Method and device for authenticating a subscriber for utilizing services in a wireless lan (wlan)
Abstract
An efficient authentication is made possible by a method for authenticating a subscriber MT (6) for utilizing services in a wireless LAN (WLAN) (10) while using an IP multimedia subsystem (IMS) (3). The inventive method is characterized in that a subscriber MT (6), who is to be authenticated and who is located at a location having WLAN coverage, receives an IP address from the WLAN (10) in an attributed manner, after which the subscriber authenticates himself with regard to the IP multimedia subsystem (3) while giving this IP address. In addition, an element ((WAGW (2)) of the WLAN (10) is informed of the result of the authentication of the subscriber MT (6) with regard to the IMS (3).

Term
Term ended
Expired 7 June 2022, 4.3 years ago.
- Priority and filed
- Granted
- Expired
- Today
26 claims: 26 independent, 0 dependent
- 1Method for authenticating a subscriber (MT,6) for utilising services in a wireless LAN (WLAN,10) while using an IP multimedia subsystem (IMS,3), characterised in that a subscriber (MT,6) who is to be authenticated and who is located at a location having WLAN coverage, receives an IP address from the (WLAN,10) in an attributed manner, after which the subscriber authenticates himself to the IP multimedia subsystem (IMS,3) while giving this IP address, whereby an element (WAGW,2) of the (WLAN,10) is informed of the result of the authentication of the subscriber (MT,6) with regard to the (IMS,3). Procédé pour l'authentification d'un abonné (MT, 6) pour l'utilisation de services dans un Wireless LAN (WLAN 10) avec l'emploi d'un sous-système IP multimedia (IMS, 3) d'un réseau de téléphonie mobile, caractérisé en ce que, un abonné (MT, 6) à authentifier, qui se trouve dans un endroit avec couverture Wireless LAN, reçoit une adresse IP attribuée du Wireless LAN (WLAN, 10), après quoi il s'identifie par rapport au sous-système IP multimedia (IMS, 3) en indiquant cette adresse IP au moyen de l'enregistrement SIP, un élément (WAGW, 2) du Wireless LAN (WLAN, 10) étant informé du résultat de l'authentification de l'abonné (MT, 6) par rapport au système multimédia (IMS, 3). Verfahren zur Authentifizierung eines Teilnehmers (MT,6) für die Inanspruchnahme von. Diensten in einem Wireless LAN (WLAN10) unter Verwendung eines IP Multimedia Subsystems (IMS,3) eines Mobilfunknetzes, dadurch gekennzeichnet,dass ein zu authentifizierender Teilnehmer (MT,6), der sich an einem Ort mit Wireless LAN-Abdeckung befindet, vom Wireless LAN (WLAN10) eine IP-Adresse zugewiesen bekommt, worauf er sich gegenüber dem IP Multimedia Subsystem (IMS,3) unter Angabe dieser IP-Adresse mittels SIP-Registrierung authentifiziert, wobei ein Element (WAGW,2) des Wireless LAN (WLAN,10) vom Ergebnis der Authentifizierung des Teilnehmers (MT, 6) gegenüber dem IP Multimedia System (IMS,3) informiert wird.
- 2Method according to claim 1, characterised in that a subscriber (MT,6) of a wireless LAN (WLAN,10) in an IP multimedia subsystem (IMS,3) is authenticated while using a home subscriber system (HSS,5). Procédé selon la revendication 1, caractérisé en ce que l'authentification d'un abonné (MT, 6) d'un Wireless LAN (WLAN, 10) s'effectue dans un sous-système IP multimedia (IMS, 3) avec l'utilisation d'un Home Subscriber System (HSS, 5). Verfahren nach Anspruch 1. dadurch gekennzeichnet,dass die Authentifizierung eines Teilnehmers (MT,6) eines Wireless LAN (WLAN,10) in einem IP Multimedia Subsystem (IMS, 3) unter Verwendung eines Home Subscriber System (HSS, 5) geschieht.
- 3Method according to one of the preceding claims, characterised in that a subscriber (MT,6) in a wireless LAN (WLAN,10) in an IP multimedia subsystem (IMS,3) is authenticated while using an authentication server (AAA server). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que l'authentification d'un abonné (MT, 6) dans un Wireless LAN (WLAN, 10) s'effectue dans un sous-système IP multimedia (IMS, 3) avec l'utilisation d'un server d'authentification (server AAA). Verfahren nach einem der vorhergehenden Ansprüche dadurch gekennzeichnet,dass die Authentifizierung eines Teilnehmers (MT,6) in einem Wireless LAN (WLAN, 10) in einem IP Multimedia Subsystem (IMS,3) unter Verwendung eines Authentifizierungsservers (AAA Server) geschieht.
