Mobile terminal addressing procedure
Abstract
We use existing capacities, SIP protocol (126a), address translation (126d), short messages (126b), TCP (126c) to implement a resolution server (119) capable of dialoging with an extension (101). calling, a called mobile terminal (108) and a gateway 128 to be configured to establish a connection between the calling station and the mobile terminal via the Internet network (106). The resolution server accepts connection invitations, according to the SIP protocol. These invitations are transmitted, after resolution of the SIP address, to the mobile terminal in the form of a short message. The mobile terminal accepts or refuses the connection request. In the event of acceptance, the mobile terminal makes a request for allocation of communication means to the gateway. These allocated means are notified to the calling station via the resolution server.

Term
Term ended
Expired 10 July 2022, 4.2 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
15 claims: 1 independent, 14 dependent
- 1REVENDICATIONS 1. Procédé d'adressage d'un terminal mobile identifié par une première adresse symbolique, par les étapes suivantes :émission, depuis un poste appelant vers un serveur de résolution de la première adresse via un premier réseau, d'une demande d'établissement d'une connexion avec le terminal mobile;association, dans le serveur de résolution de la première adresse, de la première adresse symbolique à une entrée d'une table de résolution enregistrée dans une mémoire du serveur de résolution de la première adresse;extraction, de la table de résolution, d'une deuxième adresse du terminal mobile dans un deuxième réseau;émission d'un message d'invitation, depuis le serveur de résolution de la première adresse vers le terminal mobile via le deuxième réseau;réception, sur une passerelle de communication, d'une requête d'allocation de moyens de communication pour établir une connexion entre le poste appelant et le terminal mobile via la passerelle de communication;émission, depuis la passerelle de communication vers le serveur de résolution de la première adresse via un troisième réseau, d'une trame d'allocation de moyens comportant une description de moyens alloués;émission, depuis le serveur de résolution de la première adresse vers le poste appelant via le premier réseau, d'une trame de résultat de la demande d'établissement de connexion comportant une description des moyens alloués;et établissement d'une communication entre le poste appelant et le terminal mobile via la passerelle de communication en utilisant les moyens alloués.
- 2Le procédé selon la revendication 1, caractérisé en ce que la requête d'allocation est émise par un terminal distant via un quatrième réseau. CA 02393089 2004-07-06
- 3Le procédé selon la revendication 2, caractérisé en ce que le quatrième réseau est un réseau de téléphonie mobile supportant un GPRS.
- 4Le procédé selon la revendication 1, caractérisé en ce que la requête d'allocation est émise par le serveur de résolution de la première adresse via le troisième réseau.
- 5Le procédé selon la revendication 4, caractérisé en ce que la requête d'allocation est émise suite à une réception, par le serveur de résolution de la première adresse, d'un message d'acceptation, le message d'acceptation étant émis par le terminal mobile.
- 6Le procédé selon l'une quelconque des revendications 1 à 5, caractérisé en ce que le premier réseau est Internet utilisé en combinaison avec un protocole SIP (Protocole d'initialisation de Session).
- 7Le procédé selon l'une quelconque des revendications 1 à 6, caractérisé en ce que le deuxième réseau est un réseau de téléphonie mobile supportant des messages courts.
- 8Le procédé selon l'une quelconque des revendications 1 à 7, caractérisé en ce que le troisième réseau est Internet utilisé en combinaison avec l'un des protocole du groupe constitué de TCP et UDP et un protocole applicatif de type FCP (Protocole de Contrôle d'un Programme Pare-Feu).
- 9Le procédé selon l'une quelconque des revendications 1 à 8, caractérisé en ce que la demande d'établissement de connexion comporte des coordonnées du poste appelant. CA 02393089 2004-07-06
- 10Le procédé selon l'une quelconque des revendications 1 à 9, caractérisé en ce que les moyens alloués comportent une adresse Internet publique.
- 11Le procédé selon l'une quelconque des revendications 1 à 10, caractérisé en ce qu'en fin de communication entre le poste appelant et le terminal mobile, les moyens alloués sont libérés.
- 12Le procédé selon l'une quelconque des revendications 1 à 11, caractérisé en ce que le serveur de résolution de la première adresse est identifié par une adresse Internet publique.
- 13Le procédé selon l'une quelconque des revendications 1 à 12, caractérisé en ce que la passerelle de communication est identifiée par une adresse Internet publique.
- 14Le procédé selon l'une quelconque des revendications 10 à 13, caractérisé en ce que la trame d'allocation comporte un identifiant d'émetteur, une valeur de cet identifiant étant l'adresse Internet publique comportée par les moyens alloués.
