Transitive authentication authorization accounting in interworking between access networks
Abstract
A method and system for allowing a user equipment (240) that has been authenticated by a first communication network to obtain access to a second communication network without being authenticated by the second communication network. There is a pre-established trust relationship between the first communication network and the second communication network. The second network receives packets from the user equipment (240) including the user equipment public key via the first network (210). When the source Internet Protocol (IP) address associated with the packet falls within the range assigned to the first network (210), the session key is sent from the second network (220) to the user equipment ( 240). Encrypt the session key with the public key of the user device. The user equipment uses the private key to decrypt the session key, and then uses the session key to access the second network (220). It also generates a mapping that correlates the identity of the user equipment (240) with the session key, so that the second communication network generates usage data related to the user equipment (240) and transmits it to the first communication network, which generates a specific user equipment (240) Access to the accounting information of the second communication network.

Term
Term ended
Projected expiry passed 12 March 2023, 3.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 4 independent, 16 dependent
- 1一种用于允许用户设备获得对无线LAN的访问权的方法,包括以下步骤:经由第二通信网络从用户设备接收包括用户设备公钥的登记消息,所述第二通信网络已认证过所述用户设备,所述无线LAN与所述第二通信网络具有预先建立的信任关系;以及确定从所述第二通信网络接收的源IP地址是否在IP源地址的预定范围内,而且如果在该范围内,产生会话密钥来响应所述用户设备公钥,所述会话密钥适合利用用户设备私钥进行解密,将所述会话密钥传送给所述第二通信网络,以及允许所述用户设备利用所述会话密钥获得对所述通信网络的访问权。
- 2如权利要求1所述的方法,其特征在于,所述第二通信网络包括蜂窝网络,并且还包括在所述无线LAN和所述蜂窝网络之间建立安全IP信道的步骤。
- 3如权利要求1所述的方法,其特征在于还包括接收与所述用户设备相关联的接口的地址以及登记所述地址和所述会话密钥之间的映射的步骤。
- 4如权利要求3所述的方法,其特征在于,所述地址包括媒体接入控制(MAC)地址和因特网协议(IP)地址其中之一。
- 5如权利要求3所述的方法,其特征在于还包括以下步骤:由所述用户设备产生使用数据来响应对所述通信网络的访问,以及将所述使用数据传送给所述第二通信网络,从而可响应所述使用数据而产生用于所述用户设备的记帐信息。
- 6一种无线LAN,包括:用于与用户设备通信的第一装置;用于与通信网络通信的第二装置;连接到所述第二通信装置的装置,用于接收包括用户设备公钥的登记消息,以便确定与所述登记消息相关联的源IP地址是否在预定的源IP地址的范围内;以及连接到所述确定装置和所述通信装置的装置,用于如果所述源IP地址在所述范围之内,则产生利用所述用户设备公钥加密的会话密钥,并且经由所述通信装置将所述会话密钥传送给所述用户设备,其中,所述第一通信装置允许用户设备利用所述会话密钥来访问所述无线LAN。
- 7如权利要求6所述的无线LAN,其特征在于还包括用于将与所述用户设备相关联的接口地址与所述会话密钥相映射的存储器装置,以及用于产生使用数据来响应所述无线LAN的用户设备访问和用于将所述使用数据传送给所述通信网络的装置。
- 8一种利用用户设备访问无线LAN的方法,包括以下步骤:建立与第一通信网络的通信以及执行所述第一通信网络的认证步骤;将包括用户设备公钥的登记消息传送给所述第一通信网络;从所述第一通信网络接收从所述无线LAN接收的会话密钥;以及利用私钥对所述会话密钥进行解密;以及利用所述会话密钥建立对所述无线LAN的访问。
- 9如权利要求8所述的方法,其特征在于,所述第一通信网络是蜂窝网络。
- 10如权利要求8所述的方法,其特征在于,所述登记消息包括用于与所述无线LAN通信的接口的相关地址,从而可产生对于所述地址和所述会话密钥的映射。
- 11如权利要求10所述的方法,其特征在于,所述地址包括媒体接入控制(MAC)地址和因特网协议(IP)地址其中之一。
- 12如权利要求11所述的方法,其特征在于还包括以下步骤:接收关于所述用户设备经由所述无线LAN或所述蜂窝网络访问所述无线LAN的记帐信息。
- 13如权利要求8所述的方法,其特征在于还包括以下步骤:最初确定所述第一通信网络是否与所述无线LAN具有预先建立的信任关系。
- 14一种用于允许与第一通信网络进行通信的用户设备获得对第二通信网络的访问权的方法,所述第一通信网络和所述第二通信网络之间具有预先建立的信任关系,所述方法包括以下步骤:在所述第一通信网络内认证所述用户设备;从所述用户设备接收(310)包括用户设备公钥的登记消息;将包括所述用户设备公钥和落入分配给所述第一通信网络的预定范围的源地址的消息发送(310)给所述第二通信网络;从所述第二通信网络接收(320)会话密钥;以及将所述会话密钥传送(320)给所述用户设备,其中所述会话密钥允许所述用户设备获得对所述第二通信网络的访问权。
- 15如权利要求14所述的方法,其特征在于,所述第一通信网络包括蜂窝网络以及所述第二通信网络包括无线LAN网络。
- 16如权利要求15所述的方法,其特征在于还包括以下步骤:在所述第一通信网络和所述第二通信网络之间建立安全IP信道来防止非法截听所述会话密钥。
- 17如权利要求15所述的方法,其特征在于还包括以下步骤:接收与所述用户设备相关联的接口的地址以及登记所述接口与所述会话密钥之间的映射。
- 18如权利要求17所述的方法,其特征在于,所述接口的所述地址包括媒体接入控制(MAC)地址和因特网协议(IP)地址其中之一。