- 4Method according to one of the preceding claims, characterised in that the subscriber (MT,6) transmits, via the wireless LAN (WLAN, 10), an SIP register message to a device (CSCF,4) of the IP multimedia system (IMS,3), which transmits a request for authentication of this IP multimedia subsystem (IMS,3) subscriber, using the mechanisms provided for an IP multimedia subsystem authentication, to the home subscriber system (HSS,5), after which the home subscriber system (HSS,5) authenticates the subscriber (MT,6) using these mechanisms and communicates the result of the authentication to the wireless LAN access gateway (WAGW,2). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que l'abonné (MT, 6) envoie par le Wireless LAN (WLAN, 10) un message de registre SIP à un appareil (CSCF, 4) du système SIP multimedia (IMS, 3) qui envoie une demande d'authentification de cet abonné du sous-système IP multimedia (IMS, 3) avec l'utilisation des mécanismes prévus pour une authentification du sous-système IP multimedia au Home Subscriber System (HSS, 5), après quoi le Home Subscriber System (HSS, 5) authentifie l'abonné (MT, 6) avec l'utilisation de ces mécanismes et communique le résultat de l'authentification à la Wireless LAN Access Gateway (WAGW, 2). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass der Teilnehmer (MT,6) über das Wireless LAN (WLAN, 10) eine SIP Register Nachricht an eine Einrichtung (CSCF, 4) des IP Multimedia Systems (IMS,3) sendet, die eine Aufforderung zur Authentifizierung dieses IP Multimedia Subsystem (IMS,3) Teilnehmers unter Verwendung der für eine IP Multimedia Subsystem-Authentifizierung vorgesehenen Mechanismen an das Home Subscriber System (HSS,5) sendet, worauf das Home Subscriber System (HSS, 5) den Teilnehmer (MT,6) unter Verwendung dieser Mechanismen authentifiziert und das Ergebnis der Authentifizierung dem Wireless LAN Access Gateway (WAGW,2) mitteilt.
- 5Method according to one of the preceding claims, characterised in that an association is implemented between the subscriber terminal (MT,6) and the wireless LAN (WLAN, 10) for the purpose of transmitting and receiving via the radio interface between subscriber (MT,6) and wireless LAN (WLAN, 10). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que, pour l'émission et la réception par l'interface radio entre l'abonné (MT, 6) et le Wireless LAN (WLAN, 10), on effectue une association entre le terminal d'abonné (MT, 6) et le Wireless LAN (WLAN , 10). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass zum Senden und Empfangen über die Luftschnittstelle zwischen Teilnehmer (MT,6) und Wireless LAN (WLAN,10) eine Assoziation zwischen dem Teilnehmerendgerät (MT,6) und dem Wireless LAN (WLAN,10) durchgeführt wird.
- 6Method according to one of the preceding claims, characterised in that the subscriber terminal (MT,6) receives an IP address from the address area of the wireless LAN (WLAN,10), with which - together with all other IP transport-based data - it can transmit and receive SIP messages that transport authentication messages from and to the IP multimedia subsystem (IMS,3). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le terminal d'abonné (MT, 6) reçoit une adresse IP provenant de la zone d'adresse du Wireless LAN (WLAN, 10) avec laquelle il peut envoyer et recevoir des messages SIP en plus de toutes les autres données basées sur le transport IP, qui transportent des messages d'authentification venant du sous-système IP multimedia (IMS, 3) et allant à ce système. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Teilnehmerendgerät (MT,6) eine IP Adresse aus dem Adressraum des Wireless LAN (WLAN,10) erhält, mit der es, neben allen anderen IP-Transport basierten Daten, SIP Nachrichten senden und empfangen kann, die Authentifizierungsnachrichten von und zum IP Multimedia Subsystem (IMS,3) transportieren.
- 7Method according to one of the preceding claims, characterised in that the access to services is controlled via a wireless LAN access gateway (WAGW,2), which monitors successful authentication in the IP multimedia subsystem (IMS,3). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que l'accès aux services est contrôlé par une Wireless LAN Access Gateway (WAGW, 2), qui contrôle l'authentification réussie dans le sous-système IP multimedia (IMS, 3). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass der Zugang zu Diensten über ein Wireless LAN Access Gateway (WAGW, 2) kontrolliert wird, das die erfolgreiche Authentifizierung im IP Multimedia Subsystem (IMS,3) überwacht.
