or a satellite radio), a global positioning system device, or any other suitable device that is configured to communicate wirelessly.
An access point can comprise, be implemented as, or known as, a NodeB, an eNodeB, a radio network controller (RNC), a base station (BS), a radio base station (RBS), a station controller base (BSC), a base transceiver station (BTS), a transceiver function (TF), a radio transceiver, a radio router, a set of basic services (BSS), a set of extended services (ESS), or some other similar terminology.
In some respects, a node (for example, an access point) may comprise an access node for a communication system. This access node can provide, for example, connectivity to a network (for example, an extended area network, such as the Internet or a cellular network) through a direct link communication link or wireless link to the network. Consequently, an access node can enable another node (for example, an access terminal) to access a network or some other functionality. In addition, it should be assessed that one or both of the nodes may be portable or, in some cases, relatively non-portable.
Likewise, it must be assessed that a wireless node may be able to transmit and / or receive information in a straightforward manner (for example, through a direct connection). Therefore, a receiver and a transmitter, as
66/90 discussed in this document, may include appropriate communication interface components (for example, electrical or optical interface components) to communicate through a direct medium.
A wireless node can communicate through one or more wireless communication links that are based on or otherwise support any suitable wireless communication technology. For example, in some ways, a wireless node can join a network. In some respects, the network may comprise a local area network or an extended area network. A wireless device may support or otherwise use one or more among a variety of wireless communication technologies, protocols, or standards, such as those discussed in this document (for example, CDMA, TDMA, OFDM, OFDMA, WiMAX, Wi-Fi, and so on). Similarly, a wireless node can support or otherwise use one or more among a variety of corresponding modulation or multiplexing schemes. Therefore, a wireless node can include appropriate components (for example, overhead interfaces) to establish and communicate over one or more wireless communication links using the previous wireless communication technology or other wireless communication technologies. For example, a wireless node can comprise a wireless transceiver with associated transmitting and receiving components that can include various components (for example, signal generators and signal processors) that facilitate communication over a wireless medium.
The components described here can be implemented in a variety of ways. Referring to Figures 18 to 28, the 1800, 1900, 2000, 2100, 2200, 2300, 2400, 2500, 2600, 2700, and 2800 devices are represented as a series of related inter67 / 90 functional blocks.
In some respects, the functionality of these blocks can be implemented as a system that includes one or more processor components. In some aspects, the functionality of these blocks can be implemented using, for example, at least a portion of one or more integrated circuits (for example, an ASIC).
As discussed in this document, an integrated circuit can include a processor, software, or other related components, or some combination thereof. The functionality of these blocks can also be implemented in some other way, as taught in this document.
In some respects, one or more dotted blocks in Figures 18 to 28 are optional.
The 1800, 1900, 2000, 2100, 2200, 2300, 2400, 2500, 2600, 2700, and 2800 devices can include one or more modules that can perform one or more of the previous functions with reference to the various figures. For example, a 1802 receive / send mechanism may correspond, for example, to a communication controller, as discussed in this document. A mechanism for determining identifiers 1804 can correspond, for example, to an access controller, as discussed in this document. A mechanism for determining permitted services 1806 may correspond, for example, to an access controller, as discussed in this document. A receiving mechanism 1902 can correspond, for example, to a communication controller, as discussed in this document. A 1904 sending mechanism can correspond, for example, to an access controller, as discussed in this document. A 1906 identifier determination mechanism can correspond, for example, to an access controller, as discussed in
68/90 this document. A 2002 sending mechanism can correspond, for example, to an access controller as discussed in this document. A receiving mechanism 2004 can correspond, for example, to a communication controller, as discussed in this document. A mechanism for determining permitted services 2006 may correspond, for example, to an access controller, as discussed in this document. A 2102 configuration mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A means of obtaining 2104 may correspond, for example, to an access controller, as discussed in this document. A receiving mechanism 2106 can correspond, for example, to a communication controller, as discussed in this document. A 2108 determination mechanism can correspond, for example, to an access controller, as discussed in this document. A 2202 identifier determination mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A sending mechanism 2204 can correspond, for example, to a communication controller, as discussed in this document. An allocation mechanism 2206 can correspond, for example, to a provisioning controller, as discussed in this document. A receiving mechanism 2302 can correspond, for example, to a provisioning controller, as discussed in this document. A transmission mechanism 2304 can correspond, for example, to a communication controller as discussed in this document. A mechanism for determining identifiers 2402 can correspond, for example, to an