- 19如权利要求17所述的方法,其特征在于还包括以下步骤:从所述第二通信网络接收使用数据,指明所述第二通信网络的用户设备访问,并且根据所述使用数据产生与所述用户设备相关联的记帐信息。
- 20如权利要求15所述的方法,其特征在于,所述会话密钥利用所述用户设备公钥进行加密,并且适合利用用户设备私钥进行解密。
Independent claims20
34 paragraphs, as filed
Passable authentication, authorization and accounting in the interworking between access networks
FIELD OF THE INVENTION Generally speaking, the present invention relates to networking, and more specifically, to a method for transferable authentication, authorization, and accounting (AAA) in interworking between access networks.
BACKGROUND OF THE INVENTION Generally, authentication, authorization, and accounting (AAA) is required in order to access and utilize networks such as cellular networks and wireless local area networks (WLAN). In an environment where mobile terminals have multiple network access mechanisms, it is very important to provide AAA interworking between these networks. However, it is usually the case that one or more involved networks have a closed AAA scheme, and it is difficult for one network to use the AAA structure of the other network, and vice versa. For example, a cellular network has an AAA infrastructure that is incompatible with Internet-based AAA, and cannot be easily accessed through the Internet protocol, even if the network involved (including the cellular network) has external IP connectivity.
Conventional methods for providing AAA interworking all require special interworking functions between networks, even for AAA interworking between networks that have pre-established trust relationships between the networks themselves. Using this interworking function, for example, network B will then access the AAA infrastructure of network A to authenticate users who have been authenticated by network A (through a closed network AAA mechanism). The conventional method does not take advantage of the fact that network A and network B have established a trust relationship, and network A has authenticated the user.
Therefore, it is desirable and very advantageous to have a method of transferring the trust of one network to users from this network to another network, especially without any special interworking function to accomplish the same purpose.
SUMMARY OF THE INVENTION Through the present invention, that is, a method for transferring authentication, authorization and accounting (AAA) in the interworking between access networks, the above-mentioned problems and other related problems of the prior art are solved.
According to an aspect of the present invention, there is provided a method for allowing a user equipment that has been authenticated by a first network to obtain access to a second network. There is a pre-established trust relationship between the first network and the second network. A packet including the public key of the user equipment is received from the user equipment through the second network. When the source Internet Protocol (IP) address associated with the packet falls within the range allocated to the first network, the session key is sent from the second network to the user equipment. Encrypt the session key with the public key of the user device. The session key is used to permit the user equipment to access the second network.
These and other aspects, features and advantages of the present invention will become apparent by reading the following detailed description of the preferred embodiments in conjunction with the accompanying drawings.
BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied according to an illustrative embodiment of the present invention; FIG. 2 is a diagram illustrating a transferable AAA structure to which the present invention can be applied according to an illustrative embodiment of the present invention Block diagram; Figure 3 is a flowchart illustrating an AAA method for allowing a user equipment that has been authenticated by a 3G cellular network to obtain access to a wireless local area network WLAN according to an illustrative embodiment of the present invention; and Figure 4 is a flowchart illustrating the method according to the present invention An illustrative embodiment of the invention, a flowchart of a billing method for performing billing for a user of a user equipment of the method of FIG. 3.
Detailed description of the invention The present invention is directed to a transitive authentication, authorization and accounting (AAA) scheme for interworking between access networks. It can be understood that the present invention can be applied to any combination of access networks. However, the present invention is particularly suitable for interworking between a cellular network and a wireless local area network (WLAN).
The present invention transfers the trust of the user from the first access network to the second access network, wherein the first and second access networks have a pre-established trust relationship. Compared with the prior art, the present invention does not require any special interworking function between the two networks, but instead relies on IP addressing and routing schemes to verify user access rights. It can be understood that the present invention is also referred to herein as a deliverable AAA.
It can be understood that the present invention can be implemented in various forms of hardware, software, firmware, dedicated processors, or a combination thereof. The present invention is preferably implemented by a combination of hardware and software. Moreover, the software is preferably implemented as an application program that is definitely contained in a program storage device. The application program can be uploaded to and executed by a machine including any suitable architecture. The machine is preferably implemented on a computer platform with hardware such as one or more central processing units (CPU), random access memory (RAM), and input/output (I/O) interfaces. The computer platform also includes an operating system and microinstruction code. The various processes and functions described here may be part of the microinstruction code or part of the application program (or a combination thereof) executed via the operating system. Also, various other peripheral devices may be connected to computer platforms such as additional data storage devices and printing devices.
It should also be understood that, because some of the constituent system components and method steps illustrated in the drawings are best implemented by software, the actual connections between system components (or processing steps) may vary depending on the programming mode of the present invention. Given these teachings here, those of ordinary skill in the relevant fields can conceive of these and similar implementations or configurations of the present invention.
FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied according to an illustrative embodiment of the present invention. The computer processing system 100 includes at least one processor (CPU) 102 operatively connected to other components through a system bus 104. Read only memory (ROM) 106, random access memory (RAM) 108, display adapter 110, I/O adapter 112, user interface adapter 114, sound adapter 199, and network adapter 198 are operatively connected to system bus 104.
The display device 116 is effectively connected to the system bus 104 through the display adapter 110. A disk storage device (for example, a magnetic disk or an optical disk storage device) 118 is operatively connected to the system bus 104 through an I/O adapter 112. The mouse 120 and the keyboard 122 are operatively connected to the system bus 104 through the user interface adapter 114. The mouse 120 and the keyboard 122 are used to input information into and output from the system 100.
At least one speaker (hereinafter referred to as "speaker) 197 is operatively connected to the system bus 104 through a sound adapter 199.
The (digital and/or analog) modem 196 is operatively connected to the system bus 104 through a network adapter 198.
Fig. 2 is a block diagram illustrating a transitive AAA structure to which the present invention can be applied according to an illustrative embodiment of the present invention. In the illustrative embodiment of FIG. 2, the deliverable AAA structure includes: a first network 210; a second network 220; the Internet 230 and a user equipment 240. The second network 220 includes an AAA server 220a. The user equipment 240 includes a first network interface 240a and a second network interface 240b. It can be understood that although the present invention is described here for two networks, the present invention can be applied with any number and any type of networks while maintaining the essence and scope of the present invention.
To illustrate the present invention, the following description is made for two types of networks, namely 3G cellular network and wireless local area network (WLAN). However, it can be understood that the present invention can be applied to any number of networks and any types of networks in combination, while maintaining the essence and scope of the present invention.
In the illustrative example, user equipment 240 has a dual radio interface for accessing a 3G network and WLAN. According to the present invention, the user equipment 240 can access the WLAN 220 through the AAA mechanism of the 3G network 210 as follows. When detecting the WLAN 220, the user equipment 240 determines whether the WLAN 220 supports passable AAA. If supported, the user equipment 240 sends the registration message to the 3G network through the path 212. The registration message includes the user's public key. The registration message is transmitted to the WLAN server 230a via the Internet as indicated by the paths 216 and 222. When receiving the registration message, the WLAN server 230a checks the source IP address to determine whether the received address is within the address range supported by the deliverable AAA. If it is within this range, the WLAN server 230 provides the session key encrypted with the user equipment public key, and transmits the session key to the 3G network 210 via the Internet as indicated by the paths 224 and 218. The 3G network is as indicated by the path 214 Indicates that the session key is transmitted to the user equipment 240. The user equipment 240 then decrypts the session key using the user equipment private key, and can obtain access to the WLAN 220 using the session key.