- 8Method according to one of the preceding claims, characterised in that the wireless LAN (WLAN,10) is connected to the IP multimedia subsystem (IMS,3) via a Gi interface. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le Wireless LAN (WLAN, 10) est relié par une interface Gi au sous-système IP multimedia (IMS, 3). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Wireless LAN (WLAN,10) über eine Gi Schnittstelle mit dem IP Multimedia Subsystem (IMS,3) verbunden wird.
- 9Method according to one of the preceding claims, characterised in that the wireless LAN (WLAN,10) is connected to the IP multimedia subsystem (IMS,3) via an Mm interface. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le Wireless LAN (WLAN, 10) est relié par une interface Mm au sous-système IP multimedia (IMS, 3). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Wireless LAN (WLAN,10) über eine Mm Schnittstelle mit dem IP Multimedia Subsystem (IMS,3) verbunden wird.
- 10Method according to one of the preceding claims, characterised in that the result of the authentication (P-CSCF,1) is fed to the wireless LAN access gateway (WAGW,2) by a (proxy-call state control function)/policy control function (P-CSCF,1) at a location having wireless LAN coverage. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le résultat de l'authentification (P-CSCF, 1) est amené à la Wireless LAN Access Gateway (WAGW, 2) en un endroit avec couverture Wireless LAN par une fonction de contrôle Proxy-Call State/Fonction Policy Control (P-CSCF, 1). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Ergebnis der Authentifizierung (P-CSCF, 1) dem Wireless LAN Access Gateway (WAGW,2) durch eine (Proxy-Call State Kontroll Funktion)/Policy Control Funktion (P-CSCF, 1) an einem Ort mit Wireless LAN-Abdeckung zugeführt wird.
- 11Method according to claim 7, characterised in that the wireless LAN (WLAN,10) has a proxy-call state control function node (P-CSCF, 1) which forwards the SIP messages to the corresponding entity in the IP multimedia subsystem (IMS,3) and controls the WLAN access gateway (WAGW,2) with regard to the authentication result of the IP multimedia subsystem (IMS, 3). Procédé selon la revendication 7, caractérisé en ce que le Wireless LAN (WALN, 10) présente un noeud Proxy-Call State Fonction (P-CSCF, 1), qui transmet les messages SIP à l'instance correspondante dans le sous-système IP multimedia (IMS, 3) et commande la WLAN Access Gateway (WAGW, 2) en ce qui concerne le résultat de l'authentification du sous-système IP multimédia (IMS, 3). Verfahren nach Anspruch 7, dadurch gekennzeichnet,dass das Wireless LAN (WLAN,10) einen Proxy-Call State Control Funktion Knoten (P-CSCF, 1) besitzt, der die SIP Nachrichten an die entsprechende Instanz im IP Multimedia Subsystem (IMS,3) weiterleitet und das WLAN Access Gateway (WAGW, 2) hinsichtlich des Authentifizierungsergebnisses des IP Multimedia Subsystem (IMS,3) steuert.
- 12Method according to claim 7, characterised in that instructions are provided to the WLAN access gateway (WAGW,2) on the basis of the result of the authentication in the IP multimedia subsystem (IMS,3), as to how the data traffic of a subscriber (MT,6) is to be handled by the wireless LAN access gateway (WAGW,2), in particular instructions regarding the blocking of data traffic. Procédé selon la revendication 7, caractérisé en ce que des instructions sont données à la WLAN Access Gateway (WAGW, 2) sur la base du résultat de l'authentification dans le sous-système IP multimedia (IMS, 3) sur la façon dont le trafic de données d'un abonné (MT, 6) doit être traité par la Wireless LAN Access Gateway (WAGW, 2), en particulier des instructions concernant le blocage du trafic de données. Verfahren nach Anspruch 7, dadurch gekennzeichnet,dass dem WLAN Access Gateway (WAGW,2) aufgrund des Ergebnisses der Authentifizierung im IP Multimedia Subsystems (IMS, 3) Anweisungen gegeben werden, wie der Datenverkehr eines Teilnehmers (MT,6) durch das Wireless LAN Access Gateway (WAGW,2) zu behandeln ist insbesondere Anweisungen betreffend das Blockieren des Datenverkehrs.