- 15Le procédé selon l'une quelconque des revendications 1 à 14, caractérisé en ce que, à la réception de la trame d'allocation, le serveur de résolution de la première adresse met à jour la table de résolution en fonction des moyens alloués. CA 02393089 2002-07-10 1/2 ί 125 ί μΡ 127a 127b 127c 128v 190 119 106 126b 126c 126d 126- 120 INTERNET 109 Tsip SMS Ip pub FTP IMSI/MSISDN 105 102. 101 103a I r-·-CONNECT 110d FTP CONNECT S J 110 114 138 S. ? 127d 103b 1° 7 103 103c 128 νλ 132a 132a 132b 132b 132c. 132c 132 132 μ,Ρ 129 133b 133c 133d 133a / j ί ri /..d A/ A.IP priv A.IP pub A.IMSI/MSISDN port ί 1. 134
Independent claims15
263 paragraphs, as filed
CA 02393089 2002-07-10 1 Method for addressing a mobile terminal The present invention relates to a method for addressing a mobile terminal.
The field of the invention is that of mobile telephony considered in combination with that of the Internet.
An object of the invention is to make it possible to make incoming calls, in data mode (DATA), to mobile terminals of the GPRS and UMTS type.
Another object of the invention is to limit the possibilities of destructive attacks that can be carried out towards mobile terminals visible from the public Internet.
Yet another object is to allow a user to control which applications and entities outside the network can reach him in data mode.
Another aim is also to make it possible to reach a user not only on a single terminal, but on a known list of terminals belonging to him.
In the state of the art, in order to be able to reach a mobile terminal via Internet, it is necessary to be able to (identify by a global identifier, known from the public Internet. The mobile terminal must also be known in the Internet network, ie. that is, has an allocated public internet address.
The current solutions consist in simply using permanent public Internet addresses for mobiles, that is to say permanently allocated at the level of the public Internet, counting in practice on a rapid deployment of version 6 of the Internet protocol (IPV6 ).
Indeed, the number of public addresses available in version 4 of the Internet protocol (IPV4) is increasingly limited.
These addresses are allocated by three international offices, the RIR "Regional Internet Registries".
But in practice there are few IPV4 addresses left, and certainly an insufficient number with regard to the number of mobile terminals which will be connected in GPRS or UMTS mode.
It should be noted, however, that the deployment of IPV6 in the GPRS / UMTS infrastructure will have a significant cost.
The availability of this protocol is also uncertain, particularly at the terminals.
Finally, IPV6 only brings a low-level routing address solution. It remains to solve the problem of symbolic identification of the user, and not of his terminals, the problem of securing incoming connection requests, ie who can contact which terminal. There also remains the problem of the flexibility of the management of this security, ie is the user able to restrict access by third parties to his terminals.
Despite the limitations of IPV4, the number of users connected to the Internet has been able to grow thanks to address translation techniques (Network Address Translation NAT).
An Internet service provider (ISP, Internet Service Provider), or a company, can manage a set of private addresses in the network which is its own, these addresses being allocated in any way to the active terminals of the network, since no visible from public web.
These private addresses are dynamically matched, by the NAT equipment, with a public address.
Only a set of public addresses, corresponding to the maximum number of terminals that can be active at the same time, is then managed by the access provider or (company.
The problem with this solution is then that it is impossible to initiate a session to a terminal on the private network from a public Internet, since the public address which has been dynamically allocated to it is not known, nor especially published.
One possible solution to this addressing problem, which is beginning to be deployed in fixed data networks, is to set up dynamic DNS (Domain Name Server) servers, allowing the association to be published. between a machine name in FQDN (Full Qualified Domain Name) and its IP address, possibly dynamic.
This solution allows "inbound" addressing of a terminal. Other solutions are more specific to applications, such as instant messaging applications, where "client" software registers the terminal, and therefore the external public address that it has been dynamically allocated, with a server. external to the private network.
These solutions have a certain number of drawbacks, in particular, they do not take into account the specific features of mobile data networks, GPRS and UMTS.
Thus, the GPRS standard specifies that a terminal can be addressed in the "incoming" direction by the GGSN (Gateway GPRS Support Node), but this function will not necessarily be carried out in the first deployed versions of this equipment. .
In fact, unlike the terminals of fixed networks, a mobile terminal can be available for given sessions without having an allocated address in the GPRS network.
In this case, it is the GGSN which will contact the terminal and allocate (address, in a more general context, including QoS (Quality of Service, for quality of service) parameters, called the PDP context (Packet Description Protocol, that is, any packet network protocol for which GPRS offers compatibility). It should be noted that this address allocation policy corresponds in practice to a choice of the operator, with a dependence on the mechanisms implemented by the equipment manufacturers.
Current solutions also have drawbacks such as:
in the case of IPV4 addresses, not being able to cover general public needs, knowing that there are not enough addresses available for the fleet of mobile terminals, - in the case of IPV6 addresses, involving a complete infrastructure change, with a relatively long practical deployment horizon. It should also be noted that these two solutions provide direct visibility of the terminals from the public boarding school.
A clear danger is that of Denial of Service or DoS type attacks, i.e. service hijacking which could render the target terminals inoperative, - dynamic DNS type solutions only partially cover the needs of data networks mobile: a primary assumption is indeed that it is client software at the terminal level that registers with the external dynamic DNS server.
