EP1512260A1

Method and device for authenticating a subscriber for utilizing services in a wireless lan (wlan)

Abstract

An efficient authentication is made possible by a method for authenticating a subscriber MT (6) for utilizing services in a wireless LAN (WLAN) (10) while using an IP multimedia subsystem (IMS) (3). The inventive method is characterized in that a subscriber MT (6), who is to be authenticated and who is located at a location having WLAN coverage, receives an IP address from the WLAN (10) in an attributed manner, after which the subscriber authenticates himself with regard to the IP multimedia subsystem (3) while giving this IP address. In addition, an element ((WAGW (2)) of the WLAN (10) is informed of the result of the authentication of the subscriber MT (6) with regard to the IMS (3).

Term

Term ended

Projected expiry passed 7 June 2022, 4.3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

29 claims: 29 independent, 0 dependent

  1. 1
    Claims of equivalent WO 03105436 A1 Claims of equivalent WO 03105436 A1 Claims 1. Method for authenticating a subscriber MT (6) for the use of services in a wireless LAN (WLAN) (10) using an IP multimedia subsystem (IMS) (3), characterized in that a subscriber MT (6) to be authenticated, which is located in a location with WLAN coverage, is assigned an IP address by the WLAN (10), whereupon it authenticates itself to the IP multimedia subsystem (3) by specifying this IP address, wherein an element (WAGW (2)) of the WLAN (10) is informed of the result of the authentication of the subscriber MT (6) to the IMS (3). Patentansprüche 1. Verfahren zur Authentifizierung eines Teilnehmers MT (6) für die Inanspruchnahme von Diensten in einem Wireless LAN (WLAN) (10) unter Verwendung eines IP Multimedia Subsystems (IMS) (3), dadurch gekennzeichnet, dass ein zu authentifizierender Teilnehmer MT (6) , der sich an einem Ort mit WLAN-Abdeckung befindet, vom WLAN (10) eine IP-Adresse zugewiesen bekommt, worauf er sich gegenüber dem IP Multimedia Subsystem (3) unter Angabe dieser IP-Adresse authentifiziert, wobei ein Element (WAGW (2)) des WLAN (10) vom Ergebnis der Authentifizierung des Teilnehmers MT (6) gegenüber dem IMS (3) informiert wird.
  2. 2
    Verfahren nach Anspruch 1 dadurch gekennzeichnet, dass die Authentifizierung eines Teilnehmers MT (6) eines Wireless LAN (WLAN) unter Verwendung eines IP Multimedia Subsystems (IMS) (3) eines Mobilfunknetzes geschieht. 2nd Method according to claim 1, characterized in that the authentication of a subscriber MT (6) of a wireless LAN (WLAN) takes place using an IP multimedia subsystem (IMS) (3) of a mobile radio network.
  3. 3
    Verfahren nach einem der vorhergehenden Ansprüche dadurch gekennzeichnet, dass die Authenti izierung eines Teilnehmers MT (6) eines Wireless LAN (WLAN) (10) in einem IP Multimedia Subsystem (3) unter Verwendung eines Offline Home Subscriber System (HSS) (5) geschieht. 3rd Method according to one of the preceding claims, characterized in that the authentication of a subscriber MT (6) of a wireless LAN (WLAN) (10) takes place in an IP multimedia subsystem (3) using an offline home subscriber system (HSS) (5) .
  4. 4
    Verfahren nach einem der vorhergehenden Ansprüche dadurch gekennzeichnet, dass die Authentifizierung eines Teilnehmers MT (6) in einem Wireless LAN (WLAN) (10) in einem IP Multimedia Subsystem (3) unter Verwendung eines AuthentifizierungsServers (AAA Server) geschieht . 4th Method according to one of the preceding claims, characterized in that the authentication of a subscriber MT (6) in a wireless LAN (WLAN) (10) in an IP multimedia subsystem (3) takes place using an authentication server (AAA server).
  5. 5
    Method according to one of the preceding claims, characterized in that the keys (Ki) using the subscriber MT (6) authenticated in the mobile communication network are also used for authentication in the wireless LAN (WLAN) (10). 5. Verfahren nach einem der vorhergehenden Ansprüche dadurch gekennzeichnet, dass die Schlüssel (Ki) unter deren Nutzung sich der Teilnehmer MT (6) im mobilen Kommunikationsnetzwerk authentifziert auch zur Authentifizierung im Wireless LAN (WLAN) (10) verwendet werden.
  6. 6