- 13Method according to one of the preceding claims, characterised in that the proxy-call state control function (P-CSCF,1), by means of a policy control function, controls the data traffic through the wireless LAN access gateway (WAGW,2) and grants, restricts, increases or declines the quantity and/or quality of the data flow of a subscriber (MT,6) through the wireless LAN access gateway (WAGW,2). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que la fonction Proxy-Call State Control (P-CSCF, 1) contrôle au moyen d'une fonction Policy Control le trafic de données par la Wireless LAN Access Gateway (WAGW, 2) et garantit, diminue, augmente ou refuse la quantité et/ou la qualité du flux de données d'un abonné (MT, 6) par la Wireless LAN Access Gateway (WAGW, 2). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass die Proxy-Call State Control Funktion (P-CSCF, 1) mittels einer Policy Kontroll Funktion den Datenverkehr durch das Wireless LAN Access Gateway (WAGW,2) kontrolliert und die Quantität und oder die Qualität des Datenflusses eines Teilnehmers (MT,6) durch das Wireless LAN Access Gateway (WAGW,2) gewährt, beschränkt, erhöht oder ablehnt.
- 14Method according to one of the preceding claims, characterised in that the policy control function is part of the proxy-call state control function node (P-CSCF,1) or is a separate unit. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que la fonction Policy Control est un élément constituant du noeud Proxy-Call State Control Fonction (P-CSCF, 1) ou représente une unité propre. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass die Policy Kontroll Funktion Bestandteil des Proxy-Call State Control Funktion Knoten (P-CSCF, 1) ist oder eine eigene Einheit darstellt.
- 15Method according to one of the preceding claims, characterised in that the result of the authentication is fed to the wireless LAN access gateway (WAGW,2) by the call state control function (CSCF,4) /policy control function in the IP multimedia subsystem (IMS,3). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le résultat de l'authentification est amené à la Wireless LAN Access Gateway (WAGW, 2) par la Call State Control Fonction (CSCF, 4)/Policy Control Fonction) dans le sous-système IP multimedia (IMS, 3). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Ergebnis der Authentifizierung dem Wireless LAN Access Gateway (WAGW,2) durch die Call State Control Function (CSCF,4)/Policy Kontroll Funktion im IP Multimedia Subsystem (IMS, 3) zugeführt wird.
- 16Method according to claim 12, characterised in that the call state control function node (CSCF,4) of the IP multimedia subsystem (IMS,3) controls the wireless LAN access gateway (WAGW,2) with regard to the authentication result of the IP multimedia subsystem (IMS,3). Procédé selon la revendication 12, caractérisé en ce que le noeud Call State Control Fonction (CSCF, 4) du sous-système IP multimedia (IMS, 3) commande la Wireless LAN Access Gateway (WAGW, 2) en ce qui concerne le résultat de l'authentification du sous-système IP multimedia (IMS, 3). Verfahren nach Anspruch 12, dadurch gekennzeichnet,dass der Call State Control Funktion Knoten (CSCF,4) des IP Multimedia Subsystem (IMS,3) das Wireless LAN Access Gateway (WAGW,2) hinsichtlich des Authentifizierungsergebnisses des IP Multimedia Subsystems (IMS, 3) steuert.
- 17Method according to claim 13, characterised in that a Go interface is installed between the call state control function node (CSCF,4) of the IP multimedia subsystem (IMS,3) and the wireless LAN access gateway (WAGW,2), for protected data transfer. Procédé selon La revendication 13, caractérisé en ce que une interface Go est installée entre le noeud Call State Control Fonction (CSCF, 4) du sous-système IP multimedia (IMS, 3) et la Wireless LAN Access Gateway (WAGW, 2) pour une transmission de données sécurisée. Verfahren nach Anspruch 13, dadurch gekennzeichnet,dass eine Go Schnittstelle zwischen dem Call State Control Funktion Knoten (CSCF,4) des IP Multimedia Subsystems (IMS,3) und dem Wireless LAN Access Gateway (WAGW,2) installiert wird für eine gesicherte Datenübertragung.
- 18Method according to one of the preceding claims, characterised in that the authentication result is evaluated by expanded functionalities in the wireless LAN access gateway (WAGW, 2). Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le résultat de l'authentification est analysé par des fonctionnalités élargies dans la Wireless LAN Access Gateway (WAGW, 2). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass durch erweiterte Funktionalitäten im Wireless LAN Access Gateway (WAGW,2) das Authentifizierungsergebnis ausgewertet wird.
- 19Method according to claim 16, characterised in that the authentication result received from the IP multimedia subsystem (IMS,3) is converted by the wireless LAN access gateway (WAGW,2), whereby said WLAN access gateway (WAGW,2) allows subscriber data to pass through completely or with restrictions. Verfahren nach Anspruch 16, dadurch gekennzeichnet,dass das vom IP Multimedia Subsystem (IMS, 3) erhaltene Authentifizierungsergebnis vom Wireless LAN Access Gateway (WAGW, 2) umgesetzt wird, indem es (2) Teilnehmerdaten vollständig oder eingeschränkt passieren lässt. procédé selon la revendication 16, caractérisé en ce que le résultat de l'authentification reçu du sous-système IP multimedia (IMS, 3) est converti par la Wireless LAN Access Gateway (WAGW, 2) du fait qu'il (2)fait passer complètement ou de façon limitée des données d'abonnés.