If the terminal is reachable, but does not have a Internat address at a given time (case of dynamic addressing management by GPRS), then it is not known to the DNS server even though if it is potentially reachable, typically through their phone number (MSISDN). It therefore lacks a generic notification mechanism both at the level of (Public boarding school to signal that a terminal belonging to Mr.
Dupont, or number 336xxxxxxxx, must be contacted to open an interactive games session on port P, and potentially between the GGSN gateway and the terminal, in the event that the latter does not in practice know how to initiate an incoming data connection to the terminal.
CA 02393089 2002-07-10 r 4 The invention solves these problems by associating a symbolic address with each mobile terminal.
Such an electronic address is, for example, described by the SIP protocol for Section Initiation Protocol.
The SIP protocol corresponds to RFC 2543.
In the invention, a station therefore sends a request to establish a connection, said request then comprises a symbolic address of a mobile terminal.
This request is addressed to a SIP address resolution server.
This SIP server manages an association table between the symbolic SIP address and the identifiers of the mobile telephone network, that is to say either an MSISDN telephone number (Mobile Station ISDN Number, that is to say telephone number) , or an IMSI number for International Mobile Subscriber Identity.
The resolution server therefore determines to which telephone number it must send a short message, or SMS for Short Message Service.
This short message is sent in transparent mode, that is to say that it will not be seen by the user and includes data indicating to the mobile terminal that a remote station wishes to establish a communication with it in given mode, for example via Internat.
But it can also be sent in non-transparent mode, which pem ~ et à (user to be notified of a request to open a session and to be able to validate it explicitly.
The SIM Toolkit application (STK, SIM with extended capabilities), triggered by the arrival of the SMS message (and its possible validation by the user in an interactivity process), then initiates a TCP session to a specified port of the server SIP resolution.
For reasons of flexibility and security, the IP address and port number information of the SIP server is sent in the SMS message, the overall content of which is signed by means of a private key by the SIP server.
This TCP session then allows the terminal to send a message allowing the SIP resolution server to associate a public internship address with the terminal.
The creation of this outgoing session involves, through standard GPRS mechanisms, the allocation of PDP context and of an IP address for the terminal.
This address is a private address of the GPRS data network.
The mechanics of address transformation. ~ CA 02393089 2002-07-10 compliant with the NAT function guarantees that when the TCP / IP packets from the tem ~ inal reach the SIP resolution server, located on the public Internet side, their IP address has been translated into a public address which corresponds to the private address internal to the GPRS network of the terminal.
Since the TCP / IP packets contain MSISDN / IMSI information, the resolving server can update the association table between the SIP, MSISDN / IMSI symbolic address and the allocated public IP address.
The resolution server then sends a message to the station wishing to establish a communication in data mode with the remote terminal.
The set then retrieves the public Internet address and can address itself, using an Internet protocol for example FTP, (File Transfer Protocol, for File Transfer Protocol) directly to the mobile terminal via an Internet connection.
The subject of the invention is a method for addressing a mobile terminal 15 identified by a first symbolic address during which:
- a request for establishing a connection with the mobile terminal is sent from a calling station to a resolution server for the first address via a first network, - associated, in the first symbolic address resolution server , the first symbolic address to an entry of a resolution table, recorded in a memory of the resolution server of the first address, - a second address of the mobile terminal in a second network is extracted from the resolution table, - an invitation message is sent from the server for resolving the first address to the mobile terminal via the second network, - we receive, on a communication gateway, a request for allocation of communication means to establish a connection between the calling station and the mobile terminal via the communication gateway, - one sends, from the communication gateway to the resolution server for the first address via a third network, a means allocation frame comprising a description of the allocated means, - the first address resolution server is sent to the calling station via the first network, a result frame of the connection establishment request comprising a description of the means - CA 02393089 2002-07-10 6 aIIOUéS, - A communication is established between the calling station and the mobile terminal via the communication gateway using the allocated means.
The invention will be better understood on reading the following description and on (examination of the figures which (accompany.
These are presented as an indication and in no way limit the invention.
The figures show - Figure 1: an illustration of means useful for implementing the method according to the invention.
- Figure 2: a step illustration of the method according to the invention.
It will be recalled that when, in the course of the description, an action is performed on a microprocessor or on an apparatus comprising a microprocessor, this action is performed by the microprocessor controlled by instruction codes recorded in a memory.
It is also recalled that a bus is a set of tracks or wires comprising these elements in sufficient number to convey address, data, command, clock and power supply signals.
Figure 1 shows a calling station 101.
The station 101 is for example a personal computer.
The station 101 comprises a microprocessor 102, a program memory 103, circuits 104 for interfacing with an Internet network 106, and a memory 105 in which the public Internet address of the station 101 is stored.
The elements 102 to 105 are connected via a bus 107. The interface 104 makes it possible to connect the station 101 to the Internet network 106.