69/90 provisioning as discussed in this document. A sending mechanism 2404 can correspond, for example, to a communication controller, as discussed in this document. A .2502 receiving mechanism can correspond, for example, to a communication controller, as discussed in this document. An access enable determination mechanism 2504 may correspond, for example, to an access controller, as discussed in this document. A determination mechanism based on a 2506 configuration can correspond, for example, to an access controller, as discussed in this document. A list maintenance mechanism 2508 can correspond, for example, to an access controller, as discussed in this document. A 2602 configuration mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A transmission mechanism 2604 can correspond, for example, to a communication controller, as discussed in this document. A receiving mechanism 2606 can correspond, for example, to a communication controller, as discussed in this document. A 2608 shipping mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A 2610 definition mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A 2702 monitoring mechanism can correspond, for example, to a receiver, as discussed in this document. A signaling receiving mechanism 2704 can correspond, for example, to a receiver, as discussed herein. A 2706 send mechanism can correspond, for example, to a
70/90 communication, as discussed in this document. A visitor list reception mechanism 2708 can correspond, for example, to a provisioning controller, as discussed in this document. A 2802 configuration mechanism can correspond, for example, to a provisioning controller, as discussed in this document. A signaling receiving mechanism 2804 can correspond, for example, to a receiver, as discussed herein. A 2806 sending mechanism can correspond, for example, to a communication controller, as discussed in this document. An authorization receiving mechanism 2808 can correspond, for example, to an access controller, as discussed in this document. A 2810 prompting medium can correspond, for example, to an access controller, as discussed in this document. A 2812 display mechanism can correspond, for example, to an access controller, as discussed in this document.
It should be understood that any reference to an element in this document that uses a designation, such as first (a), second (a), and so on, does not generally limit the quantity or order of those elements. Instead, these designations can be used in this document as a convenient method of distinguishing between two or more elements or examples of an element. Therefore, a reference to the first and second elements does not mean that only two elements can be employed or that the first element must precede the second element in some way. Likewise, except where otherwise indicated, a set of elements can comprise one or more elements.
71/90
Individuals skilled in the art will understand that information and signals can be represented using any of a variety of different techniques.
For example, data, instructions, commands, information, signals, bits, symbols, and chips that can be referenced throughout the previous description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, fields or optical particles, or any combination of them.
Individuals skilled in the art will further assess that any of the various blocks, modules, processors, media, circuits, and illustrative logic algorithm steps described in conjunction with the aspects described here can be implemented as electronic hardware (for example, an digital implementation, an analog implementation, or a combination of the two, which can be designated using source coding or some other technique), various forms of instructions for incorporating program or project code (which may be referred to in this document, for convenience, as software or a software module), or combinations of both. In order to clearly illustrate this interchangeability between hardware and software, several components, blocks, modules, circuits, and illustrative steps have been described above generically in terms of their functionality. Whether such functionality is implemented as hardware or software will depend on the particular application and design restrictions imposed on the system as a whole. Artisans skilled in the art can implement the described functionality in a number of ways for each particular application, however, such implementation decisions should not be interpreted as causing a divergence in the scope of this description.
72/90
The various blocks, modules, and illustrative logic circuits described in conjunction with the aspects described here can be implemented or executed by an integrated circuit (IC), an access terminal, or an access point. 0 IC can comprise a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable port arrangement (FPGA) or other programmable logic device, discrete port logic or transistor , discrete hardware components, electrical components, optical components, mechanical components, or any combination thereof designed to perform the functions described herein, and can execute the codes or instructions that reside in the CI, outside the IC, or both. A general purpose processor can be a microprocessor, however, alternatively, the processor can be any processor, controller, microcontroller, or conventional state machine. A processor can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other configuration.