- 20Method according to claim 13, characterised in that the evaluation of the authentication result is implemented using an "application layer gateway". Procédé selon la revendication 13, caractérisé en ce que l'analyse de résultat de l'authentification est réalisée avec une "Application Layer Gateway". Verfahren nach Anspruch 13, dadurch gekennzeichnet,dass die Auswertung des Authentifizierungsergebnisses mit einem "Application Layer Gateway" realisiert wird.
- 21Method according to one of the preceding claims, characterised in that the subscriber (MT,6) of the wireless LAN (WLAN,10) is also a subscriber of the mobile communication network. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que l'abonné (MT, 6) du Wireless LAN (WLAN, 10) est également un abonné du réseau de communication mobile. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass der Teilnehmer (MT,6) des Wireless LAN (WLAN,10) auch ein Teilnehmer des mobilen Kommunikationsnetzwerks ist.
- 22Method according to one of the preceding claims, characterised in that the wireless LAN network (WLAN,10) is integrated into mobile communication networks with the help of ETSI HiperLan and IEEE 802.11. Procédé selon l'une quelconque des revendications précédentes, caractérisé en ce que le Wireless LAN (WLAN, 10) est intégré dans des réseaux de communication mobiles à l'aide du ETSI HiperLan et IEEE 802.11. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet,dass das Wireless LAN (WLAN,10) in mobile Kommunikationsnetzwerke mit Hilfe von ETSI HiperLan und IEEE 802.11 integriert wird.
- 23Device for authenticating a subscriber (MT,6) for utilising services in a wireless LAN (WLAN,10) with the help of an IP multimedia subsystem (IMS,3) of a mobile radio network, characterised by- an IP multimedia system (IMS,3) for authenticating a subscriber (MT,6) who is to be authenticated by means of SIP registration, and who is located at a location having wireless LAN coverage, by giving an IP address allocated by the wireless LAN (WLAN,10), and- an IP multimedia subsystem (IMS,3) for informing an element (WAGW,2) of the wireless LAN (WLAN,10) of the result of the authentication of the subscriber (MT,6) with regard to the IP multimedia subsystem (IMS,3). Dispositif pour l'authentification d'un abonné (MT, 6) pour l'utilisation de services dans un Wireless LAN (WLAN, 10) à l'aide d'un sous-système IP multimedia (IMS, 3) d'un réseau de téléphonie mobile, caractérisé par- un sous-système IP multimedia (IMS, 3) pour l'authentification d'un abonné (MT, 6) à authentifier au moyen d'un enregistrement SIP, qui se trouve en un lieu avec une couverture Wireless LAN avec l'indication d'une adresse IP attribuée par le Wireless LAN (WLAN, 10),- un sous-système IP multimedia (IMS, 3) pour l'information d'un élément (WAGW, 2) du Wireless LAN (WLAN, 10) du résultat de l'authentification de l'abonné (MT, 6) par rapport au sous-système IP multimedia (IMS, 3). Vorrichtung zur Authentifizierung eines Teilnehmers (MT,6) für die Inanspruchnahme von Diensten in einem Wireless LAN (WLAN,10) mit Hilfe eines IP Multimedia Subsystems (IMS, 3) eines Mobilfunknetzes, gekennzeichnet durch- ein IP Multimedia Subsystem (IMS, 3) zum Authentifizieren eines zu authentifizierenden Teilnehmers (MT,6) mittels SIP-Registrierung, der sich an einem Ort mit Wireless LAN-Abdeckung befindet unter Angabe einer vom Wireless LAN (WLAN,10) zugewiesenen IP-Adresse,- ein IP Multimedia Subsystem (IMS,3) zum Informieren eines Elements (WAGW, 2) des Wireless LAN (WLAN, 10) vom Ergebnis der Authentifizierung des Teilnehmers (MT,6) gegenüber dem IP Multimedia Subsystem (IMS,3).
- 24Device according to claim 23, characterised in that a device constituting the proxy call state control function node (CSCF,1) is a node in the wireless LAN (WLAN,10). Dispositif selon la revendication 23, caractérisé en ce que un appareil noeud Proxy Call State Control Fonction (CSCF, 1) est un noeud dans le Wireless LAN (WLAN, 10). Vorrichtung nach Anspruch 23, dadurch gekennzeichnet,dass eine Einrichtung Proxy Call State Control Funktion Knoten (CSCF, 1) ein Knoten im Wireless LAN (WLAN10) ist.
