Method and apparatus for access control of a wireless terminal device in a communications network
Abstract
Method for controlling the access of a wireless terminal device (303, 404) in a communications network, the communications network comprising: an access point (501) to establish a communication connection with the wireless terminal device, an authentication server (505) to provide an authentication service so that the wireless terminal device authenticates with the communications network, an agent authentication (504) to relay authentication information between the wireless terminal device and the authentication server, and an access controller for retransmitting data packets of wireless terminal devices and blocking data packets of wireless terminal devices, an access controller functionality (502) comprising an access control list (503) which is a list of devices authenticated wireless terminals, the wireless terminal device being configured to use one of the following authentication methods with a view to authenticating with the communications network: a first authentication method in which the access point (501) relays authentication information between the wireless terminal device and the authentication server (505), a second authentication method in which the authentication agent (504) relays information authentication between the wireless terminal device and the authentication server (505), characterized in that it comprises the following steps to identify (101) at the access point (501) if the wireless terminal device is using the first authentication method or the second authentication method.

Term
Term ended
Projected expiry passed 18 January 2022, 4.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
18 claims: 4 independent, 14 dependent
- 1ES 2 274 358 T3 REIVINDICACIONES 1. Método para controlar el acceso de un dispositivo terminal inalámbrico (303, 404) en una red de comunicaciones, comprendiendo la red de comunicaciones:un punto de acceso (501) para establecer una conexión de comunicación con el dispositivo terminal inalámbrico, un servidor de autenticación (505) para proporcionar un servicio de autenticación con vistas a que el dispositivo terminal inalámbrico se autentique con la red de comunicaciones, un agente de autenticación (504) para retransmitir información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación, y un controlador de acceso para retransmitir paquetes de datos de dispositivos terminales inalámbricos y bloquear paquetes de datos de dispositivos terminales inalámbricos, una funcionalidad de controlador de acceso (502) que comprende una lista de control de acceso (503) que es una lista de dispositivos terminales inalámbricos autenticados, estando configurado el dispositivo terminal inalámbrico para usar uno de los siguientes métodos de autenticación con vistas a autenticarse con la red de comunicaciones: un primer método de autenticación en el que el punto de acceso (501) retransmite información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación (505), un segundo método de autenticación en el que el agente de autenticación (504) retransmite información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación (505), caracterizado porque comprende las etapas siguientes identificar (101) en el punto de acceso (501) si el dispositivo terminal inalámbrico está usando el primer método de autenticación o el segundo método de autenticación, de tal manera que el dispositivo terminal inalámbrico se autentica (102) mediante la utilización del primer método de autenticación, llevando a cabo las etapas siguientes: el punto de acceso retransmite (108) información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación, el punto de acceso envía (106) datos identificadores del dispositivo terminal inalámbrico en respuesta a una autenticación satisfactoria, a la lista de control de acceso, y el controlador de acceso añade (107) los datos identificadores del dispositivo terminal inalámbrico a la lista de control de acceso y retransmite los paquetes de datos del dispositivo terminal inalámbrico incluido en la lista de control de acceso, y si el dispositivo terminal inalámbrico se autentica (103) mediante la utilización del segundo método de autenticación, llevando a cabo las etapas siguientes: el punto de acceso retransmite (105) información de autenticación entre el dispositivo terminal inalámbrico y el agente de autenticación, el agente de autenticación retransmite información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación, el agente de autenticación envía (106) datos identificadores del dispositivo terminal inalámbrico, en respuesta a una autenticación satisfactoria, a la lista de control de acceso, y el controlador de acceso añade (107) los datos identificadores del dispositivo terminal inalámbrico a la lista de control de acceso y retransmite paquetes de datos del dispositivo terminal inalámbrico incluido en la lista de control de acceso.
- 2Método según la reivindicación 1, caracterizado porque la funcionalidad de controlador de acceso (502, 503) se implementa como parte del punto de acceso (501).
- 3Método según la reivindicación 1, caracterizado porque la funcionalidad del controlador de acceso (502, 503) se implementa como parte del agente de autenticación (504).
- 4Método según la reivindicación 1, caracterizado porque la funcionalidad del controlador de acceso (502, 503) se implementa en un dispositivo separado del punto de acceso y del agente de autenticación.
- 5Método según la reivindicación 1, caracterizado porque los datos identificadores comprenden por lo menos uno de entre los siguientes:una dirección IP y una dirección MAC del dispositivo terminal inalámbrico.
- 6Método según la reivindicación 1, caracterizado porque el primer método de autenticación se lleva a cabo según el protocolo IEEE 802.1X.
- 7Método según la reivindicación 6, caracterizado porque el primer método de autenticación se lleva a cabo según el protocolo IEEE 802. 11i.
- 8Método según la reivindicación 1, caracterizado porque el segundo método de autenticación se lleva a cabo a través de un protocolo de Internet.
- 9Método según la reivindicación 8, caracterizado porque el segundo método de autenticación se lleva a cabo según un protocolo de intercambio de claves de Internet o un protocolo de transferencia de hipertexto.
- 10Método según las reivindicaciones 6 a 9, caracterizado porque el punto de acceso identifica el método de autenticación mediante la recepción de un mensaje de solicitud de asociación del dispositivo terminal inalámbrico.
- 11Método según la reivindicación 10, caracterizado porque el mensaje de solicitud de asociación comprende un elemento de conjunto de autenticación, comprendiendo asimismo dicho elemento de conjunto de autenticación la información del método de autenticación que está usando el dispositivo.
- 12Método según cualquiera de las reivindicaciones 2 a 11, caracterizado porque el método comprende asimismo renovar la autenticación tras un periodo de tiempo.
- 13Punto de acceso (501) para establecer una conexión de comunicación a un dispositivo terminal inalámbrico en una red de comunicaciones, comprendiendo dicha red de comunicaciones un servidor de autenticación (505) para proporcionar un servicio de autenticación con vistas a que el dispositivo terminal inalámbrico se autentique con la red de comunicaciones un agente de autenticación (504) para retransmitir información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación, y un controlador de acceso para retransmitir paquetes de datos de dispositivos terminales inalámbricos y bloquear los paquetes de datos de los dispositivos terminales autenticados, una funcionalidad de controlador de acceso (502, 503) que comprende una lista ES 2 274 358 T3 de control de acceso (503) que es una lista de los dispositivos terminales inalámbricos autenticados, caracterizado porque el punto de acceso está configurado para aceptar que el dispositivo terminal inalámbrico use uno de los siguientes métodos de autenticación con vistas a autenticarse con la red de comunicaciones:un primer método de autenticación en el que el punto de acceso está configurado para retransmitir información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación, un segundo método de autenticación en el que el punto de acceso está configurado para retransmitir información de autenticación entre el dispositivo terminal inalámbrico y un agente de autenticación, en el que el punto de acceso comprende identificar unos medios (207) para identificar si el dispositivo terminal inalámbrico está usando el primer método de autenticación o el segundo método de autenticación, unos primeros medios de retransmisión (201, 205, 206) para retransmitir la información de autenticación entre el dispositivo terminal inalámbrico y el servidor de autenticación como una respuesta a una situación en la que se ha identificado que el dispositivo terminal inalámbrico está usando el primer método de autenticación está usando, unos primeros medios de envío (201, 205) para enviar los datos identificadores de envío del dispositivo terminal inalámbrico, como una respuesta a una autenticación satisfactoria del dispositivo terminal inalámbrico según el primer método de autenticación, a la lista de control de acceso unos segundos medios de retransmisión (201, 205, 206) para retransmitir información de autenticación entre el dispositivo terminal inalámbrico y el agente de autenticación como una respuesta a una situación en la que se ha identificado que el dispositivo terminal inalámbrico está usando el segundo método de autenticación, unos segundos medios de envío (201, 205) para enviar los datos de identificación del dispositivo terminal inalámbrico, como una respuesta a una autenticación satisfactoria del dispositivo terminal inalámbrico según el segundo método de autenticación, a la lista de control de acceso.