It should be understood that any specific order or hierarchy of steps in any process described is an example of a sample approach. Based on design preferences, it should be understood that the specific order or hierarchy of steps in processes can be rearranged while remaining within the scope of this description. The attached claims of the method present the elements of the various steps in a sample order, and should not be taken as limiting the specific order or hierarchy presented.
73/90
The functions described can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, functions can be stored or transmitted in one or more instructions or code in a computer-readable medium. Computer-readable media includes both a computer storage medium and a communication medium that includes any medium that facilitates the transfer of a computer program from one place to another. A storage medium can be any available medium that can be accessed by a computer. By way of example, and without limitation, such computer-readable media may comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other means that may be used to transport or store desired program codes in the form of instructions or data structures and which can be accessed by a computer. Likewise, any connection is appropriately designated as a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source that uses a coaxial cable, fiber optic cable, twisted pair cable, digital signature line (DSL), or wireless technologies , such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair cable, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. Depending on the usage in question, the terms diskette and disk include a compact disk (CD), a laser disk, an optical disk, a versatile digital disk (DVD), a floppy disk and a blu-ray diskette, with diskettes generally reproduce data in a magnetic way,
74/90 while discs reproduce data optically with lasers. Combinations of these should also be included in the scope of the computer-readable media. Briefly, it must be assessed that a computer-readable medium can be implemented in any suitable computer program product.
In view of the above, in some respects, a first method of communication comprises: determining an identifier for a set of at least one access point that is configured to provide at least one service to only a set of at least one access terminal, with the identifier uniquely identifying the set of at least one access point in an operator network; and send the identifier to each access point in the set of at least one access point. In addition, in some respects, at least one of the elements cited below may also apply to the first method of communication: the identifier comprises a network identifier, and the network comprises a cellular operator domain; the identifier is determined in conjunction with the activation of an access point in the set of at least one access point; the set of at least one access point comprises a plurality of access points that belong to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a closed group of common subscribers; the identifier is based on text; each access point in the set of at least one access point is restricted so as not to provide at least one other access terminal with at least one of the groups consisting of: signaling, data access, registration, and service; each access point in the set of at least one access point comprises a
75/90 femto knot or peak-knot; determining the identifier comprises receiving a request for an identifier and determining whether the identifier is already in use by at least one other access point; if the requested identifier is already in use by at least one other access point, sending the identifier comprises sending a response to the request comprising an identifier that is not in use by any other access point; each access point in the set of at least one access point provides at least one other service to at least one other access terminal; the method further comprises assigning a unique device identifier to each access point in the set of at least one access point; each access point in the set of at least one access point provides different services for the set of at least one access terminal in relation to at least one other access terminal.
Likewise, in view of what was said earlier, in some respects, a second method of communication comprises: receiving an identifier for a set of at least one access point in an access point in the set, with each access point pool access is configured to provide at least one service to only a pool of at least one access terminal, and where the identifier uniquely identifies the at least one access point on an operator network; and transmit the identifier over the air. In addition, AM some aspects, at least one of the elements mentioned below may apply to the second method of communication: the method also comprises receiving a registration message from an access terminal of the set of at least one terminal of access in response to the transmission of the identifier; being that the identifier comprises a
76/90 network identifier, and the network comprises a cellular operator domain; the identifier is received as a result of activating the access point that receives the identifier; the set of at least one access point comprises a plurality of access points that belong to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a closed group of common subscribers; the identifier is based on text; each access point in the set of at least one access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; each access point in the set of at least one access point comprises an ostomy or a peak-knot; each access point in the set of at least one access point provides at least one other service to at least one other access terminal; each access point in the set of at least one access point provides different services for the set of at least one access terminal in relation to at least one other access terminal; the identifier is received in response to a request for the identifier; the method also includes determining a proposed identifier, and the request includes the proposed identifier.