In this way, the user equipment 240 can obtain access to the WLAN 220 through the AAA mechanism of the 3G network 210, as long as the WLAN 220 supports passable AAA and has a pre-existing trust relationship with the 3G network 210. By directly using the AAA mechanism of the 3G network, instead of making the WLAN contact 3G AAA authentication services or using the AAA mechanism associated with each WLAN, the present invention provides for allowing the user equipment 240 to communicate between WLANs that have a pre-existing relationship with the 3G network. Roaming mechanism.
A range of IP addresses is allocated for the 3G cellular network; when users use the 3G cellular network for IP access, the source IP address will fall into this range. Given the routing scheme of the Internet, any snooper can forge such a source IP address. When sending a return IP packet, only the user who actually has the IP address can receive the packet, unless the snooper can break in and forward the IP packet router. Therefore, the present invention can provide additional safety measures.
3 is a flowchart illustrating an AAA method for allowing a user equipment that has been authenticated by a 3G cellular network to obtain access to a wireless local area network WLAN according to an illustrative embodiment of the present invention. The user equipment has dual radio access interfaces (3G cellular and WLAN). There is a pre-established trust relationship between the 3G cellular network and the WLAN.
When the user equipment enters the area covered by the WLAN, it is determined (for example, through the WLAN interface of the user equipment) whether the WLAN supports passable AAA and whether the 3G cellular network has a pre-established trust relationship with the WLAN (for example, through broadcast or dynamic host configuration). Protocol (DHCP)) (step 302). If this is not the case, the method is terminated. Otherwise, as described below, step 304 is executed, and then the method proceeds to step 305. In step 305, the user equipment obtains the IP address of the AAA server of the WLAN (hereinafter referred to as WLAN AAA server) (step 305).
For example, through the 3G cellular interface of the user equipment, a User Datagram Protocol (UDP) packet including a registration message is sent from the user equipment to the WLAN AAA server (step 310). It can be understood that although step 310 is described in terms of UDP packets, any type of packet can be used, including but not limited to Transmission Control Protocol (TCP) packets. The registration message includes the WLAN address of the user equipment (for example, the media access control (MAC) address or IP address of the WLAN interface) and the public key of the user equipment.
Upon receiving the registration message, the WLAN AAA server determines whether the source IP address of the registration message (for example, the IP address of the 3G interface) falls within the range allocated to the 3G cellular network that has a pre-established relationship with the WLAN network (step 315). If it does not fall within the range, the method is terminated. Otherwise, the WLAN AAA server sends a confirmation message back to the 3G cellular interface of the user equipment (step 320). The confirmation message includes the session key used between the user equipment and the WLAN (the session key allows the user equipment to access the WLAN); the session key is encrypted with the public key of the user equipment. The WLAN AAA server also registers the mapping between the WLAN address of the user equipment and the (allocated) session key (step 325). Step 325 is performed so that the given session key is associated with the corresponding user.
When the confirmation message is received (for example, through the 3G cellular interface of the user equipment), the private key of the user equipment is used to decrypt the session key (step 328). Using the session key, the user equipment obtains access to the WLAN (step 330).
A description of possible cooperative hacking in the method of Figure 3 is now given. It can be understood that due to the use of IP addressing and IP routing without additional authentication support from the 3G cellular network, the following attacks are possible. The hacker sends a registration message with a pseudo IP address that falls within the range of the 3G cellular network. The hacker then intercepted the confirmation message somewhere along the route between the WLAN and the 3G cellular core network. The hacker informs another hacker in the WLAN coverage about the discovered key.
However, it is very difficult to implement the above attack, especially the step of intercepting the confirmation message. The hacker must gain access to the router along the path between the WLAN and the 3G network, just for the purpose of obtaining the session key, and the two hackers must cooperate to carry out the attack (assuming that a hacker within the coverage of the WLAN cannot gain access to the above discussion If the hacker can gain access, then since the hacker already has Internet access, there will be no problem of attacking).