    Method according to one of the preceding claims, characterized in that the subscriber MT (6) via the wireless LAN (10) sends a SIP register message to a device (CSCF) (4) of the IMS (3) which requests this to be authenticated Sends the IP multimedia subsystem (IMS) to the home subscriber system (HSS) (5) using the mechanisms provided for an IP multimedia subsystem (IMS) authentication, whereupon the home subscriber system (HSS) (5) authenticates the subscriber MT (6) using these mechanisms and communicates the result of the authentication to the wireless LAN access gateway (WAGW) (2). 6. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der Teilnehmer MT (6) über das Wireless LAN (10) eine SIP Register Nachricht an eine Einrichtung (CSCF) (4) des IMS (3) sendet, die eine Aufforderung zur Authentifizierung dieses IP Multimedia Subsystem (IMS) Teilnehmers unter Verwendung der für eine IP Multimedia Subsystem (IMS) - Authentifizierung vorgesehenen Mechanismen an das Home Subscriber System (HSS) (5) sendet, worauf das Home Subscriber System (HSS) (5) den Teilnehmer MT (6) unter Verwendung dieser Mechanismen authentifiziert und das Ergebnis der Authentifizierung dem Wireless LAN Access Gateway (WAGW) (2) mitteilt.
  7. 7
    Method according to one of the preceding claims, characterized in that an association between the subscriber terminal MT (6) and the wireless LAN (WLAN) for sending and receiving via the air interface between subscriber MT (6) and wireless LAN (WLAN) (10) (10) is carried out. 7. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeich et, dass zum Senden und Empfangen über die Luftschnittstelle zwischen Teilnehmer MT (6) und Wireless LAN (WLAN) (10) eine Assoziation zwischen dem Teilnehmerendgerät MT (6) und dem Wireless LAN (WLAN) (10) durchgeführt wird.
  8. 8
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Teilnehmerendgerät MT (6) eine IP Adresse aus dem Adressraum des Wireless LAN (10) erhält, mit der es, neben allen anderen IP-Transport basierten Daten, SIP Nachrichten senden und empfangen kann, die Authentifizierungsnachrichten von und zum IP Multimedia Subsystem (IMS) (3) transportieren. 8th. Method according to one of the preceding claims, characterized in that the subscriber terminal MT (6) receives an IP address from the address space of the wireless LAN (10) with which it can send and receive SIP messages, in addition to all other IP transport-based data that carry authentication messages to and from the IP Multimedia Subsystem (IMS) (3).
  9. 9
    Method according to one of the preceding claims, characterized in that access to services is controlled via a wireless LAN access gateway (WAGW) (2) which monitors the successful authentication in the IP multimedia subsystem (IMS) (3). 9. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der Zugang zu Diensten über ein Wireless LAN Access Gateway (WAGW) (2) kontrolliert wird, das die erfolgreiche Authentifizierung im IP Multimedia Subsystem (IMS) (3) überwacht .
  10. 10
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Wireless LAN (WLAN) (10) über eine Gi Schnittstelle mit dem IP Multimedia Subsystem (IMS) (3) verbunden wird. 10th Method according to one of the preceding claims, characterized in that the wireless LAN (WLAN) (10) is connected to the IP multimedia subsystem (IMS) (3) via a Gi interface.
  11. 11
    Method according to one of the preceding claims, characterized in that the wireless LAN (WLAN) (10) is connected to the IP multimedia subsystem (IMS) (3) via an Mm interface. 11. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Wireless LAN (WLAN) (10) über eine Mm Schnittstelle mit dem IP Multimedia Subsystem (IMS) (3) verbunden wird.
  12. 12
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Ergebnis der Authentifizierung dem Wireless LAN Access Gateway (WAGW) (2) durch eine P-CSCF (1) (Proxy-Call State Kontroll Funktion) /Policy Control Funktion an einem Ort mit WLAN-Abdeckung (Ho spot) zugeführt wird. 12th Method according to one of the preceding claims, characterized in that the result of the authentication of the wireless LAN access gateway (WAGW) (2) by a P-CSCF (1) (proxy call state control function) / policy control function in one place WLAN coverage (ho spot) is supplied.
  13. 13
    Method according to claim 9, characterized in that the wireless LAN (WLAN) (10) has a proxy call state control function node (P-CSCF) (1) which sends the SIP messages to the corresponding instance in the IP multimedia subsystem (SIP Request) and the WLAN access gateway (WAGW) (2) controls the authentication result (SIP response) of the IP multimedia subsystem (IMS) (3). 13. Verfahren nach Anspruch 9, dadurch gekennzeichnet, dass das Wireless LAN (WLAN) (10) einen Proxy-Call State Control Funktion Knoten (P-CSCF) (1) besitzt, der die SIP Nachrichten an die entsprechende Instanz im IP Multimedia Subsystem (SIP Anfrage) weiterleitet und das WLAN Access Gateway (WAGW) (2) hinsichtlich des Authentifizierungsergebnisses (SIP Antwort) des IP Multimedia Subsystem (IMS) (3) steuert.
  14. 14
    Method according to Claim 9, characterized in that instructions are given to the WLAN access gateway (WAGW) (2) on the basis of the result of the authentication in the IP multimedia subsystem (3) as to how the data traffic of a subscriber MT (6) through the WLAN access gateway ( WAGW) (2) is to be dealt with in particular instructions relating to the blocking of data traffic. 14. Verfahren nach Anspruch 9 , dadurch gekennzeichnet, dass dem WLAN Access Gateway (WAGW) (2) aufgrund des Ergebnisses der Authentifizierung im IP Multimedia Subsystems (3) Anweisungen gegeben werden, wie der Datenverkehr eines Teilnehmers MT (6) durch das WLAN Access Gateway (WAGW) (2) zu behandeln ist insbesondere Anweisungen betreffend das Blockieren des Datenverkehrs.
  15. 15
    Method according to one of the preceding claims, characterized in that the proxy call state control function (P-CSCF) (1) uses a policy control function to control the data traffic through the WLAN access gateway (WAGW) (2) and the quantity and or grants, limits, increases or rejects the quality of the data flow of a subscriber MT (6) through the WLAN access gateway (WAGW) (2). 15. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Proxy-Call State Control Funktion (P-CSCF) (1) mittels einer Policy Kontroll Funktion den Datenverkehr durch das WLAN Access Gateway (WAGW) (2) kontrolliert und die Quantität und oder die Qualität des Datenflusses eines Teilnehmers MT (6) durch das WLAN Access Gateway (WAGW) (2) gewährt, beschränkt, erhöht oder ablehnt.
  16. 16
    Method according to one of the preceding claims, characterized in that the policy control function is part of the proxy call state control function node (P-CSCF) (1) or is a separate unit. 16. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Policy Kontroll Funktion Bestandteil des Proxy-Call State Control Funktion Knoten (P-CSCF) (1) ist oder eine eigene Einheit darstellt.
  17. 17
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Ergebnis der Authentifizierung dem Wireless LAN Access Gateway (WAGW) (2) durch die CSCF (Call State Control Function) (4) /Policy Kontroll Funktion im IP Multimedia Subsystem (IMS) (3) zugeführt wird. 17th Method according to one of the preceding claims, characterized in that the result of the authentication to the wireless LAN access gateway (WAGW) (2) by the CSCF (Call State Control Function) (4) / policy control function in the IP multimedia subsystem (IMS) ( 3) is supplied.
  18. 18
    Verfahren nach Anspruch 14, dadurch gekennzeichnet, dass der Call State Control Funktion Knoten (CSCF) (4) des IP Multimedia Subsystem (3) .das WLAN Access Gateway (WAGW) (2) hinsichtlich des Authentifizierungsergebnisses des IP Multimedia Subsystems (3) steuert. 18th Method according to claim 14, characterized in that the call state control function node (CSCF) (4) of the IP multimedia subsystem (3) controls the WLAN access gateway (WAGW) (2) with regard to the authentication result of the IP multimedia subsystem (3) .
  19. 19
    Verfahren nach Anspruch 15, dadurch gekennzeichnet, dass die Proxy-Call State Control Funktion (P-CSCF) (1) mittels einer Policy Kontroll Funktion den Datenverkehr durch das WLAN Access Gateway (WAGW) (2) kontrolliert und die Quantität und oder die Qualität des Datenflusses eines Teilnehmers MT (6) durch das WLAN Access Gateway (WAGW) (2) gewährt, beschränkt, erhöht oder abgelehnt wird. 19th Method according to claim 15, characterized in that the proxy call state control function (P-CSCF) (1) controls the data traffic through the WLAN access gateway (WAGW) (2) and the quantity and or the quality by means of a policy control function the data flow of a subscriber MT (6) is granted, limited, increased or rejected by the WLAN access gateway (WAGW) (2).
  20. 20
    Method according to claim 15, characterized in that a Go interface between the call state control function node (CSCF) (4) of the IP multimedia subsystem (3) and the WLAN access gateway (WAGW) (2) is installed for secure data transmission. 20. Verfahren nach Anspruch 15, dadurch gekennzeichnet, dass eine Go Schnittstelle zwischen dem Call State Control Funktion Knoten (CSCF) (4) des IP Multimedia Subsystems (3) und dem WLAN Access Gateway (WAGW) (2) installiert wird für eine gesicherte Datenübertragung.
  21. 21
    Method according to one of the preceding claims, characterized in that the authentication result is evaluated by means of expanded functionalities in the wireless LAN access gateway (WAGW) (2). 21. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass durch erweiterte Funktionalitäten im Wireless LAN Access Gateway (WAGW) (2) das Authentifizierungsergebnis ausgewertet wird.
  22. 22
    Method according to Claim 18, characterized in that the authentication result obtained from the IP multimedia subsystem (IMS) (3) is implemented by the WLAN access gateway (2) by (2) allowing subscriber data to pass completely or to a limited extent. 22. Verfahren nach Anspruch 18, dadurch gekennzeichnet, dass das vom IP Multimedia Subsystem (IMS) (3) erhaltene Authentifizierungsergebnis vom WLAN Access Gateway (2) umgesetzt wird, indem es (2) Teilnehmerdaten vollständig oder eingeschränkt passieren lässt .
  23. 23
    A method according to claim 19, characterized in that the evaluation of the authentication result (SIP messages) is realized with an "Application Layer Gateway". 23. Verfahren nach Anspruch 19, dadurch gekennzeichnet, dass die Auswertung des Authentifizierungsergebnisses (SIP Nachrichten) mit einem „Application Layer Gateway" realisiert wird.
  24. 24
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der Teilnehmer MT (6) des Wireless LAN (WLAN) (10) auch ein Teilnehmer des mobilen Kommunikationsnetzwerks ist. 24th Method according to one of the preceding claims, characterized in that the subscriber MT (6) of the wireless LAN (WLAN) (10) is also a subscriber of the mobile communication network.
  25. 25
    Verfahren nach einem der vorhergehenden Ansprüche, dadurch geke nzeichnet, dass das Wireless LAN Netzwerk (WLAN) in mobile Kommunikationsnetzwerke mit Hilfe von ETSI HiperLan und IEEE 802.11 integriert wird. 25th Method according to one of the preceding claims, characterized in that the wireless LAN network (WLAN) is integrated into mobile communication networks using ETSI HiperLan and IEEE 802.11.
  26. 26
    Device for authenticating a subscriber MT (6) for the use of services in a wireless LAN (WLAN) (10) with the aid of an IP multimedia subsystem (IMS) (3), characterized in that a device proxy call state control function node ( 1) by means of the policy control function of an IP multimedia subsystem which is designed that an obtained authentication result is evaluated and thus the quantity and or the quality of the data flow through the WLAN access gateway (2) of a subscriber MT (6) is granted, restricted, increased or rejected. 26. Vorrichtung zur Authentifizierung eines Teilnehmers MT (6) für die Inanspruchnahme von Diensten in einem Wireless LAN (WLAN) (10) mit Hilfe eines IP Multimedia Subsystems (IMS) (3), dadurch gekennzeichnet, dass eine Einrichtung Proxy Call State Control Funktion Knoten (1) mittels der Policy Kontroll Funktion ein von einem IP Multimedia Subsystem die so ausgebildet ist, dass ein erhaltenes Authentifizierungsergebnis ausgewertet und damit die Quantität und oder die Qualität des Datenflusses durch das WLAN Access Gateway (2) eines Teilnehmers MT (6) gewährt, beschränkt, erhöht oder abgelehnt wird.
  27. 27
    27 Device according to claim 23, characterized in that the device proxy call state control function node (1) is a node in the WLAN (10). 27. Vorrichtung nach Anspruch 23, dadurch gekennzeichnet, dass die Einrichtung Proxy Call State Control Funktion Knoten (1) ein Knoten im WLAN (10) ist.
  28. 28
    28 Device according to one of the preceding claims, characterized in that the device proxy call control function node (1) of the IP multimedia subsystem (3) is provided for controlling the authentication in the WLAN (10). 28. Vorrichtung nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Einrichtung Proxy Call Control Funktion Knoten (1) des IP Multimedia Subsystems (3) für die Steuerung der Authentifizierung im WLAN (10) vorgesehen ist.
  29. 29
    Device according to one of the preceding claims, characterized in that the WLAN access gateway (2) has a device which is designed in such a way that it implements the authentication result which is obtained from the IP multimedia subsystem (3) by this device completely subscriber data or let it happen to a limited extent. 29. Vorrichtung nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das WLAN Access Gateway (2) eine Einrichtung besitzt, die so ausgebildet ist, dass sie das Authentifizierungsergebnis, welches vom IP Multimedia Subsystem (3) erhalten wird, umsetzt, indem diese Einrichtung Teilnehmerdaten vollständig oder eingeschränkt passieren lässt .
Independent claims29