EP1519604A1

Method for authentication of a mobile node to a wireless access network

Abstract

Method for authentication and/or authorization of a mobile node to a wireless access network, whereby the mobile node, the air interface and the wireless access network comprise a service network for providing services to a user of the mobile node, to provide an authentication and authorization mechanism for temporary subscriptions, which is reliable and easy to implement, and which takes into account current user location, i.e. mobility, whereby a self-authenticating token for temporary subscription is generated by a code generation server external to the service network, authentication/authorization information is derived from the token by the mobile node, and the mobile node utilizes the authentication/authorization information to authenticate and/or authorize itself to an authentication/authorization server located in the service network.

EP1519604A1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 29 September 2023, 3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

19 claims: 8 independent, 11 dependent

  1. 1
    Method for authentication and/or authorization of a mobile node to a wireless access network, whereby the mobile node, the air interface and the wireless access network comprise a service network for providing services to a user of the mobile node, characterized in that a self-authenticating token for temporary subscription is generated by a code generation server external to the service network, authentication/authorization information derived from the token is provided to the mobile node, and the mobile node utilizes the authentication/authorization information to authenticate and/or authorize itself to an authentication/authorization server located in the service network.
  2. 5
    Method according to one of the preceding claims, characterized in that the token is generated prior to a generation request from the service network.
  3. 6
    Method according to one of the preceding claims, characterized in that the token includes authorization data, which comprise one or more of the following authorization elements:- calendar date, - time of day as starting time or time interval - number of users, - service privileges, - user data volume to be received and/or transmitted, - network classification, - location information.
  4. 8
    Method according to one of claims 6 or 7, characterized in that resource consumption for time and/or volume based authorization elements is metered and recorded in the service network and this resource consumption is suspendable upon request transmitted from the mobile node to the authentication/authorization server.
  5. 10
    Method according to any one of the preceding claims, characterized in that authentication/authorization related context data is transferred from the authentication/authorization server to a second wireless access network to which a handover of the mobile node is performed.
  6. 12
    Method according to any one of the preceding claims, characterized in that the temporary subscription is restricted to - one or more devices by registering specific device parameters with the first authentication/authorization and/or - one or more users by registering personal information with the first authentication/authorization.
  7. 13
    Method according to any one of the preceding claims, characterized in that the provision of the token-based authentication/authorization information to the mobile node is triggered by transmission of credentials from the mobile node to the code generating server.
  8. 14
    Method according to any one of the preceding claims, characterized in that the lifetime of a token is extendable by the authentication/authorization server or the code generation server, in particular upon request transmitted from the mobile node.
  9. 15
    Arrangement for authentication and/or authorization of a mobile node to a wireless access network according to one of the preceding claims, whereby the mobile node, the air interface and the wireless access network comprise a service network for providing services to a user of the mobile node, characterized by a central code generation server, located external to the service network, adapted to generate a self-authenticating token for temporary subscription, whereby the mobile node derives authentication/authorization information from the token provided to the mobile node, and an authentication/authorization server, located in the service network, adapted to authenticate and/or authorize the mobile node based on the authentication/authorization information derived from the token.
  10. 18
    Arrangement according to any one of claims 15 to 17, characterized in that the authentication/authorization server is adapted to transfer the context related to authentication/authorization of the mobile node to a second access network.
  11. 19
    Arrangement according to any one of claims 15 to 18, characterized in that the authentication/authorization server meters and records resource consumption for time and/or volume based authorization elements of the temporary subscription and is adapted to suspend the resource consumption upon request transmitted from the mobile node.