EP1523129B1

Method and apparatus for access control of a wireless terminal device in a communications network

Abstract

This record has no abstract on file.

EP1523129B1, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 18 January 2022, 4.7 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

18 claims: 4 independent, 14 dependent

  1. 1
    A method for access control of a wireless terminal device (303, 404) in a communication network, the communication network comprising an access point (501) for setting up a communication connection to the wireless terminal device, an authentication server (505) for providing an authenticating service for the wireless terminal device to authenticate to the communication network, an authentication agent (504) for relaying authentication information between the wireless terminal device and the authentication server, and an access controller for relaying data packets of authenticated wireless terminal devices and blocking data packets of unauthenticated wireless terminal devices, an access controller functionality (502) comprising an access control list (503) that is a list of authenticated wireless terminal devices, the wireless terminal device being configured to use either of the following authentication methods in order to authenticate itself to the communication network:a first authentication method wherein the access point (501) relays authentication information between the wireless terminal device and the authentication server (505), a second authentication method wherein the authentication agent (504) relays authentication information between the wireless terminal device and the authentication server (505), characterized by the method comprising the steps of identifying (101) at the access point (501) whether the wireless terminal device is using the first authentication method or the second authentication method, whereby if the wireless terminal device authenticates (102) by using the first authentication method, performing the steps of: the access point relaying (108) authentication information between the wireless terminal device and the authentication server, the access point sending (106) an identifier data of the wireless terminal device, in response to successful authentication, to the access control list, and the access controller adding (107) the identifier data of the wireless terminal device to the access control list and relaying data packets of the wireless terminal device included on the access control list, and if the wireless terminal device authenticates (103) by using the second authentication method, performing the steps of: the access point relaying (105) authentication information between the wireless terminal device and the authenticating agent, the authentication agent relaying authentication information between the wireless terminal device and the authentication server, the authentication agent sending (106) the identifier data of the wireless terminal device, in response to successful authentication, to the access control list, and the access controller adding (107) the identifier data of the wireless terminal device to the access control list and relaying data packets of the wireless terminal device included on the access control list.
  2. 10
    A method according to claims 6 to 9, characterized in that the access point identifies the authentication method by receiving an association request message from the wireless terminal device.
  3. 13
    An access point (501) for setting up a communication connection to a wireless terminal device in a communication network, said communication network comprising an authentication server (505) for providing an authenticating service for the wireless terminal device to authenticate to the communication network, an authentication agent (504) for relaying authentication information between the wireless terminal device and the authentication server, and an access controller for relaying data packets of authenticated wireless terminal devices and blocking data packets of unauthenticated wireless terminal devices, an access controller functionality (502, 503) comprising an access control list (503) that is a list of the authenticated wireless terminal devices, characterized in that the access point is configured to accept the wireless terminal device to use one of the following authentication methods in order to authenticate to the communication network:a first authentication method wherein the access point is configured to relay authentication information between the wireless terminal device and the authentication server, a second authentication method wherein the access point is configured to relay authentication information between the wireless terminal device and an authentication agent, whereby the access point comprises identifying means (207) for identifying whether the wireless terminal device is using the first authentication method or the second authentication method, first relaying means (201, 205, 206) for relaying authentication information between the wireless terminal device and the authentication server as a response to a situation that the wireless terminal device has been identified to be using the first authentication method, first sending means (201, 205) for sending identifier data of the wireless terminal device, as a response to a successful authentication of the wireless terminal device according to the first authentication method, to the access control list, second relaying (201, 205, 206) means for relaying authentication information between the wireless terminal device and the authentication agent as a response to a situation that the wireless terminal device has been identified to be using the second authentication method, and second sending means (201, 205) for sending identifier data of the wireless terminal device, as a response to successful authentication of the wireless terminal device according to the second authentication method, to the access control list.
  4. 18
    A system for access control of a wireless terminal device (303, 404) in a communication network, the communication network comprising:an access point (501) for setting up a communication connection to the wireless terminal device, an authentication server (505) for providing an authenticating service for the wireless terminal device (303, 404) to authenticate to the communication network, an authentication agent (504) for relaying authentication information between the wireless terminal device (303) and the authentication server (505), and an access controller (502) for relaying data packets of authenticated wireless terminal devices and blocking data packets of unauthenticated wireless terminal devices, an access controller functionality comprising an access control list (503) that is a list of the authenticated wireless terminal devices, the wireless terminal device (303, 404) being configured to use one of the following authentication methods in order to authenticate itself to the communication network: a first authentication method wherein the access point (501) relays authentication information between the wireless terminal device (404) and the authentication server (505), a second authentication method wherein the authentication agent (504) relays authentication information between the wireless terminal device (303) and the authentication server (505), characterized in that the system comprises: identifying means for identifying at the access point (501) whether the wireless terminal device (303, 404) is using the first authentication method or the second authentication method, first relaying means for relaying at the access point (501) the authentication information of the first authentication method between the wireless terminal device (404) and the authentication server (505), second relaying means for relaying at the access point (501) authentication information of the second authentication method between the wireless terminal device (303) and the authentication agent (504), third relaying means at the authentication agent (504) for relaying authentication information of the second authentication method between the access point (501) and the authentication server (505), first sending means for sending from the access point (501) identifier data of the wireless terminal device (404), as a response to successful authentication of the wireless terminal device according to the first authentication method, to the access control list (503), second sending means for sending from the authentication agent (504) the identifier data of the wireless terminal device (303), as a response to successful authentication of the wireless terminal device according to the second authentication method, to the access control list (503), and relaying means at the access controller functionality (502) for relaying data packets of the wireless terminal device (303, 404) included on the access control list.