EP3050270B1

Lawful interception in a wi-fi / packet core network access

Abstract

This record has no abstract on file.

EP3050270B1, drawing sheet 1
Sheet 1 of 14

Term

7 yearsleft in the term

Expires 27 September 2033.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

15 claims: 11 independent, 4 dependent

  1. 1
    A method, by an authentication unit (300) of a wireless access network, to allow anchoring of a data packet session of a user entity (10) connected to the wireless access network to a packet core network of a mobile communications network (20), the user entity using an access identifier allowing the user entity to be identified in the wireless access network, wherein the access identifier is not used in the mobile communications network to identify a subscriber, the method comprising the steps of:- receiving a request message in which access to the wireless access network is requested, wherein the request message contains an MAC address of the requesting user entity (10), - converting the MAC address in the received request message into a sequence of digits used as a mobile subscriber identifier with which the user entity is identified in the mobile communications network, - transmitting a response message accepting the access to the packet core network, the response message including the sequence of digits used as mobile subscriber identifier.
  2. 4
    The method according to any of the preceding claims, wherein the sequence of digits is transmitted in the response message by the authentication unit as IMSI of the user entity (10) and as MSISDN of the user entity (10).
  3. 5
    The method according to any of the preceding claims, further comprising the step of adding an offload indicator to the transmitted response message, which indicates an offload situation in which a data packet session which could be transmitted to the user entity via an access network of the mobile communications network is transmitted to the user entity through the wireless access network.
  4. 6
    The method according to any of the preceding claims, wherein the received request message, in addition to the MAC address, contains an authentication of the user entity.
  5. 7
    The method according to any of claims 1 to 5, wherein the received request message is an authentication request requesting authentication of the user entity.
  6. 8
    The method according to any of the preceding claims, wherein the wireless access network is a WI-FI network.
  7. 9
    The method according to any of the preceding claims, wherein the request message is received from a wireless access gateway (24), the response message being transmitted back to the wireless access gateway (24).
  8. 10
    An authentication unit (300) configured to allow anchoring of a data packet session of a user entity (10) connected to a wireless access network to a packet core network of a mobile communications network (20), the user entity using an access identifier allowing the user entity to be identified in the wireless access network, wherein the access identifier is not used in the mobile communications network (20) to identify a subscriber, the authentication unit comprising:- a receiver (322) configured to receive a request in which access to the wireless access network is requested, wherein the request message contains an MAC address of the requesting user entity (10), - a converting unit (330) configured to convert the MAC address in the received request into a sequence of digits used as a mobile subscriber identifier with which the user entity (10) is identified in the mobile communications network (20), - a transmitter (321) configured to transmit a response message accepting the access to the packet core network, the response message including the sequence of digits used as mobile subscriber identifier.
  9. 13
    The authentication unit according to any of claims 10 to 12, wherein the converting unit (330) is configured to use the generated sequence of digits as IMSI and as MSISDN of the user entity.
  10. 14
    The authentication unit according to any of claims 10 to 13, wherein the converting unit (330) is configured to check whether the sequence of digits has a value which lies in a predefined range of values, wherein, if this is the case, the converting unit changes the sequence of digits in such a way that the value of the changed sequence of digits lies outside the predefined range of values.
  11. 15
    A lawful interception control module (400) configured to collect communication data of user entities in a mobile communications network which comprises a packet core network, the control module comprising:- a input unit (410) configured for an input of an identifier with which a user entity (10) is identified the communication data of which should be collected, wherein the input unit (410) is configured for an input of an identifier being a MAC address of the user entity (10), - a converting unit (420) configured to convert the MAC address into a sequence of digits used as mobile subscriber identifier with which the user entity (10) is identified in the mobile communications network (20), - a transmitter (431) configured to transmit the generated sequence of digits as mobile subscriber identifier to all PDN gateways of the mobile communications network.