Likewise, in view of what was said earlier, in some respects, a third method of communication comprises: determining access terminal identifiers for a set of access terminals; and sending the identifiers to at least one access point that is configured to provide at least one service to the set of access terminals only. Furthermore, in some respects, at least one of the elements
77/90 mentioned below can also apply to the third method of communication: the identifiers comprise permanent identifiers for the access terminals; the identifiers comprise temporary identifiers for the access terminals; the identifiers comprise network address identities or digital network numbers for services integrated into the mobile station; identifiers are sent in response to a request from an access point of at least one access point; the determination comprises receiving the identifiers from a network node; the determination comprises receiving the identifiers from a web server that enables a user to specify access terminals that are allowed to receive at least one service from at least one access point; the set of access terminals is associated with a closed group of common subscribers; each access point of at least one access point is restricted so as not to provide, at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; each access point of at least one access point comprises a femto node or a pico-node; each access point of at least one access point provides at least one other service to at least one other access terminal.
Likewise, in view of what was said earlier, in some respects, a fourth method of communication comprises: receiving a message referring to a request by an access terminal to access an access point, the message comprising a first identifier associated with the access terminal; determining a second identifier associated with the access terminal based on the first identifier; and determine
78/90 whether the access terminal is allowed to receive the access point based on the second identifier and at least one identifier associated with the access point. In addition, in some respects, at least one of the elements mentioned below can also apply to the fourth method of communication: the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier; the second identifier comprises a network address identity of the access terminal or a digital network number of services integrated with the mobile station of the access terminal; the second identifier identifies at least one closed group of subscribers that the access terminal can access, and the at least one identifier associated with the access point comprises a closed group identifier of subscribers associated with the access point; the at least one identifier associated with the access point comprises an access list for the access point and the determination of whether the access terminal is allowed to receive the service from the access point which comprises determining whether the second identifier is in the list access; a network node determines whether the access terminal is allowed to receive the service from the access point, the message comprises the request from an access point to authenticate the access terminal, and the method also comprises sending , to the access point, a message indicating whether the access terminal is allowed to receive the service from the access point; determining the second identifier comprises sending the first identifier to a network node and receiving the second identifier from the network node; the access point determines whether the access terminal is allowed to receive the service from the access point
79/90 access; and at least one identifier associated with the access point is received from a network node; determining whether the access terminal is allowed to receive service from the access point comprises: sending the second identifier and at least one identifier associated with the access point to a network node, and receiving from the network node , an indication of whether the access terminal is allowed to receive service from the access point; determining whether the access terminal is allowed to receive the service from the access point comprises: sending the second identifier to a network node, and receiving at least one identifier associated with the access point from the network node; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
Likewise, in view of what was said earlier, in some respects, a fifth method of communication comprises: receiving a request from an access point for authentication of an access terminal; and send to the access point at least one identifier that identifies at least one set of
<td>points</td><td>access to</td><td>leave</td><td>of</td><td>which are</td><td colspan="2">if you allow</td><td>The</td>
<td colspan="2">terminal receive at</td><td>any less</td><td>one</td><td>served</td><td>ço. Beyond</td><td>of this,</td><td>in</td>
<td>some</td><td>aspects, at</td><td>any less</td><td>one</td><td>From</td><td>elements</td><td>cited</td><td>The</td>
<td>follow</td><td>can also</td><td colspan="3">apply to</td><td>fifth</td><td>method</td><td>in</td>
communication: the at least one identifier comprises a closed subscriber group identifier; the request comprises a network address identity of the access terminal or a digital network number of services integrated with the mobile station of the access terminal; it's the
The 80/90 method further comprises determining at least one identifier based on a permanent identifier associated with the access terminal, and determining the permanent identifier based on a temporary identifier associated with the access terminal; the request comprises the temporary identifier; determining the permanent identifier comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node; the method further comprises receiving at least one identifier from a network node; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
Likewise, in view of what was said earlier, in some aspects, a sixth method of communication comprises: sending, through an access point, a request for authentication of an access terminal; and receiving, in response to the request, at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. In addition, in some respects, at least one of the elements mentioned below may also apply to the sixth method of communication: the method also comprises determining whether the access terminal is allowed to receive service from the access point based on at least one identifier; the at least one identifier comprises a closed subscriber group identifier; the at least one identifier identifies a closed group of subscribers that the access terminal can access, and the determination comprises determining whether the at least one identifier is