The memory 103 comprises several areas, in particular an area 103A comprising instruction codes corresponding to the implementation of the SIP protocol, and an area 103B comprising instruction codes corresponding to the implementation of the FTP protocol.
In our example, it is in fact considered that the station 101 wishes to establish a link in given mode, according to the FTP protocol, with a mobile terminal 108.
To establish this connection, the memory 103 comprises an area 103C comprising the instruction codes corresponding to (establishment of this connection.
The instruction codes of zone 103C constitute a program which calls upon primitives, also called subroutines, of zones 103A and 1038.
This means that during the execution of the program of zone 103C, it calls upon primitives CA 02393089 2002-07-10 7 corresponding to (transmission or reception of a frame according to the SIP or FTP.
The public Internet address stored in the memory 105 guarantees that the station 101 is visible from the public Internet.
FIG. 1 shows that the terminal 108 comprises a microprocessor 109, a program memory 110, circuits 111 for interfacing with a mobile telephone network, a memory 112 for storing a private address, and a memory 113 for storing an IMSI number. and / or a telephone number.
The elements 109 to 113 are connected to each other by a bus 114.
The circuits 111 are on the other hand connected to an antenna 115 which makes it possible to transmit and receive radio signals 116 to or from a base station 117 of a cellular telephone network 118.
The memory 110 includes an area 110A corresponding to instruction codes for the implementation of the short message service.
An area 110B comprises instruction codes corresponding to the implementation of the GPRS mode.
An area 110C corresponds to instruction codes for the implementation of the FTP protocol.
An area 110D comprises instruction codes which correspond to the management of connection requests according to the invention.
These functionalities are, for example, available via a SIM Toolkit card comprising primitives for management, reception / sending of SMS, GPRS connection accessible from a program executed by the processor of the SIM card.
Such a card communicates with the terminal 108 by known means.
In our example, the circuits 111 correspond to the GSM standard which, used in association with the GPRS instruction codes of the zone 1108, makes it possible to obtain a terminal 108 compatible with most of the protocols used on the Internet.
However, in a variant of the invention, the circuits 111 can also operate according to the UMTS standard for example.
In this case, it is no longer necessary to implement the GPRS mode, because the UMTS standard provides for this type of operation.
The memory 112 makes it possible to record (address which is allocated to the terminal 108 when the latter makes a request for the allocation of a so-called PDP context. This is in fact, for the terminal 108, an activation of the operation. in GPRS mode.
Terminal 108 is then assigned a. CA 02393089 2002-07-10 address recorded in memory 112.
This address is, for example, a private IPV4 address.
It makes it possible to identify the terminal 108 in the GPRS network considered as a private network as opposed to the Internet network which is itself considered as a public network.
FIG. 1 also shows an address resolution server 119.
The connection of the SIP resolution server to the network is made, for example, via a TCPIIP or X.25 connection to the SMSC server (Short Message Service Center), and possibly via SS7 / TCAPIMAP for a connection , to the HLR of the GSM network, allowing access to presence information.
Indeed, it should be noted that there may be an interface between the SIP-NAT server and the HLR, which makes it possible to check the status of the terminal and, in the event that it is not attached to the GPRS network, to return a "not reachable" error message.
Figure 1 also shows means 120 to 123 GSM making it possible to connect, in a variant, the server 119 to the cellular network 118.
In practice, the means for connecting the server 119 to the network 118 allow the exchange of SMS messages between the server 119 and the terminal 108.
The server 119 also includes circuits 124 ~ interface with the Internet network 106.
The server 119 also includes a microprocessor 125, a program memory 126, and an association memory 127.
The elements 120 and 124 to 127 are connected to each other by a bus 128.
The memory 126 includes an area 126A corresponding to instruction codes for the implementation of the SIP protocol.
An area 126B comprises instruction codes corresponding to the implementation of a short message service, an area 126C corresponds to instruction codes for the implementation of the TCP (Transport Control Protocol, for controlled transport protocol), and a zone 126D corresponding to the implementation of part of the method according to the invention.
The instruction codes of the area 126D make use of the instruction codes of the areas 126A, 126B and 126C.
The resolution memory 127 is also referred to as a resolution table.
Indeed, the memory 127 is structured in rows and columns.
A column 127A corresponds to a symbolic address according to the SIP protocol.
A column 127B corresponds to an IMSI number and / or a telephone number.
A 127C column corresponds to a public Internet address.
CA 02393089 2002-07-10 9 A 127D column completes the 127C cotton by specifying a number of port numbers as defined by the IP protocol.
Each row of the association memory 127 con-espond to the allocation of means of communication via the Internet network to a mobile terminal identified by the value of column 1278.
Table 127 also makes it possible to perform an association between a symbolic address and a telephone number and an IMSI number.
The server 119 also includes an address memory 150 for recording a public Internet address via which the server 119 is visible on the Internet network.
FIG. 1 also shows a communication gateway 128.
Gateway 128 corresponds to a GGSN as defined in the work entitled Réseau GSM 5 ~ "'~ revised and augmented edition, published by Hermès and written by Xavier LAGRANGE, Philippe GODLEWSKI, and Sami TABANNE.
The description of the GGSN can be found in particular in chapter 14.3 of this book.
The gateway 128 includes a microprocessor 129, circuits 130 for interfacing with the GSM network 118; circuits 131 for interfacing with the Internet 106 network, a program memory 132, a memory 151 for recording a public Internet address of the gateway 128, a memory 133 for allocating communication means, and a memory 134 for controlling 'access.
Elements 129 through 134 are connected via a bus 135.
The memory 132 comprises an area 132A corresponding to instruction codes for the implementation of an address translation program (NAT), the area 1328 comprises instruction codes corresponding to the implementation of a firewall program , also known under the name of firewall, a 132C zone compiles instruction codes corresponding to the management of GPRS mode.
The gateway 128 also includes means for connecting and communicating with the cellular network 118.
These means are, for example purely GSM means.
The memory 133 is structured in a table.
The memory 133 comprises a column 133A corresponding to a private Internet address, a column 133B corresponding to a public Internet address, a column 133C corresponding to the identifier of the IMSI number or telephone number type, and a column 133D corresponding to telephone numbers. ports.
The table 133 CA 02393089 2002-07-10 makes it possible to associate means of communication with a mobile terminal identified by its IMSI number or its telephone number.
These means are on the one hand a public boarding school address visible from the public boarding school network, on the other hand a private boarding school address which makes it possible to identify the mobile terminal operating in GPRS mode on the cellular telephone network.
These means are optionally supplemented by a list of ports on which the mobile terminal can send and / or receive via the communication gateway 128.
These means are included in a PDP context.
Table 134 allows the firewall function of the gateway 128 to know which are the holders of public addresses which have the right to send messages via the gateway 128.
For example, the memory 128 includes a column 134A corresponding to a public internship address and a column 1348 describing the rights associated with this address.
The rights are for example a list of ports on which the holder of the public Internet address has the right to send messages.
FIG. 2 describes an implementation of the means which have just been described with FIG. 1.
FIG. 2 shows a preliminary step 201 executed by the calling station. Step 201 is a step for initiating communication.
During step 201, station 101 uses the SIP protocol to send a so-called invitation frame in this protocol.
Such a frame comprises an in-teta and a message body.
This header and body of messages are defined in RFC 2543.
This invitation frame corresponds to a connection establishment request. The header of this frame therefore includes a code identifying it as an invitation frame, and a symbolic address of the mobile terminal with which (user of set 101 wishes to establish the connection. The symbolic address is for example sip: termina1108 @ domain. fr.
The invitation frame also comprises the parameters according to which the user of the station 101 wishes to establish the connection, in our example these parameters are intended to establish a connection according to the FTP protocol.
The purpose of these parameters could very well be to use another protocol, for example HTTP, or to establish a voice communication or a videoconference.
The invitation frame is sent to the resolution server 119 via the Internet 106 network.
The station 101 is therefore aware of a CA 02393089 2002-07-10 11 public Internet address of the server 119, or of a symbolic address of this server, for example www. server119. Fr.
We go to a step 202 of receiving the connection establishment request by the resolution server 119.
In (step. 202, the server 119 extracts from the connection establishment request the symbolic identifier of the mobile terminal with which the calling station wishes to establish a connection.
The server 119 then searches the table 127 in search of this symbolic identifier, the latter being recorded in the column 127A.
Once the symbolic identifier has been found, the server 119 is able to determine whether the terminal is, or is not, accessible via the network 106 Internet. This determination is made by consulting the field 127C corresponding to the symbolic address.
If this field is filled in, this means that the mobile terminal is already accessible via a public Internet address and the Internet network 106, we then go from step 202 to step 203 of transmission of the connection parameters.
Otherwise, if the mobile terminal does not have a public Internet address, we go to a step 204 for transmitting the invitation to the mobile terminal.
In step 204, the server 219 constitutes a short message, or SMS.
This short message is sent to the mobile terminal 108, the telephone number of which is obtained by virtue of the value of the field 1278 corresponding to the symbolic address contained in the connection establishment request.
This short message contains the parameters of the connection that station 101 wishes to establish, as well as an identifier of the user of station 101.
We go to a step 205 of receiving (invitation by the mobile terminal 108.
In step 205, the short invitation message is read by the terminal 108.
We go to a step 206 whether or not to accept (invitation.
In (step 206, the terminal 108 presents its user with an invitation to establish a connection. The user can then use a keyboard of the terminal 108 to decide whether or not he wishes to accept the invitation.
The invitation message is presented on a screen of the terminal 108 and includes an identifier of the person wishing to establish the connection, and the parameters of the connection that this person wishes to establish.
If the user refuses the connection, we go to a step 207 where the terminal 108 composes a short message comprising an instruction code CA 02393089 2002-07-10 12 specifying that the terminal 108 does not wish to accept the connection.
The short message is then sent to the resolution server 119.
We go to step 208 of transmission of the refusal to set up the communication.
In (step 208, the server 119 transforms the short refusal message into an acknowledgment SIP frame.
This frame therefore includes an instruction code which indicates that the terminal 108 does not wish to establish the connection, this frame is transmitted to the calling station 101.
We go to step 209 of receiving a non-acknowledgment frame by the calling station.
In step 209, the calling station receives the frame according to the leaked SIP protocol specifying that the mobile terminal does not wish to establish the connection.
This ends the connection establishment procedure.
If in step 206 the user chooses to accept the invitation, we go to a step 210 of requesting a network connection.
In (step 210, the terminal 108 sends, to the communication channel 128, a request for allocation of means to establish a connection to the resolution sector 119 via the Internet network 106.
This request is made as defined, for example, in the GPRS standard.
This request includes information on the identity of station 101, as well as on the parameters of the connection which must be established. The identity information is, for example, the MSISDN number of the extension 101, the information on the parameters of the connection and, for example, the protocol which will be used, namely the FTP protocol.
In a variant of the invention, it is considered that the connection requests are systematically accepted by the terminal 108.
We therefore go directly from step 205 to step 210.
From step 210 we go to a step 211 of allocation of communication means by the communication gateway 128.
In step 211, the gateway 128 receives the resource allocation request sent by the terminal 108.
Following this request, the gateway 128 updates the table 133. That is to say, it assigns a public identifier of the terminal 108, for example its IMSI number or its telephone number (MSISDN), an address pair Private internet / public internet address. The private Internet address makes it possible to identify the terminal 108 on the GPRS network, the public Internet address makes it possible to identify the terminal 108 on the public Internet CA 02393089 2002-07-10 13 network.
Gateway 128 can also assign a port number for the connection that terminal 108 will establish.
Thus when the gateway 128 receives a message whose recipient is identified by an IP address and a port number, and that this IP address and this port number correspond to a public Internet address in table 133 then the gateway 128 will redirect this message to the terminal whose identifier is present in the line containing the public Internet address.
In step 211, the gateway 128 also updates the table 134.
In fact, the means allocation request message includes an identifier of the station 101.
The gateway 128 therefore inserts a row in the table 134, the public Internet address field of the table 134 will then correspond to the public Internet address of the station 101, and the field 134b will correspond to the port which has been allocated for the establishment of a connection with terminal 108.
The gateway 128 is thus able to filter the messages sent to the terminal 108 and thus avoid unwanted messages.
It is considered here that all the messages addressed to the gateway 128 whose senders are not registered in the table 134 are undesirable. This is a classic technique of filtering by a firewall, there are others which are not described here.
These means of communication being allocated, when the terminal 108 sends a message to the communication gateway, it is sent with the allocated private Internet address.
The gateway 128 then retransmits this message to the public Internet, on this public Internet network this message will be seen as having been sent from the public Internet address allocated by the gateway 128. This is a translation mechanism of addresses.
From step 211, we go to a step 212 of transmission of the connection parameters allocated to the server 119.
In this step 212, the gateway 128 constitutes a message, for example using the TCP protocol, the body of which comprises (allocated public Internet address, possibly the allocated port (s) and a public identifier of the terminal 108 (either its IMSI number or its number phone).
The field identifying the sender of this message has as its value the public Internet address which has been allocated.
This message is therefore in fact sent by the terminal 108 to the server 119 via the Internet network.
, CA 02393089 2002-07-10 14 In a variant of (invention, in step 206 when (user of terminal 108 accepts the connection request, we go to a connection request step 225, but this request is made by the server 119.
When accepting the invitation, the terminal 108 therefore sends a short acceptance message to the server 119.
This short acceptance message is received in (step 225.
In step 225 the server 119 then sends a request, for example by using the FCP protocol (Firewall Control Protocol, for the control protocol of a firewall program defined by the IETF in a publication by Jiri Kuthan and Jonathan Rosenberg), bound for footbridge 128.
This request comprises a field identifying the request as being a request for allocation of communication means, and a field identifying the terminal 108.
This request is transmitted via the network 106 Intemet.
The request is received by the gateway 128 and processed as for step 211.
~ In this variant (step 211 is followed by a step 226 for opening a connection in which the terminal 108 receives messages sent by the gateway 128 to notify it of the allocation of the means of communication.
In this variant, it is therefore the gateway 128 which takes the initiative and no longer the terminal 108.
From step 226 we go to step 212.
From (step 212, we go to step 203.
In step 203, the server 119 constitutes an acknowledgment message according to the SIP protocol.
The body of this message includes the public Internet address that has been allocated.
The message is sent to extension 101 via the 106 Internat network.
From step 203, we go to step 213 for the start of the session.
In step 213, the station 101 has just received the parameters allocated by the gateway 128 for establishing a connection with the terminal 108.
Extension 101 is therefore in possession of the public Internet address through which it can reach extension 108.
We then go to a step 214 of sending a frame by the station 101.
In step 214, the station 101 constitutes a frame according to the FTP protocol, the destination address of which is (public Internet address which has been allocated by the gateway 128.
The Internet network will route this frame to the gateway 128.
In step 215, the gateway 128 receives the frame in FTP format sent by the station 101.
In step 215, the gateway 128 extracts the frame that elf has just received (identifier of the sender of this frame.
If this identifier is present CA 02393089 2002-07-10 in table 134 then this frame will be transmitted further, otherwise it is rejected.
In the present case, this identifier is present since the table 134 was updated during step 211.
We go to a step 216 of receiving the frame by the mobile terminal 108.
In step 216, terminal 108 receives the frame which was sent by station 101.
This frame was then first received by the gateway 128 and then re-transmitted by this same gateway using the private IPV4 address allocated during step 211.
This private address corresponds, via table 133, to the public address used by station 101 to communicate with terminal 108.
10 We go to a step 217 in which the terminal 108 in turn transmits a frame according to the FTP protocol. the recipient of this frame is then the station 101 via its public Internet address.
This frame is transmitted. to the gateway 128 which receives it in step 218.
The gateway 218 then checks that the protocol used has been authorized thanks to the table 133 and to the identifier of the sender of this frame, namely the private Internet address of the terminal 108, this identifier making it possible to find the allocated rights. at terminal 108 in table 133.
At the end of step 218, the gateway 128 sends the frame, which was originally sent by the terminal 108, to the station 101.
In this frame, the field identifying the sender has the value of the private Internet address that was allocated during step 211 to the terminal 108.
In step 219 following step 218, terminal 108 receives the frame originally sent by terminal 108.
We go to a step 220 in which the station 101 determines whether it has received all the frames if it should receive, or whether it has sent all the frames it should send. If it has not yet received or sent all the frames, we go back to (step 214.
Otherwise, we go to a step 221 of interrupting the connection.
In (step 221, the station 101 sends, to the server 119, a SIP frame called BYE (goodbye).
This frame includes an identifier of the terminal 108.
We go to step 222 of receiving the SIP BYE frame by the server 119.
In step 222, the server 119 sends a short message to the mobile terminal informing it that the station 101 wishes to interrupt the communication.
This short interrupt message is received by the mobile terminal 108 in step 223.
The server 119 also updates the table 127, that is to say it erases the contents of the field of the columns 127c and 127d. _ CA 02393089 2002-07-10 16 corresponding to terminal 108.
During step 223, the mobile terminal 108 sends one or more messages, according to the GPRS protocol, to the communication gateway 128.
In step 224, the gateway 128 receives these messages.
In step 224, the gateway 128 is therefore informed of the interruption of the communication.
The gateway 128 therefore updates your tables 133 and 134.
This amounts to erasing, in the table 133 the line corresponding to the terminal 108, and in the table 134 the line corresponding to the station 101.
In the invention, the communications between the station 101 and the server 119 are carried out via the Internet network 106 using the SIP protocol (it is the first network) defined in RFC 2543.
The communications between the server 119 and the terminal 108 are carried out using short messages as defined, for example, in the GSM standard (this is the second network).
The communications between the terminal 108 and the communication gateway 128 are carried out according to the GPRS protocol (this is the third network).
The communications between the gateway 128 and the terminal 101 are carried out via the Internet network 106 according to a protocol specified during the allocation of the communication means.
The possible protocols are a priori all the protocols that can be used on the Internet 106 network.
Among these protocols we can mention TCP, UDP, FTP, HTTP and there are many others.
Communications between the gateway 128 and the server 119 are carried out via the Internet 106 network using the TCP protocol or the FCP protocol (this is the third network).
Insofar as the Internet network is used for a certain number of communications, it is possible to implement already existing encryption solutions.
One can for example use IP Secure, for Secure Internet, in which the body of Internet frames is encrypted so that their content is accessible only by the recipient of the frame.
The advantages of (infrastructure according to the invention are therefore as follows ,.
This infrastructure makes it possible to solve the problem of incoming addressing of mobile terminals immediately, and with existing equipment.
This solution makes it possible to rapidly deploy value-added services such as instant messaging in all its multimedia versions, mobile office notification services, etc.
In addition, CA 02393089 2002-07-10 17 standard protocols are used.
Insofar as a mobile terminal is not permanently visible from the public Internet network, and insofar as its public Internet address, when it exists, is not published, this limits the possibilities of destructive type attacks.
Another advantage is that this embodiment allows the user of the terminal 108 to decide which connection request he accepts and which connection request he refuses.
It is also noted that, in the variant where it is the terminal 108 which takes the initiative to establish the link with the gateway 128, there is no modification to be made to said gateway.
In fact, it is the terminal 108 which takes the initiative to send a message, via the Internet, to the server 119.
This message is transmitted in a standard manner to the IP address (that of the server 119) specified by the terminal.
This message includes the elements allowing the server 119 to interpret this message as a response from the terminal to the connection establishment request sent by the station 101.
In this case, the gateway 128 is only a known intermediary.
In the variant where the connection between the terminal 108 and the gateway 128 is opened on the initiative of the gateway 128, following the reception of a message from the server 119, this connection is established from an identifier of the terminal 108 , preferably an IMSI number or an MSISDN number.
The result of the opening of the connection, in particular the public IP address allocated to the terminal 108, is transmitted to the server 119.
This transmission is made either by the terminal 109 or by the gateway 128.
In this variant, the modifications to be made to the gateway are not significant.
In a variant of the invention, it is also possible to use SIP frames called option frames to specify the quality of the services and of the means which are allocated by the gateway 128.
Among the quality factors we can cite the bandwidth, that is to say the throughput, and the protocols that can be used.
These options are then requested by station 101 and accepted or downgraded by gateway 128 under the possible control of terminal 108.
In the invention, it is the user of the terminal who is contacted, and not just a given terminal, through his symbolic SIP address (for example, SIP: pierre.dupont@cegetel.fr).
Thus, it is possible to associate several mobile terminals with the user and to have the CA 02393089 2002-07-10 18 119 SIP server successively notify all the associated terminals until successfully finding the "active" one ( or desired active). The user can thus configure access filters making it possible to completely control the applications, sites or terminals outside the network which may contact his terminal.
In the invention, the SIP addresses can correspond to natural persons, as well as to a service, for example technical support, of a company.
Thanks to the invention, it is easy to establish, and at minimal cost, sessions from the public Internet to mobile terminals by deploying high value-added services such as instant messaging, multimedia services, notification. mobile office.
The implementation of the invention does not imply a complete upgrade of the infrastructure, as would be the case for IPV6.
This implementation is also compatible with the future deployment of IPV6, it only uses standard and existing protocols.
The deployment of the solution according to the invention can therefore be immediate both at the level of the infrastructure and at the level of the terminals. It is also not necessary to modify the terminals because the solution can be added to the terminals via a SIM toolkit card for example.
The invention makes it possible to manage the dynamic allocation and “de-allocation” of addresses by the use of local policies for managing the set of addresses at the level of the NAT function of the gateway 128, by allowing applications to control this policy in case of very intermittent traffic, etc.
The invention is also compatible with GPRS “roaming” (geographic roaming with possibly a change of operator), that is to say makes it possible to address active terminals in a visited mobile network that is a partner of the native network (the one to which the user is subscribed. user of terminal 108).
Likewise, the invention can be used in combination with a local traffic monitoring policy.
For example, in the case of "connectionless" protocols like UDP, there is no session establishment at the transport level, and a way to know if a connection should be left open or maybe, at the gateway level. 128, to monitor the traffic and to launch a “de-activation” procedure after a configurable time CA 02393089 2002-07-10 19 of inactivity.
In this case, the gateway 128 includes means for sending a “de-allocation” request to the server 119, which can then signal to the station 101 that a connection is closed.
The server 119 then sends a SIP BYE message to the extension 101.
If the station 101 responds with an SiP ACK message, the server 119 authorizes the gateway 128 to “de-allocate” your addresses as provided in step 224.
If the extension 101 responds with a new SIP “Invite” message, the server 119 does not authorize it.
A mobile terminal is, for example, a mobile telephone, a personal electronic assistant (PDA), or more generally any device provided with means of communication via a data network.
3 sheets
Sheet 1 Sheet 2 Sheet 3
10 members in 6 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 0109426 | France | – | |
| 0109426 | France | A | |
| 0109426 | – | – | – |
| FR20010009426 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| CA2393089A1 | Canada | A1 | |
| EP1276298A1 | European Patent Office (EPO) | A1 | |
| US2003013467A1 | United States of America | A1 | |
| FR2827465A1 | France | A1 | |
| CN1398095A | China | A | |
| JP2003110597A | Japan | A | |
| FR2827465B1 | France | B1 | |
| US6885871B2 | United States of America | B2 | |
| CA2393089CThis record | Canada | C | |
| JP4030373B2 | Japan | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| LapsedLapsedMKLA | MKLA | |
| Examination requestEEER | EEER |
Numbers
- Publication
- 2393089
- Publication, DOCDB
- 2393089
- Publication, EPODOC
- CA2393089
- Application
- 2393089
- Application, DOCDB
- 2393089
- Application, EPODOC
- CA20022393089
Titles2
- English
- MOBILE TERMINAL ADDRESSING PROCEDURE
- French
- PROCEDE D'ADRESSAGE D'UN TERMINAL MOBILE
Classification
- CPC, 10
- H04L12/2856
- H04L29/12094
- H04L29/125
- H04L61/1529
- H04L61/2564
- H04L63/029
- H04L63/0853
- H04L69/14
- H04W12/06
- H04W12/72
- IPC, 8
- H04L12 56
- H04L12 28
- H04L29 06
- H04W12 06
- H04W8 26
- H04L61 256
- H04L61 4505
- H04L69 14