In order to prevent the aforementioned cooperative hacker attack, step 304 is performed in the method of FIG. 3. In step 304, a secure IP channel (for example, an Internet Protocol (IP) security (IPSec) tunnel) is established between the WLAN AAA server and the gateway General Packet Radio Service (GPRS) of the 3G cellular network between the service/support node (GGSN). Because the path between the user and the GGSN of the 3G cellular network is also secure (because it is ensured by the security of the 3G network), the above attacks can be combated.
According to an illustrative embodiment of the present invention, a description is now given of a billing method that can be used with the method of FIG. 3. 4 is a flowchart illustrating a billing method for performing billing for a user of the user equipment of the method of FIG. 3 according to an illustrative embodiment of the present invention.
It is determined whether the IP address of the 3G cellular interface of the user equipment is a static IP address (step 405). If it is a static address, the user identity is determined according to the IP address of the 3G cellular interface (step 410), and the method proceeds to step 450. Otherwise (the IP address is dynamic), the user identity is determined from the mapping between the (temporary) IP address of the 3G cellular interface and the user's actual ID (step 415), and the method proceeds to step 450. In step 450, according to the IP address (static IP address) or mapping (dynamic IP address) of the 3G cellular interface, a billing step for the user is performed.
It can be understood that, for the purpose of the present invention, network address translation (NAT) is treated as if the IP address of a 3G cellular interface is dynamic. Furthermore, regarding the mappings mentioned in step 415 above, these mappings may be stored in, for example, a DHCP server, or if NAT is used, in a NAT server. It can also be understood that the present invention is not limited to the use of mapping to determine user identity in the case of non-static IP addresses, and therefore it is possible to use other methods while maintaining the essence and scope of the present invention.
Although illustrative embodiments have been described herein with reference to the accompanying drawings, it should be understood that the present invention is not limited to those exact embodiments, and those skilled in the art can carry out the present invention without departing from the scope or essence of the invention. Various other changes and modifications. All these changes and modifications must be included in the scope of the invention defined by the appended claims.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN114830704A | Cited by | China | Search report |
| CN105338524A | Cited by | China | Search report |
| WO2009049557A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN104079549A | Cited by | China | Search report |
| WO2011085566A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2017024662A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
19 members in 11 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 60376160 | United States of America | – | |
| 37616002 | United States of America | P | |
| 0307623 | United States of America | W |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| CA2482648A1 | Canada | A1 | |
| WO03092218A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003213852A1 | Australia | A1 | |
| KR20040102172A | Republic of Korea | A | |
| MXPA04010624A | Mexico | A | |
| EP1500223A1 | European Patent Office (EPO) | A1 | |
| BR0309523A | Brazil | A | |
| US2005154895A1 | United States of America | A1 | |
| CN1663168AThis record | China | A | |
| JP2006514447A | Japan | A | |
| US7721106B2 | United States of America | B2 | |
| CN1663168B | China | B | |
| EP1500223A4 | European Patent Office (EPO) | A4 | |
| MY142197A | Malaysia | A | |
| JP4583167B2 | Japan | B2 | |
| KR101013523B1 | Republic of Korea | B1 | |
| CA2482648C | Canada | C | |
| BRPI0309523B1 | Brazil | B1 | |
| EP1500223B1 | European Patent Office (EPO) | B1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Change in the address of a patent holderCP02 | CP02 | |
| Transfer of patent rightTR01 | TR01 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1663168
- Application
- 38142988
Titles2
- Chinese
- 接入网之间互配中可传递的认证、授权和记帐
- English
- Passable authentication, authorization and accounting in the interworking between access networks
Classification
- CPC, 23
- H04L63/06
- H04L63/18
- H04L9/32
- H04L63/0892
- H04W88/06
- H04W92/02
- H04L63/0435
- H04L63/0442
- H04L63/062
- H04L63/08
- H04L63/0884
- H04L63/101
- H04L2463/062
- H04W8/26
- H04W12/08
- H04W60/00
- H04W60/04
- H04W74/00
- H04W80/04
- H04W84/042
- H04W84/12
- H04W12/0431
- H04L9/00
- IPC, 15
- H04L9 32
- H04L12 28
- H04L29 06
- H04W8 26
- H04W12 04
- H04W12 06
- H04W12 08
- H04W60 00
- H04W60 04
- H04W74 00
- H04W80 04
- H04W84 04
- H04W84 12
- H04W88 06
- H04W92 02