- 25Device according to one of claims 23 to 24, characterised in that the device constituting the proxy call state control function node (CSCF, 1) of the IP multimedia subsystem (IMS,3) is provided for controlling authentication in the wireless LAN (WLAN,10). Dispositif selon l'une quelconque des revendications 23 à 24, caractérisé en ce que l'appareil noeud Proxy Call Control Fonction (CSCF, 1) du sous-système IP multimedia (IMS, 3) est prévu pour la commande de l'authentification dans le Wireless LAN (WLAN, 10). Vorrichtung nach einem der Ansprüche 23 bis 24, dadurch gekennzeichnet,dass die Einrichtung Proxy Call Control Funktion Knoten (CSCF, 1) des IP Multimedia Subsystems (IMS,3) für die Steuerung der Authentifizierung im Wireless LAN (WLAN10) vorgesehen ist.
- 26Device according to one of claims 23 to 25, characterised in that the wireless LAN access gateway (WAGW,2) has a device that is configured such that said device converts the authentication result which is received from the IP multimedia subsystem (IMS,3), by allowing subscriber data to pass through completely or with restrictions. Dispositif selon l'une quelconque des revendications 23 à 25, caractérisé en ce que le Wireless LAN Access Gateway (WAGW, 2) présente un appareil qui est conçu de telle sorte qu'il convertit le résultat d'authentification, qui est reçu du sous-système IP multimedia (IMS, 3) par le fait que cet appareil laisse passer complètement ou de façon limitée des données d'abonnés. Vorrichtung nach einem der Ansprüche 23 bis 25, dadurch gekennzeichnet,dass das Wireless LAN Access Gateway (WAGW,2) eine Einrichtung besitzt, die so ausgebildet ist, dass sie das Authentifizierungsergebnis, welches vom IP Multimedia Subsystem (IMS,3) erhalten wird, umsetzt, indem diese Einrichtung Teilnehmerdaten vollständig oder eingeschränkt passieren lässt.
Independent claims26
12 paragraphs, as filed
The invention relates to a method and a device for Authentication of a participant for the claim Of services in a wireless LAN (WLAN) using Of an IP multimedia subsystem (IMS) of a mobile radio network.
From the magazine Funkschau 09/2002. Page 14-15 are procedures For authentication of WLAN subscribers in one Mobile network, namely the authentication via a NAI (Network Access Identifier) and optionally a SIM card, as well as authentication with the IPv6 (Internet Protocol version 6) and a so-called SIM-6 mechanism. In general, an authentication of a wireless LAN Participant via an HTTP protocol.
WO 00/76249 A1 describes a method for authorizing a Internet protocol capable mobile device for access to the Internet Internet via a wireless LAN (WLAN), GSM or UMTS network. This involves sending an IP access request from the mobile device To an IP router via the access network. In response to receiving this access request to the IP router Will get an IP address routing prefix from the IP router The mobile device. The IP router only directs IP packets Then forward to the mobile device if he previously received an authorization message From a control point. The control point Monitors the payment (electronic cash) of the mobile Device for the use of the Internet.
US 2002/0062379 A1 describes the structure of a multimedia session In a mobile device having a session paket access beam (Session packet access bearer), which runs between The mobile device and an access point to a packet data network Via a radio access network. The access point Is connected to a multimedia system that Multimedia meeting services. By using the Session Packet Access is a multimedia session, Which includes a plurality of media data streams, in one Mobile device. Media packet access bearer between The mobile device and the access point.
The object of the present invention is to provide a subscriber A wireless LAN, which also participates in a mobile network In the use of services in a mobile network To efficiently authenticate.
The object is achieved according to the invention by the objects of the invention Independent claims relating to the procedure and the Device. Further developments of the invention are described in the Subclaims. The authentication according to the invention Using an IP multimedia subsystem The advantage that the authentication of a subscriber for Any services that are accessed via the wireless LAN Without installing a separate server for the Authentication in wireless LAN and without Separate connection to a corresponding instance in the Mobile radio network (eg HLR / HSS), which can be used by means of a (Interface) must be contacted, is carried out.