81/90 compatible with a closed subscriber group identifier associated with the access point; the request is sent based on a determination that the access terminal is not listed in a local access list of the access point; the request comprises a network address identity of the access terminal or a digital network number of services integrated with the mobile station of the access terminal; the request comprises a temporary identifier associated with the access terminal; the method also comprises obtaining session information associated with the access terminal from a network node, where: the session information comprises context information for the access terminal and the request comprises the context information; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
Likewise, in view of what has been said previously, in some respects, a seventh method of communication comprises: sending, through an access point, a request comprising an identifier from a set of at least one suitable access terminal to receive service from the access point; and receiving, in response to the request, a list of at least one access terminal authorized to receive service from the access point. In addition, in some respects at least one of the elements cited below may also apply to the seventh communication method: the method also comprises determining whether the access terminal is allowed to receive the service from the access point based on at least one identifier; the hair
82/90 minus one identifier comprises at least one closed group identifier of subscribers; the identifier comprises a list of at least one closed subscriber group identifier associated with the access terminal, and the determination comprises determining whether a closed subscriber group identifier associated with the access point is in the list; the request is sent based on a determination that the access terminal is not listed in a local access list of the access point; the request comprises a network address identity of the access terminal or a digital network number of services integrated with the mobile station of the access terminal; the request comprises a temporary identifier associated with the access terminal; the method also comprises obtaining the session information associated with the access terminal from a network node, where: the session information comprises context information for the access terminal, and the request comprises the context information; the access point is restricted so as not to provide at least one other access terminal with at least one of the groups that
<td>consist</td><td>in: signage,</td><td>access from</td><td colspan="2">Dice,</td><td>registration, and</td>
<td>service;</td><td colspan="2">the access point comprises</td><td>one</td><td>at the</td><td>femto or one</td>
<td>peak-knot.</td><td>Similarly,</td><td colspan="2">in view of</td><td>The</td><td>that was said</td>
previously, in some respects, an eighth method of communication comprises: receiving, from a first access point, an identifier of at least one other access point that an access terminal is qualified to access; and determine, based on the identifier, whether to allow access to at least one other access point. In addition, in some respects at least one of the elements mentioned below may also apply to the eighth method of
83/90 communication: the determination comprises showing a user's prompt in order to determine whether to allow access; the determination comprises displaying an indication of the identifier and receiving input from the user indicating whether access is permitted; the method also includes determining, based on the configuration information, whether access is automatically allowed or if access is allowed in response to a prompt; the method also includes maintaining a list of access points that the access terminal is able to access, and the determination is also based on the list; the method also includes maintaining a list of access points that a user has decided not to access, and the determination is also based on the list; the identifier comprises a network identifier; the identifier comprises an identifier of the closed group of subscribers; the identifier is received via an SMS message, an application protocol message, a radio link message, or a page; the identifier is received from a network node; each access point of at least one access point is restricted so as not to provide, at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; each access point of the at least one access point comprises a femto node or a pico-node.
Likewise, in view of what was said earlier, in some respects, a ninth method of communication comprises: configuring an access point to a boot mode; transmit a standard signal that comprises a standard configuration during boot mode; receiving a message from an access terminal in response to standard signaling; and send a preferred visitor list to the access terminal at
84/90 reply to the message. In addition, in some aspects at least one of the elements mentioned below can also apply to the ninth method of communication: the standard signaling that comprises the standard configuration transmitted in a first level Ed power, and the method also comprises configuring the access point to a different operational mode through which signals are transmitted at a second power level that is greater than the first power level; the first power level provides a smaller coverage area than that provided by the second power level; the standard configuration comprises a standard network identifier that is different from a network identifier used for a nonboot operational mode; the default setting specifies the default system and network identifiers for at least one access point of a top priority, and the preferred guest list specifies other network identifiers for at least one top priority access point; the standard signaling is transmitted on a standard frequency, and the preferred visitor list specifies another signaling frequency for the access point that is different from the standard frequency; the method also comprises defining the preferred visitor list based on another preferred visitor list associated with the access terminal; the method also comprises receiving the other preferred visitor list from the access terminal; the method also comprises receiving the other preferred visitor list from a network node; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and
85/90 service; the access point comprises a femto node or a pico-node.
Likewise, in view of what was said earlier, in some respects, a tenth method of communication comprises: monitoring, at an access terminal, for signaling based on a first preferential guest list that specifies a standard configuration; receive a signal that comprises the standard configuration from an access point as a result of monitoring; send a message to the access point in response to the signaling received; and receiving a second visiting list from the access point in response to the message, the second visiting list specifying a setting other than the default setting. In addition, in some respects at least one of the elements cited below may also apply to the tenth method of communication: the first preferred visitor list comprises a standard visiting list for starting operations, and the second preferred visitor list comprises a visiting list for non-boot operations; the standard configuration comprises a standard network identifier; the second preferred visitor list comprises another network identifier associated with the access point that is different from the standard network identifier; signaling is received at a standard frequency specified by the first preferred visitor list, and the second preferred visitor list specifies a carrier frequency for the access point that is different from the standard frequency; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access,
86/90 registration, and service; the access point comprises a femto node or a pico-node.
Likewise, in view of what was said earlier, in some respects an eleventh method of communication comprises: configuring an access point with a first identifier of an access terminal; obtaining a second access terminal identifier based on the first identifier; receive a message request access through the access terminal; and determine, at the access point, whether requested access is allowed based on the second identifier. In addition, in some respects, at least one of the elements cited below may also apply to the eleventh method of communication: the first identifier comprises a network address identity or a digital network number for services integrated with the mobile station; the second identifier comprises an electronic serial number or an international identity of the mobile subscriber; obtaining comprises: sending the first identifier to a network node, and receiving the second identifier from the network node as a result of sending the first identifier; the determination comprises comparing an identifier received through the message from the access terminal with the second identifier; the determination comprises: sending the second identifier to a network node, and receiving, as a result of sending the second identifier, an indication as to whether the requested access is allowed; the access point is configured through a web interface; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
87/90
Likewise, in view of what was said earlier, in some respects a twelfth method of communication comprises: configuring an access terminal with a preferred visitor list that includes an identifier for a set of access points that are restricted to provide service to limited sets of access terminals; receive a signal from one of the access points, the signal comprising the identifier; send a message to an access point in response to signaling;
and receive authorization to access an access point in response to a message. In addition, in some respects at least one of the elements cited below may also apply to the twelfth method of communication: the set of access points comprises all access points in a cellular operator domain that are restricted in order to provide a service limited sets of access terminals; the identifier comprises a network identifier; the preferred visitor list specifies a carrier frequency for the set of access points;
the method also comprises showing a user's prompt in order to determine access to an access point;
The method also includes displaying an access point indication and receiving an indicative user input if an access point is accessed; the access terminal automatically determines whether it accesses an access point; each access point in the set of access points is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; each access point in the access point set comprises a femto node or a pico-node.
88/90
Likewise, in view of what was said earlier, in some respects a thirteenth method of communication comprises: receiving a request from an access point for authentication of an access terminal; determining whether the access terminal is allowed to receive service from the access point based on an identifier from a set of at least one access terminal that receives service from the access point; and send a message indicating the determination to the access point. In addition, in some respects at least one of the elements cited below can also apply to the thirteenth method of communication: the determination comprises determining whether the identifier is in an access list of the access point; the request comprises the access list; the identifier comprises a permanent identifier, the method further comprising determining the permanent identifier based on a temporary identifier from the set of at least one access terminal; determining the permanent identifier comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node; the identifier comprises a closed subscriber group identifier; the identifier comprises a list of at least one closed subscriber group identifier associated with the set of at least one access terminal, and the determination comprises determining whether a closed subscriber group identifier associated with the access point is in the list; the access point is restricted so as not to provide, for at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
89/90
Likewise, in view of what has been said previously, in some aspects, a fourteenth method of communication comprises: receiving, at an access point, a request for access from an access terminal, with the request for access comprises a first identifier associated with the access terminal; determining a second identifier associated with the access terminal based on the first identifier; and determining whether the access terminal is allowed to receive service from the access point based on the second identifier and a list of at least one access terminal authorized to receive service from the access point. In addition, in some respects at least one of the elements cited below may also apply to the fourteenth method of communication: the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier; the first identifier comprises a network address identity of the access terminal or a digital network number of services integrated with the mobile station of the access terminal; the list is received from a network node and comprises individual access terminal identifiers; the second identifier comprises a closed subscriber group identifier associated with the access terminal, and the list comprises a closed subscriber group identifier associated with the access point; the determination comprises: sending the second identifier and the list to a network node, and receiving, from the network node, an indication if the access terminal is allowed to receive the service from the access point; the determination comprises: sending the second identifier to a network node, and receiving the list from the network node; the access point is restricted so as not to provide, for
90/90 at least one other access terminal, at least one of the groups consisting of: signaling, data access, registration, and service; the access point comprises a femto node or a pico-node.
In some respects, a feature corresponding to one or more of the previous aspects of the first, second, third, fourth, fifth, sixth, seventh, eighth, ninth, tenth, eleventh, thirteenth, thirteenth and fourteenth may be applied communication methods, for example, on a device that uses the structure, as taught in this document. In addition, a computer program product may comprise code configured to cause a computer to provide functionality corresponding to one or more of the previous aspects of these communication methods.
The foregoing description of the disclosed aspects is provided in order to allow any person skilled in the art to make or use the present description. Various modifications of these aspects will become apparent to individuals skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the description. Therefore, it is not intended that the present description be limited to the aspects shown here, however, it should be in accordance with the broader scope in line with the unusual principles and resources described in this document.
1/16
Contents9
25 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25
103 members in 19 offices
Priority claims24
| Document | Office | Kind | Date |
|---|---|---|---|
| 60978363 | United States of America | – | |
| 97836307 | United States of America | P | |
| 97836307 | United States of America | P | |
| 2568608 | United States of America | P | |
| 2568608 | United States of America | P | |
| 61025686 | United States of America | – | |
| 61061537 | United States of America | – | |
| 6153708 | United States of America | P | |
| 6153708 | United States of America | P | |
| 12246383 | United States of America | – | |
| 24638308 | United States of America | A | |
| 24638308 | United States of America | A | |
| 2008079112 | United States of America | W | |
| 2008079112 | United States of America | W | |
| 12246383 | – | – | – |
| 60978363 | – | – | – |
| 61025686 | – | – | – |
| 61061537 | – | – | – |
| PCTUS2008079112 | – | – | – |
| US20070978363P | – | – | – |
| US20080025686P | – | – | – |
| US20080061537P | – | – | – |
| US20080246383 | – | – | – |
| WO2008US79112 | – | – | – |
Members103
| Document | Office | Kind | |
|---|---|---|---|
| US2009093232A1 | United States of America | A1 | |
| US2009094351A1 | United States of America | A1 | |
| US2009094680A1 | United States of America | A1 | |
| AU2008311002A1 | Australia | A1 | |
| AU2008311003A1 | Australia | A1 | |
| AU2008311004A1 | Australia | A1 | |
| CA2701906A1 | Canada | A1 | |
| CA2701924A1 | Canada | A1 | |
| CA2701961A1 | Canada | A1 | |
| CA2881157A1 | Canada | A1 | |
| WO2009048887A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009048888A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048889A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048888A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200932007A | Taiwan Province of China | A | |
| TW200932008A | Taiwan Province of China | A | |
| TW200935930A | Taiwan Province of China | A | |
| WO2009048889A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2198585A2 | European Patent Office (EPO) | A2 | |
| EP2198586A1 | European Patent Office (EPO) | A1 | |
| EP2198653A2 | European Patent Office (EPO) | A2 | |
| MX2010003753A | Mexico | A | |
| MX2010003754A | Mexico | A | |
| KR20100075627A | Republic of Korea | A | |
| KR20100075628A | Republic of Korea | A | |
| MX2010003752A | Mexico | A | |
| KR20100085095A | Republic of Korea | A | |
| CN101889419A | China | A | |
| CN101889420A | China | A | |
| CN101889464A | China | A | |
| IL204864D0 | Israel | D0 | |
| IL204870D0 | Israel | D0 | |
| IL204871D0 | Israel | D0 | |
| JP2010541514A | Japan | A | |
| JP2010541515A | Japan | A | |
| EP2273755A1 | European Patent Office (EPO) | A1 | |
| EP2273824A2 | European Patent Office (EPO) | A2 | |
| JP2011501917A | Japan | A | |
| RU2010118312A | Russian Federation | A | |
| RU2010118488A | Russian Federation | A | |
| RU2010118515A | Russian Federation | A | |
| AU2008311004B2 | Australia | B2 | |
| UA97019C2 | Ukraine | C2 | |
| HK1150482A1 | Hong Kong, China | A1 | |
| KR20120002611A | Republic of Korea | A | |
| KR20120003957A | Republic of Korea | A | |
| KR20120004534A | Republic of Korea | A | |
| UA97552C2 | Ukraine | C2 | |
| RU2459374C2 | Russian Federation | C2 | |
| SG185280A1 | Singapore | A1 | |
| SG185282A1 | Singapore | A1 | |
| KR101216086B1 | Republic of Korea | B1 | |
| AU2008311003B2 | Australia | B2 | |
| KR20130008627A | Republic of Korea | A | |
| KR20130016405A | Republic of Korea | A | |
| RU2475991C2 | Russian Federation | C2 | |
| TWI391009B | Taiwan Province of China | B | |
| UA101337C2 | Ukraine | C2 | |
| KR101261347B1 | Republic of Korea | B1 | |
| RU2488238C2 | Russian Federation | C2 | |
| CN101889420B | China | B | |
| KR101290186B1 | Republic of Korea | B1 | |
| JP5248617B2 | Japan | B2 | |
| JP2013153485A | Japan | A | |
| EP2273824A3 | European Patent Office (EPO) | A3 | |
| JP5290303B2 | Japan | B2 | |
| KR101327456B1 | Republic of Korea | B1 | |
| TWI415492B | Taiwan Province of China | B | |
| JP2014014122A | Japan | A | |
| KR101385612B1 | Republic of Korea | B1 | |
| KR101410371B1 | Republic of Korea | B1 | |
| MY152239A | Malaysia | A | |
| TWI454110B | Taiwan Province of China | B | |
| JP5623283B2 | Japan | B2 | |
| BRPI0818612A2 | Brazil | A2 | |
| BRPI0818609A2This record | Brazil | A2 | |
| BRPI0818611A2 | Brazil | A2 | |
| US9055511B2 | United States of America | B2 | |
| IL204871A | Israel | A | |
| US9167505B2 | United States of America | B2 | |
| IL204864A | Israel | A | |
| EP2273755B1 | European Patent Office (EPO) | B1 | |
| CA2701906C | Canada | C | |
| ES2608454T3 | Spain | T3 | |
| EP2198585B1 | European Patent Office (EPO) | B1 | |
| HUE029844T2 | Hungary | T2 | |
| CN107027119A | China | A | |
| ES2633107T3 | Spain | T3 | |
| CN107196923A | China | A | |
| US9775096B2 | United States of America | B2 | |
| HUE032328T2 | Hungary | T2 | |
| CA2881157C | Canada | C | |
| CA2701961C | Canada | C | |
| MY164923A | Malaysia | A | |
| CA2701924C | Canada | C | |
| EP2198653B1 | European Patent Office (EPO) | B1 | |
| EP2198586B1 | European Patent Office (EPO) | B1 | |
| EP2273824B1 | European Patent Office (EPO) | B1 | |
| MY172831A | Malaysia | A | |
| BRPI0818611B1 | Brazil | B1 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent or certificate of addition of invention grantedGrantedB16A | B16A | |
| Decision: intention to grantB09A | B09A |
Numbers
- Publication
- PI0818609-0
- Publication, DOCDB
- PI0818609
- Publication, EPODOC
- BRPI0818609
- Application
- 18609
- Application, DOCDB
- PI0818609
- Application, EPODOC
- BR2008PI18609
Titles2
- Portuguese
- GERENCIAMENTO DE ACESSO PARA COMUNICAÇÃO SEM FIO
- English
- WIRELESS COMMUNICATION ACCESS MANAGEMENT
Classification
- CPC, 10
- H04L63/104
- H04W12/06
- H04W48/08
- H04W8/26
- H04W12/08
- H04W48/02
- H04W48/14
- H04W84/045
- H04W12/062
- H04W4/08
- IPC, 2
- H04L29 06
- H04W12 08