- 14Punto de acceso según la reivindicación 13, caracterizado porque los medios de identificación están dispuestos para identificar el método de autenticación mediante la recepción de un mensaje de solicitud de asociación a partir del dispositivo terminal inalámbrico.
- 15Punto de acceso según la reivindicación 14, caracterizado porque los medios de identificación están dispuestos para detectar un elemento de conjunto de autenticación a partir del mensaje de solicitud de asociación, comprendiendo dicho elemento de conjunto de autenticación información del método de autenticación que el dispositivo terminal inalámbrico está usando.
- 16Punto de acceso según la reivindicación 13, caracterizado porque el punto de acceso comprende unos medios de detección que están dispuestos para detectar la autenticación satisfactoria del dispositivo terminal inalámbrico que está usando dicho primer método de autenticación mediante la recepción de un mensaje del servidor de autenticación.
- 17Punto de acceso según la reivindicación 13, caracterizado porque el punto de acceso comprende unos medios de detección que están dispuestos para detectar la autenticación satisfactoria del dispositivo terminal inalámbrico que está usando dicho segundo método de autenticación mediante la recepción de un mensaje de uno de entre los siguientes:el agente de autenticación o el servidor de autenticación.
- 18Sistema para el control de acceso de un dispositivo terminal inalámbrico (303, 404) en una red de comunicaciones, comprendiendo la red de comunicaciones:un punto de acceso (501) para establecer una conexión de comunicación con el dispositivo terminal inalámbrico, un servidor de autenticación (505) para proporcionar un servicio de autenticación para que el dispositivo terminal inalámbrico (303, 404) se autentique con la red de comunicaciones, un agente de autenticación (504) para retransmitir información de autenticación entre el dispositivo terminal inalámbrico (303) y el servidor de autenticación (505), y un controlador de acceso (502) para retransmitir paquetes de datos de dispositivos terminales inalámbricos autenticados y bloquear paquetes de datos de dispositivos terminales inalámbricos no autenticados, una funcionalidad de controlador de acceso que comprende una lista de control de acceso (503) que es una lista del dispositivo terminal inalámbrico autenticado, estando configurado el dispositivo terminal inalámbrico (303, 404) para usar uno de los siguientes métodos de autenticación con vistas a autenticarse con la red de comunicaciones: un primer método de autenticación en el que el punto de acceso (801) retransmite información de autenticación entre el dispositivo terminal inalámbrico (303, 404) y el servidor de autenticación (505), un segundo método de autenticación en el que el agente de autenticación (504) retransmite información de autenticación entre el dispositivo terminal inalámbrico (303) y el servidor de autenticación (505), caracterizado porque el sistema comprende: unos medios de identificación para identificar en un punto de acceso (501) si el dispositivo terminal inalámbrico (303,404) está usando el primer método de autenticación o el segundo método de autenticación, unos primeros medios de retransmisión para retransmitir en el punto de acceso (501) la información de autenticación del primer método de autenticación entre el dispositivo terminal inalámbrico (404) y el servidor de autenticación (505), unos segundos medios de retransmisión para retransmitir en el punto de acceso (501) información de autenticación del segundo método de autenticación entre el dispositivo terminal inalámbrico (303) y el agente de autenticación (504), unos terceros medios de retransmisión en el agente de autenticación (504) para retransmitir información de autenticación del segundo método de autenticación entre el punto de acceso (501) y el servidor de autenticación (505), unos primeros medios de envío para enviar desde el punto de acceso (501) unos datos identificadores del dispositivo terminal inalámbrico (404), como una respuesta a la autenticación satisfactoria del dispositivo terminal inalámbrico según el primer método de autenticación, a la lista de control de acceso (503), y unos segundos medios de envío para enviar desde el agente de autenticación (504) unos datos identi14 ES 2 274 358 T3 ficadores del dispositivo terminal inalámbrico (303) como una respuesta a la autenticación satisfactoria del dispositivo terminal inalámbrico según el segundo método de autenticación, a la lista de control de acceso (503), y unos medios de retransmisión en la funcionalidad del controlador de acceso (502) para retransmitir paquetes de datos del dispositivo terminal inalámbrico (303, 404) incluido en la lista de control de acceso.
Independent claims18
69 paragraphs in 2 sections, as filed
ES 2 274 358 T3
DESCRIPTION
Method and apparatus for controlling the access of a wireless terminal device in a communication network.
The present invention relates to a method and apparatus for controlling the access of a wireless terminal device to a communication network and particularly, although not necessarily, for relaying data packets from a wireless terminal device having controlled access to a wireless local area network.
Previous technique
Typically, a wireless local area network presents a network comprising terminal devices, such as wireless terminal devices or laptop computers and access points, in which the data transmission between the terminal devices and the access points is partially carried out. or completely wirelessly using radio waves or infrared technology.
The structure of telecommunications networks is generally described using the OSI (Open Systems Interconnection) model, which defines the interfaces through which different devices and related software communicate with each other. The OSI model is based on a concept of layers, the lowest layer, or first layer, being known as the Physical Layer that encompasses all the logical, electrical and mechanical aspects related to data transfer. The second layer of the protocol, that is, the Data Link Layer, is responsible for establishing connections, correcting errors, and clearing connections. The third layer of the protocol, that is, the Network Layer, provides a data transfer that does not depend on the structure of the network. Subsequent layers are the Transport Layer (fourth layer), the Session Layer (fifth layer), the Presentation Layer (sixth layer), and the Application Layer (seventh layer).
In the OWLAN system (Operator Wireless Local Area Network), authentication and access control currently take place on the third layer of the OSI model, that is, the network layer, or IP layer, and the association of the WLAN between the terminal device and the Access Point is carried out without authentication. An access point is a physical device, such as a base station, that interconnects a wireless network with a wired one. In Open Systems Authentication, the association event does not imply an actual authentication, but the open systems authentication, performed prior to association, is a null authentication. After association, the terminal device is typically provided with an IP address after the association event by means of an IP-based DHCP (Dynamic Host Configuration Protocol) method. Authentication is then carried out by running an IP-based authentication protocol. Although the authentication protocol also uses protocol layers on top of the IP layer, authentication is referred to in this case as third-layer authentication of the protocol since typically access control is implemented on top of the third layer of the protocol. . The carrier's Wireless LAN solution includes the Network Access Authentication Protocol (NAAP), which is a third-layer protocol for authenticating the wireless terminal using the GSM Subscriber Identity Module. Another example of an authentication protocol of the third protocol layer is the solutions based on the Hypertext Transfer Protocol (HTTP), in which the authentication is carried out using a page of the World Wide Web (WWW) in the which the user fills in the credentials. Still another example of a third protocol layer authentication protocol is the Internet Key Exchange Protocol (IKE), which is used when establishing a Virtual Private Network connection. In all of these examples, the wireless terminal is required to execute the third protocol layer authentication protocol before it can access the resources for which access control is being enforced.
Standardization provides a framework for hardware and software manufacturers to enable the joint use of products from different manufacturers. The title of the WLAN standard is IEEE 802.11 and it has been gradually supplemented by a series of auxiliary standards. According to the future IEEE 802.11i standard, WLAN authentication will be carried out according to a second protocol layer authentication method, such as an IEEE802.1x protocol before the transmission of IP packets between the end device and the network. .
The first router in the OWLAN system, that is, the border router, which is between the communication network and the wireless terminals connected to the wireless local area network, functions in the OWLAN as the other party in the authentication carried out. performed according to the third protocol layer, that is, open systems authentication, and maintains an Access Control List (ACL) of authenticated end devices. The IEEE is standardizing a new WLAN authentication system in which authentication is performed in relation to the Access Point. If the access network only develops the new WLAN authentication system, then the current OWLAN system, such as Nokia's Version 1.0 Carrier Wireless LAN solution, cannot be used as the customer is not allowed to run the authentication. authentication protocol of the third protocol layer without first authenticating according to the IEEE 802.1x protocol. As some users will acquire new terminal devices while others will have old terminal devices, there will be “old” terminals that can access the network using the authentication method of the third protocol layer and there will also be “new” terminals that can access the network. network using the authentication method according to the IEEE 802.1x standard. There will also be networks that include access points that operate only according to the IEEE 802.1x standard and other access points that operate as part of an OWLAN system. One of the problems that the standardization of current systems will face is the incompatibility of the current open system and future authentication systems of the second protocol layer, that is, current terminals cannot access networks according to the IEEE standard. 802.1x and future IEEE802.1x terminals cannot access current open system networks.
Publication WO 01/41470 presents a method
ES 2 274 358 T3 do and apparatus for allowing a mobile station in a wireless network to perform network authentication in association with mobile packet data services. In this solution, a CHAP (Mutual Challenge Authentication Protocol) is used before a possible use of authentication protocols according to Mobile IP. In other words, there is a requirement that all mobile terminals that can authenticate via the wireless network support CHAP.
Summary of the invention
Thus, a method and apparatus have been invented to allow a wireless terminal to access a network using either a third protocol layer authentication, such as open systems authentication, or a second protocol layer authentication. , for example, according to the IEEE 802.1x protocol. An Access Point of the invention allows both Open Systems Authentication, in which the terminal device is authenticated in a later phase according to the third layer of the protocol, and authentication of the second layer of the protocol, for example IEEE 802.1 authentication. x. Using the invention, certain network elements of the Wireless LAN solution can backwardly support both the new IEEE 802.1x layer 2 authentication standard and the current layer 3 authentication.
In the current Nokia Carrier Wireless LAN solution, the gatekeeper is responsible for maintaining an access control list and performing a third protocol layer authentication protocol. In the present invention, these functionalities are separated into a logical gatekeeper functionality and an authentication agent functionality to perform a third protocol layer authentication protocol. The network is organized so that at least part of the packets from the terminal devices traverse the network element that contains the logical gatekeeper functionality. Authentication agent functionality refers to the implementation of the third layer network authentication protocol, for example, the implementation of the NAAP protocol, the HTTP (Hypertext Transfer Protocol) authentication protocol, or the Key Exchange protocol. Internet (IKE). The gatekeeper functionality and the authentication agent functionality are not necessarily implemented in the same physical network element, but it is possible to implement the gatekeeper functionality in the access point device or alternatively in some other device.
If third-layer protocol authentication is used, then the authentication agent functions as the authenticating entity executing the third-layer protocol authentication protocol, just as in the current carrier wireless LAN solution. Nokia. Successful authentication results in adding the terminal to an access control list. If the gatekeeper functionality resides on a device other than the authentication agent, then the authentication agent sends the terminal information to the network element that contains the gatekeeper functionality. An authenticator is an entity that facilitates network access authentication of the terminal device by functioning as a peer entity in the authentication protocol used between the terminal and the authenticator. An authentication server is an entity that provides an authentication service to an authenticator. This service determines, from the credentials provided by the requester, that is, the terminal device, if said requester is authorized to access the services provided by the authenticator. If the authentication of the second protocol layer is executed, in that case the Access Point will work in the first place as specified in the IEEE regulations and will act as the Authenticating entity. Additionally, after successful authentication, the Access Point updates the access control list so that packets from authenticated clients are also retransmitted at the second protocol layer. If the gatekeeper functionality resides on a device other than the access point, then the access point sends the terminal information to the network element that contains the gatekeeper functionality.
The invention provides a solution that allows a wireless local area network system, such as the Nokia Carrier Wireless LAN, to support both a second protocol layer, i.e., Layer 2, authentication standard, as well as a standard. authentication according to IEEE 802.1x, as the current authentication standard that is based on the third protocol layer, that is, Layer 3.
When using Open Systems Authentication, the system works in a similar way to the current Nokia Carrier Wireless LAN system, in which the end device and the authentication agent are the parties involved in the authentication. The authentication agent relays information regarding authentication between the terminal device and an authentication server, and is capable of updating the list of authenticated users, regardless of which network element maintains the list.
When an authentication according to the second protocol layer is to be carried out, such as IEEE 802.1x authentication, the access point works according to the IEEE 802.1x standard, acting as the authentication part and relaying information regarding the authentication between the terminal device and the authentication server. Additionally, after successful authentication the access control list is updated, for example by the access point or the authentication server, to allow the network element containing the gatekeeper functionality to also retransmit packets of terminals authenticated according to the second protocol layer.
As for the terminals that use the authentication of the second protocol layer, in the implementation according to the invention, the interface provided between the terminal and the network is in full compliance with the regulations. The invention also does not set any new requirements on terminals using third protocol layer authentication.
The advantages of the invention include compatibility with the current open system, in which authentication is carried out in the third protocol layer, and with a system in which authentication is carried out on the second protocol layer, for example, according to the IEEE 802.1x standard. Regardless of the authentication method, the element
ES 2 274 358 T3 network containing gatekeeper functionality is capable of carrying out accounting routines in connection with the transfer of data packets. In addition, the devices according to the new regulation can operate on a network according to the current open systems regulation.
According to a first aspect of the invention, a method is provided for access control of a wireless terminal device in a communication network, the communication network comprising an access point for establishing a communication connection with the wireless terminal device , an authentication server to provide an authentication service in order for the wireless terminal device to authenticate with the communication network, and an authentication agent for relaying authentication information between the wireless terminal device and the authentication server, and a gatekeeper for relaying data packets from authenticated wireless terminal devices and blocking data packets from unauthenticated wireless terminal devices, and a gatekeeper functionality comprising an access control list which is a list of authenticated wireless terminal devices, the wireless terminal device being configured to use one of the following authentication methods in order to authenticate with the communication network: a first authentication method in which the access point relays authentication information between the wireless terminal device and the authentication server, a second authentication method in which the authentication agent relays authentication information between the wireless terminal device and the authentication server, the method being characterized in that it comprises the following stages: It is identified at the access point whether the wireless terminal device is using the first authentication method or the second authentication method, so that if the wireless terminal device authenticates using the first authentication method, the following steps are carried out : the access point relays authentication information between the wireless terminal device and the authentication server, the access point sending identifying data of the wireless terminal device, in response to successful authentication, to the access control list, and the access controller adding the identifying data of the wireless terminal device to the access control list and relaying data packets from the wireless terminal device included in the access control list and if the wireless terminal device authenticates using the second method of authentication, the following steps are carried out: the access point relays authentication information between the wireless terminal device and the authentication agent, the authentication agent relaying authentication information between the wireless terminal device and the authentication server, the authentication agent sending the identifying data of the wireless terminal device , in response to successful authentication, to the access control list, and the access controller adding the identifying data of the wireless terminal device to the access control list and retransmitting the data packets of the wireless terminal device included in the access control list.
According to a second aspect of the invention, an access point is provided for establishing a communication connection with a wireless terminal device in a communication network, said communication network comprising an authentication server for providing an authentication service with views for the wireless terminal device to authenticate with the communications network, and an authentication agent for relaying authentication information between the wireless terminal device and the authentication server, and a gatekeeper for relaying data packets from authenticated wireless terminal devices and blocking data packets from unauthenticated wireless terminal devices, a gatekeeper functionality comprising an access control list which is a list of authenticated wireless devices, the access point being characterized in that it is configured to accept that the wireless terminal device uses one of the following authentication methods with views to authenticate with the communications network: a first authentication method in which the access point is configured to relay authentication information between the wireless terminal device and the authentication server, a second authentication method in which the access point is configured to relay authentication information between the wireless terminal device and an authentication agent, whereby the access point further comprises identification means intended to identify whether the wireless terminal device is using the first authentication method or the second authentication method, a first relay means for relaying the authentication information between the wireless terminal device and the authentication server as a response to a situation where it has been identified that the wireless terminal device is using the first authentication method, a first means of sending intended to send the identifying data of the wireless terminal device, as a response to a successful authentication of the wireless terminal device according to the first authentication method, to the access control list, a second relay means intended to relay the authentication information between the wireless terminal device and the authentication agent as a response to a situation where the wireless terminal device has been identified as using the second authentication method, and second sending means for sending identifying data of the wireless terminal device, as a response to the successful authentication of the wireless terminal device according to the second authentication method, to the access control list.
According to a third aspect of the invention, there is provided a system for access control of a wireless terminal device in a communication network, the communication network comprising: an access point to establish a communication connection to the wireless terminal device, an authentication server to provide an authentication service in order for the wireless terminal device to authenticate with the communication network, a destination authentication agent7
ES 2 274 358 T3 do to relay authentication information between wireless terminal device and authentication server, and a gatekeeper to relay data packets from authenticated wireless terminal devices and block data packets from unauthenticated wireless devices , a gatekeeper functionality comprising an access control list that is a list of authenticated wireless terminal devices, said wireless terminal device being configured to use one of the following authentication methods in order to authenticate with the communications network: a first authentication method in which the access point is configured to relay authentication information between the wireless terminal device and the authentication server, a second authentication method in which the authentication agent relays authentication information between the end device wireless and the authentication server, the system being characterized because it comprises: identification means to identify at the access point whether the wireless terminal device is using the first authentication method or the second authentication method, first relay means intended to relay the authentication information of the first method at the access point authentication between the wireless terminal device and the authentication server, a second relay means intended to relay at the access point the authentication information of the second authentication method between the wireless terminal device and the authentication agent, a third relay means at the authentication agent to relay the authentication information of the second authentication method between the access point and the authentication server, a first sending means intended to send from the access point identifying data of the wireless terminal device, as a response to the successful authentication of the wireless terminal device according to the first authentication method, to the access control list, a second means of sending destined to send from the authentication agent identifying data of the wireless terminal device, as a response to the successful authentication of the wireless terminal device according to the second authentication method, to the access control list, and a relay means in the gatekeeper functionality to relay data packets of the wireless terminal device included in the access control list.
The invention will now be described in more detail with reference to the accompanying drawings, in which Figure 1 is a flow chart illustrating a method according to an embodiment of the invention;
Figure 2 shows a device according to an embodiment of the invention;
Figure 3 shows the current Nokia Operator WLAN system;
Figure 4 shows a system according to the IEEE 802.1x protocol;
Figure 5 shows a system according to an embodiment of the invention;
Figure 6 shows a flow chart of a method according to an alternative embodiment of the invention;
Figure 7 shows an access point according to an alternative embodiment of the invention; and Figure 8 shows a system according to an alternative embodiment of the invention.
Figure 1 shows a method flow chart according to an embodiment of the invention. In step 101, an access point, and a terminal device, such as a wireless communication device, establish a connection and associate with each other. Then, at the initiative of the access point, the routine checks whether it is an authentication according to the second protocol layer (step 102) or an open systems authentication according to the third protocol layer (step 103). This check is done at the access point based on authentication and association messages as will be explained later. In a WLAN system according to the IEEE 802.11 standard, if the terminal is using open systems authentication, it first sends an authentication request message indicating open systems authentication to the access point. The access point responds with an authentication response message. In reality, the exchange of these initial authentication messages does not authenticate the terminal but its function is null; hence the name open systems authentication. Such open systems authentication is also possible in WLAN systems according to the IEEE 802.11i standard. In a WLAN system according to the IEEE 802.11i standard, if the terminal is using the 802.1x authentication method, there are no initial authentication request and response messages, but the terminal first associates itself with the access point by sending a request for authentication. association to the access point. The request comprises a request for authentication using the authentication method according to the IEEE 802.1x standard. In this way, the access point identifies the authentication method that the end device is using based on the authentication and association messages. If the terminal uses the Open Systems Authentication method, the terminal receives an IP address, for example, from a DHCP server, which may be located at the access point, the authentication agent, or somewhere else in the network. network (104), after which an IP-based authentication protocol according to the third protocol layer (105) is executed. IP layer authentication is performed between a terminal device and an authentication agent. After successful IP layer authentication, the authenticated terminal is updated on an access control list maintained on the network element that includes gatekeeper functionality (step 106 and 107). This allows the gatekeeper to retransmit data packets from the terminal device. If the gatekeeper functionality resides in the authentication agent, then the authentication agent is capable of independently updating the access control list by internally sending the terminal identifier data to the gatekeeper functionality. If the gatekeeper functionality resides in some other network element than the authentication agent, then the authentication agent can update the access control list by sending a message to the network element that
ES 2 274 358 T3 contains gatekeeper functionality. For example, this message can be sent over the IP protocol using the User Datagram Protocol (UDP). The message includes at least the identifying data of the authenticated terminal, such as an IP address of the terminal, which is to be updated in the access control list.
If the terminal device is authenticated according to the second protocol layer, the IEEE 802.1x protocol (step 102), authentication is first performed between the terminal device and the access point (step 108). After a successful authentication according to the IEEE 802.1x protocol, the terminal receives an IP address, for example, from the DHCP server, which can be located for example in the access point or in the authentication agent, or in some other site of the network (step 109), and the access point transmits information about the event to the gatekeeper functionality (step 106). If the access point contains gatekeeper functionality, then the access point independently updates the access control list by internally sending the terminal information to the gatekeeper functionality. If the gatekeeper functionality resides in some other network element than the access point, then the access point updates the access control list by sending a message to the network element that contains the gatekeeper functionality. access. For example, this message can be sent over the IP protocol using the User Datagram Protocol (UDP). The message includes at least the identifying data of the authenticated terminal, such as an IP address or a MAC address of the terminal, which is to be updated in the access control list. Next, the gatekeeper functionality adds to the list that maintains (step 107) the information, for example, the IP or MAC address of the authenticated end device. This allows the gatekeeper functionality to retransmit data packets from the terminal (step 110).
Even if the gatekeeper functionality is separate from the authenticating entity, such as the access point or authentication agent, the authenticating entity should not necessarily send explicit information of a successful authentication to the gatekeeper if the gatekeeper can reach that conclusion in another way, for example, in the following way. In connection with authentication, the authenticating entity typically communicates with the authentication server, which is also within the network. Communication usually takes place using what is known as the AAA (Authentication, Authorization, Accounting) protocol, for example the RADIUS (Remote Authentication Dialing User Service) or DIAMETER protocol. If the gatekeeper functionality functions as a RADIUS proxy server and transmits AAA protocol messages between the authenticating entity and the authentication server, the gatekeeper functionality already obtains information about successful authentication by examining the RADIUS messages. One of the problems that arises in this situation in the case of IEEE 802.1x authentication is that the gatekeeper needs the IP address of the terminal device, which is not yet known at the time the authentication is successful, in order to the list he keeps. However, if the gatekeeper functionality acts as a DHCP server distributing IP addresses after 802.1x authentication, then the list can be updated by combining, in the gatekeeper functionality, information about the successful authentication, the address MAC of the terminal obtained in this way, and the successful execution of the DHCP protocol, with which an IP address corresponding to the MAC address is obtained.
Figure 2 shows an access point 200 of an embodiment of the invention. The access point 200 comprises a processor 201 and a memory 202 for executing the operations in question and at least one application 203 for carrying out, for example, identification, an authentication method. The access point 200 further comprises an interface 205 for connection with the router, with servers, such as a gatekeeper, or, for example, an authentication server. The access point further comprises identification means 207 for identifying whether the terminal device is using the first or the second authentication method. Preferably, the access point identifies the authentication method by receiving a message from the terminal, said message indicating the authentication method the terminal is using. If the terminal uses the open systems authentication method, the message is preferably an authentication request message according to the IEEE 802.11 standard, said authentication request message indicates open systems authentication. If the terminal uses the IEEE 802.1x authentication method, the message is an association request message preferably according to the IEEE 802.11i standard. Said association request message comprises an authentication set element indicating IEEE 802.1x authentication. The access point further comprises sending means for sending the identifying data of the authenticated terminal to the gatekeeper list if the terminal device is using the authentication method in which the access point relays authentication information between the terminal and the authentication server. The access point further comprises relay means 206 for relaying authentication information between the terminal device of one of the following: the authentication server if the terminal device is using the first authentication method, the authentication agent if the device terminal is using the second authentication method. In cases where the logical access control functionality is contained in the access point, the access point further comprises access control means 208 for relaying authenticated terminal data packets and blocking non-terminal data packets. authenticated.
A terminal using the open systems authentication method receives an IP address to be used from the DHCP server, which may be located at the authentication agent, or alternatively, at the access point or somewhere else on the network . The access point 200 relays authentication messages between the terminal and the authentication agent, which functions as the authenticating entity and authenticates the terminal device using the third party's IP-based authentication method.
ES 2 274 358 T3 protocol layer. Typically, the authentication agent uses the authentication service provided by the authentication server by further relaying the authentication information between the terminal device and the authentication server, which verifies the authentication information. After authentication, the authentication agent sends information about a successful authentication and the terminal identifier data, such as the terminal's IP address or MAC address, to the gatekeeper, which adds them to the control list of port 204 and begins retransmitting the terminal data packets.
When a terminal uses the IEEE 802.1x protocol for authentication, the access point functions as an authenticator and authenticates the terminal using the IEEE 802.1x protocol of the second protocol layer. Typically, the access point uses the authentication service provided by the authentication server by relaying the authentication information between the terminal device and the authentication server, which verifies the authentication information. The access point sends information about a successful authentication and the identifying data of the terminal, such as the IP address of the terminal or the MAC address, to the gatekeeper, which adds the identifying data of the terminal to the access control list 204 and begins to retransmit the terminal data packets.
Figure 3 shows the current Nokia Operator WLAN system. The system comprises a wireless terminal device 303, such as a WLAN terminal, which is configured to use open systems authentication in order to authenticate with the network, an access point 301, to provide a wireless connection from the communication device 303 to the network, a gatekeeper 302 to relay authentication information between the terminal device 303 and an authentication server 307, to maintain a gatekeeper list 309 of authenticated terminal devices (eg, terminal device 303) and to relay data packets from said authenticated terminal devices included in list 309. The system further comprises the authentication server 307 to provide an authentication service to an authenticator, such as the access point 301 by determining whether the terminal device is authorized to access the services provided by the access point. The system may further comprise servers, such as a DHCP server 305 to provide an IP address to the terminal device 302 when using open systems authentication, an accounting server 306 to keep an accounting of the amount of data transferred to and from the terminal device and a router 308 for routing data packets from the terminal device.
When authentication of the wireless terminal device according to the third protocol layer, such as open systems authentication, is performed, the terminal device 303 is associated with the access point 301. The authentication is not yet performed at this time. An IP address is formed for the terminal device 303, for example, by means of the DHCP protocol. Next comes the actual authentication of the third protocol layer. In one embodiment of the OWLAN system, for example, the communication device 303 broadcasts a page message to search for an authentication server 307, the authentication server 307 responding to said message. Based on the response message, terminal device 303 knows that the network in question requires IP-based third protocol layer authentication between terminal device 303 and gatekeeper 302. Gatekeeper 302 exchanges authentication messages with authentication server 307. In SIM authentication, for example, the International Mobile Subscriber Identity (IMSI) is transmitted to authentication server 307. Gatekeeper 302 communicates with the authentication server 306 using an AAA (Authentication, Authorization, Accounting) protocol, such as the RADIUS (Remote Authentication Dialing User Service) or DIAMETER protocol.
The authentication server 307 obtains GSM challenges (the GSM challenge is a parameter, that is, a random number of 128 bits, used in a GSM authentication), and sends the challenges to the gatekeeper 302, using the AAA protocol, which it further relays them to terminal device 303 using the third layer authentication protocol NAAP protocol. The terminal device 303 then calculates a response value corresponding to the challenge issued using a secret key stored on the SIM card. The response value is a 32-bit number and the terminal device sends the response to gatekeeper 302, with the authentication protocol of the third protocol layer. Gatekeeper 302 relays the information to authentication server 307 with the AAA protocol. Authentication server 307 verifies the response by checking whether or not the terminal has calculated a correct response value. If the response received is correct, the authentication server 307 sends a successful authentication indication to the gatekeeper 302 with the AAA protocol, which relays the indication to the terminal 303 with the authentication protocol of the third protocol layer. After authentication, the identifying data from the terminal device 303 is added to the access control list 309 by the access controller 302. The access controller 302 only transmits data packets from the communications device whose identifying data, such as an IP or MAC address, they are found in list 309.
Figure 4 shows a system according to the IEEE 802.1x protocol. The system comprises a wireless terminal device 404, such as a WLAN terminal, configured to use the authentication method according to the IEEE 802.1x protocol in order to authenticate with the network, an access point 401 to establish a communication connection with the device terminal 404 and for relaying authentication information between terminal device 404 and an authentication server 402. The system further comprises the authentication server 402 to provide an authentication service to an authenticator, such as the access point 401, determining if the terminal device 404 is authorized to access the services provided by the access point 401 and a server. accounting 405 for keeping an accounting of the amount of data transferred to and from the terminal device. The system comprises
ES 2 274 358 T3 also one or more routers 403 to route data packets from terminal device 404.
Authentication entity, such as access point 401, typically communicates with authentication server 402 using AAA (Authentication, Authorization, Accounting) protocol, similar to Nokia's Operator Wireless LAN solution described above in Figure 3. When the terminal has been successfully authenticated, the access point relays data packets between the terminal device 404 and the router 403.
Figure 5 shows a system according to an embodiment of the invention. In the following, the invention is illustrated by way of example in an environment comprising a wireless terminal device 303, such as a WLAN terminal, that can be authenticated using a third protocol layer authentication method, such as systems authentication. open and a wireless terminal device 404, such as a WLAN terminal, which can be authenticated using the authentication method according to the IEEE 802.1x standard, such as a Wireless LAN terminal that uses the IEEE 802.11i standard. The terminals are capable of establishing a connection with a communication network, which comprises an access point 501, to provide a wireless connection from the communication device 303, 304 to the network and to relay authentication information between the terminal device 404 and an authentication server 505. The access point comprises a logic access controller functionality 502 for relaying data packets from the authenticated terminal and blocking data packets from unauthenticated terminals, and a list 503 of authenticated terminal devices. Gatekeeper functionality 502 and list 503 may alternatively be located, for example, at an authentication agent 504, a router 508, or somewhere else on the network. The system further comprises an authentication agent 504 for relaying authentication information between the terminal device 303 and the authentication server 505. The system further comprises servers, such as a DHCP server 506 to provide an IP address for the terminal device 303, an accounting server 507 to keep an accounting of the amount of data transferred to and from the terminal device, and an authentication server. 505 to provide an authentication service to an authenticator. The authenticator is one of the following: access point 501 or authentication agent 504. The authentication server 505 determines whether the terminal device is authorized to access the services provided by the authenticator. The system further comprises one or more routers 508 for routing data packets from terminal devices 303, 404.
Access point 501 sends messages, such as IEEE 802.11i or IEEE 802.11 beacon messages, to the access point environment. Said beacon message may comprise an authentication set element that further comprises information on the authentication method with which the access point can operate, for example, the authentication method according to the IEEE 802.11i standard. A wireless terminal 404 that implements the IEEE 802.11i standard will recognize that the access point supports the IEEE 802.1x authentication protocol. A wireless terminal 303 that does not implement the IEEE 802.11i standard does not process the authentication set element, but interprets the beacon message according to the IEEE 802.11 standard and thus recognizes that the access point 501 supports open systems associations. Terminal 303, 404 receives the beacon message sent from access point 501. Terminal device 303, 404 can obtain multiple beacon messages from various access points that are within range of the terminal. As an alternative to beacon messages, the terminal 303, 404, can also become aware of local access points by sending messages, such as a probe request message according to the IEEE 802.11 or IEEE 802.11 standard, to all access points that are within range of the terminal. When the access point 501 receives the probe request message, the terminal 303, 404 sends, in response to said probe request, a message, such as the probe response message according to the IEEE 802.11 or IEEE 802.11 standard. The probe response message to the terminal device 404 is sent according to the IEEE 802.11i standard and comprises the authentication set element comprising information about the authentication method. The probe response message to the terminal device 303 can be sent in accordance with the IEEE 802.11 standard and therefore does not need to include the authentication set element. Terminal 303, 404 receives the probe response message from access point 501. Terminal device 303, 404 may obtain multiple probe response messages from various access points within range of the terminal.
After discovering suitable local access points based on beacon messages or probe messages, the terminal device 303, 404 selects the access point that supports the authentication method that the terminal is using. The terminal device 404 that supports the IEEE 802.11i standard and wants to use the IEEE 802.1x authentication method adds the authentication set element to the message, such as an association request message according to the IEEE802.11i standard. Terminal device 303 that wishes to use open systems authentication first initiates open authentication by sending an authentication request message, to which access point 501 responds with an authentication response message indicating successful authentication. After open authentication comes association. Terminal device 303 does not include any authentication set elements in the association messages it sends. After this, the terminal 303, 404 sends the association request message to the access point. Based on the authentication or association request message, access point 501 identifies the authentication method that terminal device 303, 404 is using.
When the authentication of the wireless communication device according to the third layer of the protocol is carried out, the communication device 303 is associated with the access point 501, the authentication not being carried out yet at this time. An IP address is formed for the communication device 303, for example, by means of the DHCP protocol. Next comes the actual authentication of the third protocol layer. In one of the embodiments of the OWLAN system, for
For example, the terminal device 303 broadcasts a search message to search for an authentication agent 504, the authentication agent responding to said message. Based on the response message, the communications device 303 knows that the network in question requires IP-based third protocol layer authentication between the communications device 303 and the authentication agent 504. Authentication agent 504 exchanges authentication messages with authentication server 505 using an AAA protocol. The authentication procedure is similar to the Nokia Carrier Wireless LAN system described in Figure 3. The authentication agent 504 receives a notification of successful authentication from the authentication server 507 via the AAA protocol. After authentication, the authentication agent sends the identifying data, such as an IP address, from the terminal device 303, to the gatekeeper functionality 502. In this embodiment, the gatekeeper functionality 502 is implemented in the access point device 501. Authentication agent 504 sends a message to access point 501. For example, the message can be formed using the User Datagram Protocol (UDP) over the Internet Protocol (IP). The message includes at least the identifying data from the terminal device 303. Upon receipt of the message, the gatekeeper functionality 502 at the access point 501 adds the identifying data to the access control list 503. Gatekeeper functionality 502 only relays data packets from the terminal device whose identifying data, such as an IP or MAC address, is found in list 503. Typically, authentication must be repeated after a specified period of time by the communications device, for example if the end device is disabled (due to low battery), leaves the network (shadow zone), or automatically interrupts. the use of a service. Gatekeeper 502 keeps track of the duration of the communication device 303 connection and the number of transmitted / received data packets. Gatekeeper 502 sends the information to authentication server 505 or accounting server 507, for example, to serve as the basis for user billing. Alternatively, authentication can be carried out according to the third protocol layer in such a way that when the user activates a browser of the Multimedia World Wide Web (WWW), the authentication agent 504 sends to the browser of the terminal 303 a page that interrogates on the identification of the user and the password, with which the user is identified and the same is added to the access control list 503. Still alternatively, authentication according to the third protocol layer can be carried out using Virtual Private Network (VPN) software, in which user authentication is typically performed as part of the Internet Key Exchange protocol ( IKE).
In the second protocol layer authentication, the communication device 404 and the access point 501 reach an agreement already during the association that they will use WLAN authentication (and not open systems authentication as in third party authentication). protocol layer). WLAN authentication is carried out as specified in the IEEE 802.1x protocol. After successful authentication, gatekeeper functionality 502 is informed of the event and adds the authenticated end device 304 according to the second protocol layer to access control list 503 and begins retransmitting packets. of the authenticated end device. Since gatekeeper functionality 502 is implemented in access point device 501, access point 501 is capable of locally sending terminal identifier data to gatekeeper functionality 502. The access control list 503 comprises identifying data of authenticated terminals according to both the third and second protocol layers. After the authentication of the second protocol layer, it is no longer necessary for the authentication agent 504 to subject the terminal device 404 to the authentication of the third protocol layer, thanks to the fact that the identifying data of the terminal device 404 is already in the list 503.
In an alternative embodiment of the present invention, service differentiation is provided for different classes of terminal devices. Figure 6 shows a flow chart of a method according to the alternative embodiment of the invention. In step 601, an access point, and a terminal device, such as a wireless communication device, establish a connection and associate with each other. At the initiative of the access point, the routine then checks whether it is an authentication according to the second protocol layer or an open systems authentication according to the third protocol layer, step 602. The terminal establishes communications with the point of access. access by sending an authentication or association request to the access point. The request comprises a request for authentication using the authentication method that the device is using. In step 603, the WLAN access point classifies the WLAN clients into different classes based preferably on the authentication method used by the WLAN clients or based on some other parameters that are exchanged during the association and authentication phase. In step 604, the access point relays data packets based on the classification. When data packets are relayed between the wireless network and the wired network (Distribution System, DS), the class of client is taken into account. For example, the authentication method, which is selected in the association, can be used to classify users so that open systems clients are directed to a different Virtual LAN (VLAN) than IEEE 802.1x / 802.11 clients. i. In the case of 802.1x, the access point can further differentiate clients based on the domain name part of the user identity (Network Access Identifier, NAI). The domain name identifies the RADIUS server that authenticates the user. For example, an enterprise WLAN access point can direct clients that are authenticated by the enterprise RADIUS server to a different VLAN than clients that are authenticated by other RADIUS servers. For the sake of simplicity, the authentication method (open system or IEEE 802.1x) is used here as an example of the parameter according to which the access point classifies wireless terminals into different classes. For a
It will be clear from a person skilled in the art that the invention is not limited to the classification of terminals according to the authentication method and that there are other parameters according to which the access point can divide terminals into independent classes. The access point can use any parameter that it is aware of at the time of the establishment of communications as the basis for the classification. The parameter can be related to radio communication technology, authentication or association or other areas of the communication establishment, such as the radio frequency band, the data rate used by the terminal, the Network Access Identifier or part of it, or the type of Extensible Authentication Protocol (EAP) used in IEEE 802.1x authentication.
Figure 7 shows an access point according to an alternative embodiment of the invention. The access point 700 comprises a processor 701 and a memory 702 for executing the operations in question and at least one application 703 for carrying out, for example, identification, an authentication method. The access point 700 further comprises an interface 705 for connection to the router, to servers, such as a gatekeeper, or, for example, an authentication server. The access point further comprises identification means 207 to identify, upon establishment of the communication, whether the terminal device is using the first or the second authentication method. Preferably, the access point identifies the authentication method by receiving a message from the terminal, said message comprising the authentication method the terminal is using. If the terminal is using the first authentication method, the message is preferably an association request message according to the IEEE 802.11i standard, said association request message comprising an authentication set element indicating IEEE 802.1x authentication. If the terminal is using the second authentication method, the message is preferably an authentication request message according to the IEEE 802.11 standard, said authentication request message indicating open systems authentication. The device further comprises a classification means 704 for classifying terminals into different classes based on the identified authentication method. The access point further comprises relay means 706 for relaying data packets from the wireless terminals between the wireless network and the wired network, said relay means taking into account the class of the customer when directing data packets from terminal devices of different classes to independent logical channels. Using different Virtual LANs for different terminal classes is an example of how to take into account the terminal class when relaying data packets. Upon receipt of a data packet from a wireless terminal, the access point first detects the terminal class corresponding to the sending wireless terminal preferably based on the source MAC address field of the data packet and then retransmits the packet. data to the wireless network using the Identifier of the Virtual LAN associated with the terminal class, so that packets from open systems clients are retransmitted using a different Virtual LAN identifier than packets from 802.1x clients. In addition, upon receipt of a unicast data packet from the wired network, the access point first detects the terminal class corresponding to the destination wireless terminal, preferably based on the destination MAC address field of the data packet, and then verifies that the Virtual LAN Identifier of the data packet is correct, that is, what it should be for the detected terminal class. The access point only relays the data packet to the destination wireless terminal if the packet was received from the wired network with the correct Virtual LAN Identifier. If the Virtual LAN identifier is incorrect, the access point preferentially rejects the data packet. When receiving a multicast or broadcast data packet from the wired network, the access point cannot detect the terminal class for an individual terminal device, as there may be multiple destinations. In this case, the access point can still process the data packets according to the terminal class indicated in the Virtual LAN identifier. For example, multicast or broadcast data frames intended for open systems clients can be transmitted without encryption or integrity protection, whereas multicast or broadcast data frames intended for IEEE 802.1x clients can be transmitted without encryption or integrity protection. IEEE 802.11i packet security can apply to them.
As an alternative to Virtual LANs, the access point can differentiate data packets based on IP subnet or IP address range. In this example, the access point ensures that the wireless terminal is assigned an IP address from the subnet or IP range that corresponds to the class of terminal identified when communications were established. Preferably, the access point relays the DHCP packets sent by the wireless terminal in the IP configuration phase to a suitable DHCP server based on the terminal class, so that the terminal is assigned an IP subnet address or range of correct IP addresses. Upon receipt of a data packet from a wireless terminal, the access point first detects the terminal class preferably based on the source MAC address field of the data packet and then verifies that the IP address field source (or other protocol field comprising an IP address) of the received data packet belongs to the correct IP subnet or IP address range, associated with the detected terminal class. The access point only relays the data packet to the wired network if this verification is successful. If this verification is not successful, preferably the access point rejects the data packet. In addition, upon receipt of a unicast data packet from the wired network, the access point first detects the terminal class preferably based on the destination MAC address field, and then verifies that the destination field destination IP address of the data packet belongs to the IP subnet or address range19
ES 2 274 358 T3 correct IP settings, associated with the class of terminal detected. The access point only retransmits the data packet to the destination wireless terminal if this verification is successful. If this verification is not successful, the access point preferably rejects the data packet. Upon reception of a multicast or broadcast data packet from the wired network, the access point can still detect a correct terminal class based on a protocol field comprising an IP address. Different processing, such as different encryption or integrity protection, may be applied to multicast or broadcast data packets intended for open systems clients and IEEE 802.1x clients. For the sake of simplicity, the use of separate Virtual LANs for different client classes is used as an example of how the access point takes into account the terminal class when relaying data packets between the wireless terminals and the wired network. . It will be apparent to a person skilled in the art that the invention is not limited to the use of different Virtual LANs for each class of terminal and that there are other ways of taking the class of terminal into account in relaying data packets. As an alternative to Virtual LANs, the access point can take into account the class of the terminal using any method of differentiating data packets into independent logical channels, based on the class of the terminal, when relaying data packets between the wireless network. and the wired network. Another example of such a method is tunneling packets to different destinations based on the class of the terminal. Upon receipt of a data packet from the wireless terminal, the access point detects the terminal class preferably based on the source MAC address field of the received packet. The access point then encapsulates the received packet into a new packet. The destination of the new packet is selected based on the class of the terminal, so that different terminal classes are tunnelled to different destinations. The encapsulation is preferably an IP encapsulation, in which the original MAC header is removed, and the resulting IP packet is encapsulated within a new IP packet. The IP packet is then forwarded based on the new IP destination address. Correspondingly, data packets received from the wired network can also be tunnelled. Upon reception of a data packet from the wireless network, the access point detects the terminal class preferably based on the source IP address in the external IP header, when different starting points are used for each terminal class tunneling. The access point then decapsulates the tunnelled packet and relays the resulting data packet to the destination wireless terminal.
Figure 8 shows a system according to an alternative embodiment of the invention. In the following, the invention is illustrated by way of example in an environment comprising a terminal device 303 that can be authenticated using a third protocol layer authentication method, such as open systems authentication and a terminal 404 that can be authenticated. authenticate using the authentication method according to the IEEE 802.1x standard, such as a Wireless LAN terminal using the IEEE 802.11i standard. The terminals are capable of establishing a connection to a communication network, which comprises an access point 801, to provide a wireless connection from the communication device 303,404 to the network and to relay authentication information between the terminal device 404 and a authentication server 806. The system further comprises an access controller 802, comprising a logical access controller functionality for relaying data packets from the terminal authenticated by the open system and blocking unauthenticated terminal data packets, and a list 803 of terminal devices in the system. authenticated open. Gatekeeper 802 is relaying authentication information between terminal device 303 and authentication server 806. The system further comprises servers, such as a DHCP server 804 to provide an IP address for the terminal device 303, an accounting server 805 to keep an accounting of the amount of data transferred to and from the terminal device, and an authentication server.
806 to provide an authentication service to an authenticator, said authenticator being one of the following: access point 801 and access controller 802, determining whether the terminal device is authorized to access the services provided by the authenticator, and one or more routers
807 to route data packets from terminal devices 303, 404.
This illustrative system is arranged such that network access control for open system terminal 303 is implemented in access controller 802, and network access control for IEEE 802.1x terminal 404 is implemented. on the access point device 801. The arrangement is based on the classification of data packets, which is placed in the access point device 801, into independent logical channels based on the authentication method of the terminal.
When a terminal device 303 using the open systems authentication method establishes communications with the access point, the access point 801 assigns the terminal 303 to a terminal class for which the gatekeeper 802 uses an access control in the third layer of the protocol. Using Virtual LANs, gatekeeper 802 is configured to enforce access control for received data packets with a Virtual LAN identifier assigned to open systems terminals. If separate IP subnets or ranges of IP addresses are used to separate data packets into logical channels, the gatekeeper 802 is configured to enforce access control on data packets from terminals 303 using an IP address from within the subnet. or IP address range of open systems terminals.
When a terminal device 404 establishes communications with access point 801 and authenticates with the IEEE 802.1x authentication method, access point 801 assigns terminal 404 to a terminal class for which access controller 802 does not use a access control. With Virtual LANs, it is possible to configure the 802 gatekeeper to route data packets with the Virtual LAN identifier associated with the IEEE 802.1x 404 terminal.
ES 2 274 358 T3 without imposing any access control. As an alternative, the Virtual LAN associated with the IEEE 802.1x 404 terminals can use another 807 router device through which the data packets from the IEEE 802.1x 404 terminals are routed, so that the data packets do not pass through the controller. access 802. If separate IP subnets or ranges of IP addresses are used to separate data packets into logical channels, the gatekeeper 802 can be configured to route data packets from terminals 404 using one IP address from among the subnets or range of IP addresses. IEEE 802.1x terminals without imposing access control.
The alternative embodiment of the invention according to Figures 6 to 8 makes it possible to use the same WLAN radio network for various purposes. The same radio network can serve legacy WLAN clients such as OWLAN version 1 clients using open systems authentication, and newer WLAN clients using new IEEE standards, such as OWLAN version 2 clients using authentication. IEEE 802.1x. An extreme implementation of the access point of the present invention could be viewed by wireless communication clients as two independent access points. One of the "virtual" access points would allow open systems associations and the other access point 802.1x associations. A simpler implementation would be viewed as a single access point although it would support both open association and 802.1x association.
Another objective of the alternative embodiment is the protected networks that are currently built on the technology of Virtual Private Networks (VPN), such as company networks. One of the access points implementing the present invention could route open systems clients to the existing LAN which is separated by a VPN gateway from the protected network. For this reason, open systems clients will need to establish a VPN connection to access the protected network. The access point could route IEEE 802.11i clients to a different Virtual LAN, which presents direct connectivity to the protected network. Thus, the present invention provides a managed deployment pathway from the current enterprise WLAN solution to the new IEEE 802.11i solution.
In another illustrative system using the alternate embodiment of the present invention, terminal classification in the access point device can be used to direct data packets from terminal devices using open systems authentication to an uncontrolled network. , in which no access control is imposed. Such an uncontrolled network can be a local intranet or other network with limited and free resources that are available to anyone. In this example, data packets from end devices using IEEE 802.1x authentication are directed to a controlled network, such as the global Internet network. Such a controlled network is such that it is only available to terminals that authenticate using the IEEE 802.1x authentication method.
The advantages of the alternative embodiment described above are: a single WLAN radio network can safely support both legacy and new WLAN clients, legacy and new WLAN clients can use different IP subnets and different services, no support is required on wireless stations.
The invention is not limited to open systems authentication and authentication according to the IEEE802.11i protocol or the IEEE 802.1x protocol. The first embodiment of the invention can be used in any of the mentioned systems in which a terminal can access the network using an access point or an authentication agent as authenticator. The second embodiment of the invention can be used in any of the aforementioned systems where it is advantageous to provide a different service for different classes of terminals, said identified class of terminal relying on a call setup parameter.
The above description illustrates the implementation of the invention and its embodiments by means of examples. It will be clear to a person skilled in the art that the invention is not limited to the details of the embodiments described above and that there are also other ways of implementing the invention without deviating from the characteristics thereof. Therefore, the above embodiments should be considered illustrative and not limiting. Thus, the possibilities of implementing and using the invention are limited only by the appended claims and for this reason the different alternative implementations of the invention, including equivalent implementations, defined in the claims, also belong to the scope of the invention.
Contents2
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
15 members in 5 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 02250352 | European Patent Office (EPO) | A | |
| 02250352 | European Patent Office (EPO) | A | |
| 04018185 | – | – | – |
| EP20020250352 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| EP1330073A1 | European Patent Office (EPO) | A1 | |
| US2004208151A1 | United States of America | A1 | |
| EP1523129A2 | European Patent Office (EPO) | A2 | |
| EP1523129A3 | European Patent Office (EPO) | A3 | |
| EP1330073B1 | European Patent Office (EPO) | B1 | |
| AT320684T | Austria | T | |
| ATE320684T1 | Austria | T1 | |
| DE60209858D1 | Germany | D1 | |
| ES2258134T3 | Spain | T3 | |
| DE60209858T2 | Germany | T2 | |
| EP1523129B1 | European Patent Office (EPO) | B1 | |
| AT345000T | Austria | T | |
| ATE345000T1 | Austria | T1 | |
| ES2274358T3This record | Spain | T3 | |
| US8045530B2 | United States of America | B2 |
Numbers
- Publication
- 2274358
- Publication, DOCDB
- 2274358
- Publication, EPODOC
- ES2274358T
- Application
- 4018185
- Application, DOCDB
- 04018185
- Application, EPODOC
- ES20040018185T
Titles2
- Spanish
- METODO Y APARATO PARA EL CONTROL DEL ACCESO DE UN DIPOSITIVO TERMINAL INLAMBRICO EN UNA RED DE COMUNICACIONES.
- English
- METHOD AND APPLIANCE FOR CONTROLLING THE ACCESS OF A WIRELESS TERMINAL DEVICE IN A COMMUNICATIONS NETWORK.
Classification
- CPC, 11
- H04L61/10
- H04L63/08
- H04L63/10
- H04W88/08
- H04L63/0236
- H04L63/101
- H04W84/12
- H04L63/205
- H04W12/069
- H04L61/50
- H04L61/00
- IPC, 7
- H04L12 28
- H04L12 56
- H04L29 06
- H04L29 12
- H04W12 06
- H04W74 00
- H04W88 08