The invention will be described with reference to the accompanying drawings, in which: FIG Illustrated by way of example. Show in detail<dl tsize="7" compact="compact"><dt>FIG</dt><dd>The architecture with the interfaces between one Wireless LAN and an IP Multimedia Subsystem (IMS)</dd><dt>FIG</dt><dd>Such as WAGW's authentication result Use of your own P-CSCF / Policy Control function On-site with WLAN coverage</dd><dt>FIG</dt><dd>As the WAGW the authentication result by the CSCF / Policy Control Function of the IP Multimedia Subsystem (IMS)</dd><dt>FIG</dt><dd>As the WAGW by extended functionalities the Authentication result</dd></dl>
Figure 1 shows how the wireless LAN with an IP multimedia Subsystem (IMS) (3). A subscriber MT (6) of a Wireless LANs (10) is connected via an air interface (11) to the Wireless LAN in one place with wireless LAN coverage (hotspot) connected. For authentication, the MT (6) is received by the proxy Call State Control function node (P-CSCF) (1) an IP address (For example, by DHCP). The subscriber MT (6) can thereby itself Via SIP registration in IMS (3) without a prior bearer Level authentication (eg H / 2, authentication via the Air interface is optional). In IMS (3) The authentication takes place on the application side in the call state Control function node (CSCF) (4) via a SIP Registration message. Through the authentication the MT (6) access to specific profiles (eg WLAN profiles) Is granted. The CSCF (4) uses one per se for the IMS (3), however Not for a WLAN (10) Known authentication using the Home Subscriber System (HSS) (5) via the Cx interface. The P-CSCF (1) of the WLAN (10) receives the result of the authentication via a SIP Registration request (for example, 200 OK). This result is attributed to the WLAN Access Gateway (WAGW) (2). The WAGW (2) Controls access to services and monitors the Successful authentication in IMS (3). Wireless LAN (10) Is connected to the Gi interface or the Mm interface with the IMS (3). The Gi interface provides a Interface within the IP network (7) Thus special safety precautions. Be considered Also the geographical distance between the IMS (3) and the Place with the WLAN coverage. For the Mm interface, the Connection between the IMS (3) and the place with the WLAN Coverage (hotspot) over an IP multimedia network (Internet) (8th).
The authentication of an MT (6) in the IMS (3) takes place under Use the SIP protocol. The result of the Authentication in the IMS (3) is sent to the WAGW (2). For this purpose, there are three possibilities, which are described under FIG. 2, FIG. 3 And FIG.
FIG. 2 shows the WAGW (2) the authentication result By its own P-CSCF (1) / policy control function at the location With WLAN coverage (hotspot). In this case, the WLAN is (10) is provided with its own P-CSCF (1), which for this purpose , SIP messages to the corresponding instance in the IMS (3) (SIP registration request) and the WAGW (2) According to the authentication results of the IP Multimedia Subsystem (IMS) (SIP response). The P-CSCF (1) Communicates with the CSCF (4) in the IP multimedia subsystem A Gi interface or a Mm interface (via Internet (8th)). The P-CSCF (1) gives the WAGW (2) based on the Result The authentication (SIP registration) in the IMS (3), Instructions, such as the data traffic of an MT (6) by the WAGW (2). For example, the WAGW (2) can control the data flow to block. Using the Policy Control function, P-CSCF (1) the data traffic through the WAGW (2) and the Quantity and quality of the data flow of an MT (6) by the WAGW (2), restrict, increase or reject them. This Mechanism is imitated by the Go interface, the Between the P-CSCF of the IMS (3) and the gateway GPRS Support Node (GGSN) (9) is installed. This policy control function Can be a component of the P-CSCF (1) or its own Unit that is optional for the IP multimedia subsystem And the PS domain can be used. A possible policy protocol is COPS (RFC 2748, applied For the Go interface). The Go interface is used An IP transport and therefore, when implementing a Secure transmission of COPS messages within the Wireless LAN or a separate (isolated from traffic) Of participants within the wireless LAN) P-CSCF (1) and WAGW (2).
FIG. 3 shows how the WAGW (2) shows the result of the IMS Authentication from the CSCF (4) of the IMS (3) Of course. The CSCF (4) of the IMS (3) controls the WAGW (2) In the sense that it exercises policy functionality. Practice here But the P-CSCF of the IMS (3) controls the WAGW (2) Instead of a separate P-CSCF in the wireless LAN. The policy functionality controls the P-CSCF of the IMS (3) the traffic through the WAGW (2) and the Quantity and quality of the data flow of the MT (6) WAGW (2), restrict, increase or reject them. This Mechanism is imitated by the Go interface, the Between P-CSCF of the IMS (3) and the GGSN (9) of the PS domain Is installed. Between the CSCF (4) of the IMS (3) and the WAGW (2) of the wireless LAN (10) is used for secure data transmission A Go interface installed. The WAGW (2) can the SIP Messages that contain the authentication result The Gi interface or via the Mm interface to the CSCF (4) in the IMS (3).
