EP2184934A1

Method and apparatuses for single sign-on access to a service network through an access network

Abstract

The present invention provides means and method for Single Sign-On authentication of a user accessing a service network through an access network when the user has been already authenticated by a core network where the user holds a subscription. Therefore, a number of means are provided in different entities distributed between the core network and the service network, as well as in the user's equipment, for carrying out the proposed method. The Single Sign-On authentication takes place upon matching in the service network a shared key for the user submitted from the core network with another shared key for the user derived at the user's equipment.

EP2184934A1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 29 December 2023, 2.7 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

24 claims: 4 independent, 20 dependent

  1. 1
    A method for supporting Single Sign-On services for a user with a user's equipment (UE) arranged for accessing a telecommunication core network (CN), where the user is subscriber, and a service network (SN), where services are provided, through an access network (WLAN) , the method comprising the steps of:- identifying (S-22, S-23) a user as subscriber of a telecommunication core network (CN) at an entity of an access network (WLAN) where the user accesses;- carrying out (S-25) an authentication procedure for the user between an entity (HLR, AG) of the core network (CN) and the user's equipment (UE);- computing at the entity (HLR, AG) of the core network (CN) a first secret user's key (KC) usable as cryptographic material;- computing at the user's equipment (UE) a second secret user's key (KC) usable as cryptographic material;- deriving (S-251) a first user's shared key (SSO_key-1) for SSO purposes from the cryptographic material at the entity (AG) of the core network (CN);- deriving (S-252) a second user's shared key (SSO_key-2) for SSO purposes from the cryptographic material at the used's equipment (UE);- the entity (AG) of the core network (CN) notifying (S-30) an entity (SAAN, SSO_SM) of a service network (SN) that an access session for the user through the access network has been initiated (S-29) and including the first user's shared key (SSO_key-1) for SSO purposes;- creating (S-301) a master session for the user at the entity (SAAN, SSO_SM) of the service network (SN), the master session comprising a user's identifier and the first user's shared key (SSO_key-1);- upon the user accessing a service of the service network for the first time, confirming (S-32, S-33) the second user's shared key (SSO_key-2) from the user's equipment (UE) towards the entity (SAAN, SSO_SM) of the service network (SN);- verifying (S-34) at the entity (SAAN, SSO_SM) of the service network (SN) whether the second user's shared key (SSO_key-2) matches the first user's shared key (SSO_key-1) for the user;and- granting (S-35, S-36, S-37) access to the requested service in the service network (SN) on matching the first and second user's shared keys.
  2. 10
    An apparatus (AG, HLR) of a telecommunication core network (CN) for supporting Single Sign-On services of a service network (SN) for a user accessing through an access network (WLAN), wherein the user is subscriber of the telecommunication core network (CN), the apparatus having:- means for receiving (S-23) an access request of a user from an entity (WLAN-AS) of an access network (WLAN) where the user with a user's equipment (UE) accesses through, the access request including a user's identifier;- means for carrying out (S-25) an authentication procedure (SIM-based;AKA;EAP) with the user's equipment (UE) through the access network (WLAN) in order to authenticate the user;- means for computing a secret user's key (KC) usable as cryptographic material;- means for deriving (S-251) from the cryptographic material a user's shared key (SSO_key-1) for SSO purposes;and- means for notifying (S-30) an entity (SAAN, SSO_SM) of a service network (SN) that an access session for the user has been initiated (S-29) through the access network (WLAN), the notification including the user's identifier and the user's shared key (SSO_key-1) for SSO purposes.
  3. 13
    An apparatus (SAAN, SSO_SM) of a service network (SN) for a user accessing Single Sign-On services through an access network (WLAN), the user having been authenticated by a telecommunication core network (CN) where the user holds a subscription, the apparatus having:- means for receiving (S-30) a notification from an entity (AG) of the core network (CN) indicating that an access session for a user with a user's equipment (UE) has been initiated through an access network (WLAN), the notification including a user's identifier and a first user's shared key (SSO_key-1) derived at the entity (AG) of the core network (CN) for SSO purposes;- means for creating (S-301) a master session for the user, the master session comprising the user's identifier and the first user's shared key (SSO_key-1);- means for confirming (S-32, S-33) with the user's equipment (UE), upon the user accessing a service of the service network for the first time, a second user's shared key (SSO_key-2) derived at the user's equipment (UE) for SSO purposes;and- means for checking (S-34) whether the second user's shared key (SSO_key-2) derived at the user's equipment (UE) matches the first user's shared key (SSO_key-1) included in the master session for the user.
  4. 21
    A user's equipment (UE) usable by a user with a subscription in a telecommunication core network (CN), and arranged to access Single Sign-On services of a service network (SN) through an access network (WLAN), the user's equipment (UE) having:- means for carrying out (S-25) an authentication procedure (SIM-based;AKA;EAP) to authenticate the user with an entity (HLR, AG) of a core network (CN), where the user holds the subscription, through the access network (WLAN);- means for computing a secret user's key (KC) usable as cryptographic material;- means (S-252) for deriving from the cryptographic material a user's shared key (SSO_key-2) for SSO purposes;- a repository for storing the user's shared key (SSO_key-2);and- means for confirming (S-32, S-33), upon accessing a service of the service network (SN) for the first time, the user's shared key (SSO_key-2) stored at the user's equipment towards an entity (SAAN, SSO_SM) of the service network (SN).