FIG. 4 shows the WAGW (2) the authentication result Even evaluated. The WAGW (2) receives the result, Whether an authentication of the MT (6) took place in the IMS (3) and Which is the result of this. Subsequently, the WAGW (2) converts the result by completing subscriber data completely or Restricted. If the WAGW (2) with a Gi Interface, so it can Authentication (SIP registration) The CSCF (4) in the IMS (3). Otherwise the Mm Interface. So that the WAGW (2) the result of the Authentication (SIP messages), it is used in Form of an "application layer gateway". Thus, It is the result of a SIP authentication without the Use a CSCF (4) accordingly. The WAGW (2) Investigates the data packets on SIP messages (Registration requests and responses) and interprets the SIP registration replies corresponding to the filtering of Subscriber data. So that not every data packet from the WAGW (2) Must be opened, a precipitation process can be initiated on OSI Layer 3 (IP address) or OSI Layer 4 (port number) will. This is an IP address, a port number, or Other criterion for elimination is an occasion for the Data packet or a datagram to the next higher OSI layer Or whether the WAGW (2) can happen.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8457046B2 | Cited by | United States of America | Applicant |
| DE102006026929A1 | Cited by | Germany | Search report |
| DE102006026929B4 | Cited by | Germany | Search report |
| EP1191763A | Cites | European Patent Office (EPO) | – |
| WO0076249A | Cites | World Intellectual Property Organization (WIPO) | – |
| WO0191389A | Cites | World Intellectual Property Organization (WIPO) | – |
| WO0191419A | Cites | World Intellectual Property Organization (WIPO) | – |
| US2002062379A1 | Cites | United States of America | – |
12 members in 8 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 0206269 | European Patent Office (EPO) | W | |
| 0206269 | European Patent Office (EPO) | W | |
| EP2002006269 | – | – | – |
| WO2002EP06269 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO03105436A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002314148A1 | Australia | A1 | |
| EP1512260A1 | European Patent Office (EPO) | A1 | |
| CN1628448A | China | A | |
| US2005181764A1 | United States of America | A1 | |
| EP1512260B1This record | European Patent Office (EPO) | B1 | |
| AT311716T | Austria | T | |
| ATE311716T1 | Austria | T1 | |
| DE50205145D1 | Germany | D1 | |
| ES2254693T3 | Spain | T3 | |
| US7634249B2 | United States of America | B2 | |
| CN1628448B | China | B |
63 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0029060000R079 | R079 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20210107 AND 20210113732E | 732E | GB | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20201203 AND 20201209732E | 732E | GB | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20201105 AND 20201111732E | 732E | GB | |
| Transfer of patentPC2A | PC2A | ES | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20190808 AND 20190814732E | 732E | GB | |
| Transfer of patentPC2A | PC2A | ES | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Designated contracting statesAK | AK | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1512260
- Publication, DOCDB
- 1512260
- Publication, EPODOC
- EP1512260
- Application
- 2740696
- Application, DOCDB
- 02740696
- Application, EPODOC
- EP20020740696
Titles3
- German
- VERFAHREN UND VORRICHTUNG ZUR AUTHENTIFIZIERUNG EINES TEILNEHMERS FÜR DIE INANSPRUCHNAHME VON DIENSTEN IN EINEM WIRELEES LAN (WLAN)
- English
- METHOD AND DEVICE FOR AUTHENTICATING A SUBSCRIBER FOR UTILIZING SERVICES IN A WIRELESS LAN (WLAN)
- French
- PROCEDE ET DISPOSITIF D'AUTHENTIFICATION D'UN ABONNE POUR L'UTILISATION DE SERVICES DANS UN RESEAU LOCAL SANS FIL (WLAN)
Classification
- CPC, 15
- H04L65/1016
- H04L29/12009
- H04L61/00
- H04L29/12216
- H04L63/08
- H04W4/00
- H04L61/2007
- H04W8/26
- H04W12/06
- H04L63/0892
- H04W48/16
- H04W80/04
- H04W80/10
- H04W84/12
- H04L61/5007
- IPC, 21
- B29C33 02
- B29C33 04
- B29C35 02
- B29C35 04
- B29D30 00
- B29D30 06
- B29D30 10
- B29D30 12
- B29L30 00
- H04L12 28
- H04L29 06
- H04L29 08
- H04L29 12
- H04W4 00
- H04W8 26
- H04W12 06
- H04W48 16
- H04W80 04
- H04W80 10
- H04W84 12
- H04W88 02
Designated states20
- Contracting states, 20
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye