Provisioning communication nodes
Abstract
A communication procedure performed by a network node (110), comprising: receiving (806) a request from at least one access point (102) in response to an access terminal (108) that attempts to access at least one service provided by the at least one access point (102); determining (808) an identifier of the access terminal (108), indicative of a set of access terminals to which the access terminal (108) belongs; send (810) the identifier to at least one access point in order to allow the at least one access point (102) to compare the identifier with a list of identifiers indicative of access terminal sets stored in the at least one access point (102), and determine if the access terminal is allowed to access at least one service based on the comparison.

Term
2 yearsto projected expiry
Projected expiry 7 October 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
12 claims: 5 independent, 7 dependent
- 1ES 2 608 454 T3 REIVINDICACIONES 1. Un procedimiento de comunicación realizado por un nodo de red (110), que comprende:recibir (806) una solicitud desde al menos un punto de acceso (102) en respuesta a un terminal de acceso (108) que intente acceder al menos a un servicio proporcionado por el al menos un punto de acceso (102);determinar (808) un identificador del terminal de acceso (108), indicativo de un conjunto de terminales de acceso a los que pertenece el terminal de acceso (108);enviar (810) el identificador al al menos un punto de acceso con el fin de permitir que el al menos un punto de acceso (102) compare el identificador con una lista de identificadores indicativos de conjuntos de terminales de acceso almacenados en el al menos un punto de acceso ( 102), y determinar si se permite que el terminal de acceso acceda al al menos un servicio en base a la comparación.
- 2El procedimiento de la reivindicación 1, en el que la determinación (808) comprende recibir el identificador desde un servidor de la Red que permite a un usuario especificar terminales de acceso (108) a los que se permite recibir el al menos un servicio desde el al menos un punto de acceso (102).
- 3El procedimiento de la reivindicación 1, en el que el conjunto de terminales de acceso está asociado a un grupo cerrado común de abonados.
- 4El procedimiento de la reivindicación 1, en el que cada punto de acceso (102) del al menos un punto de acceso (102) está restringido a no proporcionar, para al menos otro terminal de acceso (108), al menos uno del grupo que consiste en:señalización, acceso a datos, registro y servicio.
- 5Un nodo de red (110), que comprende:medios para recibir (806) una solicitud desde al menos un punto de acceso (102) en respuesta a un terminal de acceso (108) que intenta acceder a al menos un servicio proporcionado por el al menos un punto de acceso (102);medios para determinar (808) un identificador del terminal de acceso (108), indicativo de un conjunto de terminales de acceso a los que pertenece el terminal de acceso (108);medios para enviar (810) el identificador al al menos un punto de acceso, con el fin de permitir que al menos un punto de acceso (102) compare el identificador con una lista de identificadores indicativos de conjuntos de terminales de acceso almacenados en el al menos un punto de acceso (102), y para determinar si se permite que el terminal de acceso acceda al al menos a un servicio, en base a la comparación.
- 6El nodo de red (110) de la reivindicación 5, en el que la determinación (808) comprende recibir el identificador desde un servidor de la Red que permite a un usuario especificar terminales de acceso que están autorizados para recibir el al menos un servicio desde el al menos un punto de acceso (102).
- 7El nodo de red (110) de la reivindicación 5, en el que el conjunto de terminales de acceso están asociados a un grupo cerrado común de abonados.
- 8El nodo de red (110) de la reivindicación 5, en el que cada punto de acceso del al menos un punto de acceso (102) está restringido a no proporcionar, para al menos otro terminal de acceso (108), al menos uno del grupo que consiste en:señalización, acceso a datos, registro y servicio.
- 9El nodo de red (110) de la reivindicación 7, en el que los medios para la determinación incluyen un controlador de dotación, y en el que los medios para el envío incluyen un controlador de comunicación.
- 10Un punto de acceso (102), que comprende:medios para transmitir (806) una solicitud a un nodo de red (110) en respuesta a un terminal de acceso (108) que intenta acceder al menos a un servicio proporcionado por el punto de acceso (102);medios para recibir un identificador indicativo de un conjunto de terminales de acceso a los que pertenece el terminal de acceso (108);y medios para comparar el identificador con una lista de identificadores indicativos de conjuntos de terminales de acceso almacenados en el al menos un punto de acceso (102);medios para determinar si se permite que el terminal de acceso (108) acceda al al menos un servicio, en base a la comparación. ES 2 608 454 T3
- 11Un procedimiento de comunicación realizado por un punto de acceso (102), que comprende:transmitir (806) una solicitud a un nodo de red (110) en respuesta a un terminal de acceso (108) que intenta acceder al menos a un servicio proporcionado por el punto de acceso (102);recibir un identificador indicativo de un conjunto de terminales de acceso a los que pertenece el terminal de acceso (108);comparar el identificador con una lista de identificadores indicativos de conjuntos de terminales de acceso almacenados en el al menos un punto de acceso (102);y medios para determinar si se permite o no que el terminal de acceso (108) acceda al al menos un servicio, en base a la comparación.
- 12Un producto de programa informático, que comprende:un medio legible por ordenador que comprende códigos para hacer que un ordenador realice las etapas de uno cualquiera de los procedimientos de las reivindicaciones 1 a 4 u 11.
Independent claims12
295 paragraphs in 17 sections, as filed
ES 2 608 454 T3
DESCRIPTION
Provision of communication nodes
Background
Countryside
This application relates generally to wireless communication and more specifically, though not exclusively, to improving communication performance.
Introduction
Wireless communication systems are widely used to provide various types of communication (eg, voice, data, multimedia services, etc.) to multiple users. As the demand for high-speed and multimedia data services grows rapidly, implementing robust and efficient communication systems with improved performance is a challenge.
To complement conventional mobile phone network base stations, small coverage base stations can be deployed (for example, installed in a user's home). In some respects, these base stations can provide more robust indoor wireless coverage for mobile units. Such small coverage base stations are generally known as access point base stations, home Node Bs, or femto-cells. Typically, such small coverage base stations are connected to the Internet and the mobile operator's network via a DSL router or cable modem.
US Patent No. 6,185,416 describes a procedure and apparatus for fraud control in cellular telephone systems in which a control processor prevents a call origin request from being completed when a comparison indicates that the telephone is fraudulent. US Patent No. 7,263,076 describes a procedure for managing a wireless network community in which a community management system is configured to allow each registered member to register an associated wireless access point and control which of the other members is authorized. to access the wireless access point.
In some scenarios, small coverage base stations can be deployed as needed. Consequently, there may be problems associated with accessing these base stations. For example, it may be necessary to configure the access terminals to access their associated base stations. Furthermore, it may be desirable to prevent unauthorized access terminals from accessing certain base stations. Therefore, there is a need for improved access management for wireless networks.
Summary
The following is a summary of sample aspects of the disclosure. It should be understood that any reference to the term 'aspects' herein may refer to one or more aspects of the disclosure, and that the invention is defined by the appended claims.
The disclosure relates in some respect to endowing communication nodes and providing access management for wireless communication. For example, the identifiers can be assigned to groups of nodes where the identifiers can be used to control access to restricted access points that provide certain services only to defined sets of access terminals. Here, a restricted access point may, for example, provide certain services (eg, different billing, additional services, different quality of service) for the access terminals of one or more preferred users, but not for other users.
In some aspects, provisioning a node may involve providing a unique identifier for a set of one or more nodes. For example, a unique identifier can be assigned to one or more restricted access points. Similarly, a unique identifier can be assigned to a set of access terminals that are authorized to receive service from one or more restricted access points. In some aspects, a temporary identifier may be assigned to an access terminal, whereby access to the node may involve mapping the temporary identifier to a permanent identifier for the access terminal.
By using such identifiers, a desired level of access control can be achieved even though nodes can be provisioned as needed. In some aspects, access control can be provided by a restricted access point. In some aspects, access control can be provided by a network node. In some aspects, access control can be provided by the cooperation of a restricted access point and a network node.
Disclosure is concerned, in some respects, with providing a node with a preferred roaming list. In some
In aspects, a node can be provided with a default preferred roaming list, which the node can use to obtain another preferred roaming list to access restricted access points. In some aspects, a node can be provided with a preferred roaming list, through the use of a start beacon.
Brief description of the drawings
These and other exemplary aspects of the disclosure will be described in the detailed description and claims described below and in the accompanying drawings, in which:
FIG. 1 is a simplified block diagram of various sample aspects of a communication system; and FIG. 2 is a flow chart of various sample aspects of operations that can be used to provision network nodes and provide access control;
FIG. 3 is a simplified diagram of various sample network node components;
FIG. 4 is a flow chart of various sample aspects of operations that can be used to equip an access point;
FIG. 5 is a flow chart of various sample aspects of operations that can be used to equip an access terminal;
FIG. 6 is a flow chart of various sample aspects of operations that can be used to equip an access terminal;
<td>FIG. 7 is a flow chart providing access control;</td><td>from</td><td>various</td><td>aspects</td><td>from</td><td>show</td><td>from</td><td>operations</td><td>what</td><td>they can</td><td>be used</td><td>in order to</td>
<td>FIG. 8 is a flow chart providing access control;</td><td>from</td><td>various</td><td>aspects</td><td>from</td><td>show</td><td>from</td><td>operations</td><td>what</td><td>they can</td><td>be used</td><td>in order to</td>
<td>FIG. 9 is a flow chart providing access control;</td><td>from</td><td>various</td><td>aspects</td><td>from</td><td>show</td><td>from</td><td>operations</td><td>what</td><td>they can</td><td>be used</td><td>in order to</td>
<td>FIG. 10 is a flow chart providing access control;</td><td>from</td><td>various</td><td>aspects</td><td>from</td><td>show</td><td>from</td><td>operations</td><td>what</td><td>they can</td><td>be used</td><td>in order to</td>
<td>FIG. 11 is a flow chart</td><td>from</td><td>various</td><td>aspects</td><td>from</td><td>show</td><td>from</td><td>operations</td><td>what</td><td>they can</td><td>be used</td><td>in order to</td>
provide access control;
FIG. 12 is a flow chart of various sample aspects of operations that can be used to equip an access terminal;
FIG. 13 is a flow chart of various sample aspects of operations that can be used to provide access control;
FIG. 14 is a simplified diagram of a wireless communication system;
FIG. 15 is a simplified diagram of a wireless communication system that includes femto-nodes;
FIG. 16 is a simplified diagram illustrating coverage areas for wireless communication;
FIG. 17 is a simplified block diagram of various sample aspects of communication components;
<sup>Y</sup> FIGs. 18-28 are simplified block diagrams of various sample aspects of apparatus configured to provide provisioning and / or access management, as instructed herein.
In accordance with common practice, the various features illustrated in the drawings may not be drawn to scale. Accordingly, the dimensions of the various features can be arbitrarily enlarged or reduced for clarity. Also, some of the drawings may be simplified for clarity. Therefore, the drawings may not illustrate all components of a given apparatus (eg, device) or procedure. Finally, the same reference numerals can be used to denote the same characteristics throughout the specification and the figures.
Detailed description
ES 2 608 454 T3
Various aspects of the disclosure are described below. It will be apparent that the teachings herein can be implemented in many different ways and that any specific structure or function, or both, disclosed herein are merely representative. Based on the teachings herein, one skilled in the art will appreciate that one aspect disclosed herein can be implemented independently of any other aspect, and that two or more of these aspects can be combined in various ways. For example, an apparatus can be implemented, or a method can be practiced, using any number of the aspects disclosed herein. Furthermore, an apparatus of this type can be implemented, or a procedure of this type can be carried out, using another structure, functionality, or structure and functionality, in addition to, or different from, one or more of the aspects described in the present document. Furthermore, an aspect may comprise at least one element of a claim.
FIG. 1 illustrates various nodes of a sample communication system 100 (eg, a part of a communication network). For illustrative purposes, various aspects of the disclosure will be described in the context of one or more network nodes, access points, and access terminals communicating with each other. However, it should be appreciated that the teachings herein may be applied to other types of apparatus or to other similar apparatus referred to using other terminology.
Access points 102 and 104 in system 100 provide one or more services (eg, network connectivity) for one or more wireless terminals (eg, access terminals 106 and / or 108) that can be installed within the themselves or that they can move throughout an associated geographic area. Additionally, access points 102 and 104 can communicate with one or more network nodes 110 to facilitate wide area network connectivity. Such a network node can take various forms. For example, a network node may comprise a mobility manager or some other suitable network entity (eg a core network entity).
Access points 102 and 104 may be restricted in some respects, whereby each access point offers certain services to certain access terminals (for example, access terminals 106 and 108), but not to other access terminals ( for example, a macro-access terminal, which is not shown). For example, access points 102 and 104 may be restricted to not providing the other access terminals with at least one of: registration, signaling, voice calling, data access, or any other cellular service. Restricted access points can be deployed as needed. For example, a specific home owner can install and configure their own restricted access point.
FIG. 2 provides an overview of various operations that can be carried out to facilitate the deployment of restricted access points and the access terminals that are authorized to use these access points. In some respects, these operations can be used to enable a restricted access node to determine its identity, determine the identity of access terminals that are allowed to access (for example, connect) to the restricted access point, and confirm the identity of the access point. identity of an access terminal (for example, an access terminal that is trying to access the restricted access point). In some aspects, these operations can be used to allow an access terminal to determine its identity, to determine the identity of a restricted access point to which the access terminal is allowed to access, to translate the temporary identity of the access terminal to the identity. and confirm the identity of an access point (for example, a restricted access point that the access terminal is trying to access).
For convenience, the operations of FIG. 2 (or any other operations set forth or taught herein) can be described as being performed by specific components (eg, components of system 100 and / or components of a system 300 as shown in FIG. 3). However, it should be appreciated that these operations can be carried out by other types of components and can be carried out using a different number of components. It should also be appreciated that one or more of the operations described herein may not be used in a given implementation.
FIG. 3 illustrates several sample components that can be incorporated into the network node 110 (e.g., a mobility manager, a mobile switching center, or a serving GPRS support node), the access point 102, and the service terminal. access 106 according to the teachings herein. It should be appreciated that the illustrated components for a given node of these nodes can also be incorporated into other nodes in a communication system. For example, access terminal 108 may include components similar to those described for access terminal 106 and access point 104 may include components similar to those described for access point 102.
Network node 110, access point 102, and access terminal 106 include respective transceivers 302, 304, and 306 for communicating with each other and with other nodes. Transceiver 302 includes a transmitter 308 for sending signals (eg, messages) and a receiver 310 for receiving signals. Transceiver 304 includes a transmitter 312 for transmitting signals and a receiver 314 for receiving signals. Transceiver 306 includes a transmitter 316 for transmitting signals and a receiver 318 for receiving signals.
ES 2 608 454 T3
Network node 110, access point 102, and access terminal 106 also include other components that can be used in conjunction with node provisioning and access management as taught herein. For example, network node 110, access point 102, and access terminal 106 may include communication controllers 320, 322, and 324, respectively, for managing communications with other nodes (eg, send and receive messages / prompts) and to provide other related functionality, as taught herein. Network node 110, access point 102, and access terminal 106 may include provisioning controllers 326, 328, and 330, respectively, for provisioning a node and for providing other related functionality, as taught in the present document. Network node 110, access point 102, and access terminal 106 may include access controllers 332, 334, and 336, respectively, to provide access management and to provide other related functionality, as taught herein. document. For illustrative purposes, all nodes are depicted in FIG. 3 as including functionality related to manning and access control. In some implementations, however, one or more of these components may not be used on a given node. The following discussion describes several different schemes (eg, in conjunction with different figures) for staffing network nodes and providing access control. For convenience, in these different schemes, network node 110, access point 102, and access terminal 106 may be referred to as including different functionality and may be referred to as representative of different types of nodes (e.g., in different implementations, network node 110 may represent an SRNC, or an MME, or an aAa, etc.). It should be appreciated, however, that, in a given implementation, network node 110, access point 102, and access terminal 106 may be configured in a specific manner.
Referring again to FIG. 2, as represented by block 202, each access terminal (eg, access terminal 106) in a system can be provided to allow communication with one or more access points (eg, access point 102) . In the example of FIG. 3, these operations can be performed, for example, by operating the manning controllers 326 and 330.
In some aspects, an operator may assign a unique identifier to the access terminal 106. In some implementations, this identifier comprises a network access identifier (NAI) or a mobile station integrated services digital network (MS ISDN) number. . Alternatively, the subscriber identity, such as the International Mobile Subscriber Identity (IMSI), can also be obtained from a subscriber identity module, such as the SIM, USIM or VSIM present in the access terminal. . In some cases, this identifier is guaranteed to be unique within an operator domain (for example, the entire network provided by a cellular operator). In some implementations, such an identifier may be part of the session information for the access terminal 106. For example, the identifier can be sent to network node 110 (eg, a session reference network controller, SRNC) by access terminal 106 when access terminal 106 creates a session, or the identifier can be sent unilaterally to network node 110 from an authentication, authorization and accounting (AAA) entity once a session is created. In some implementations, the identifier is accessible to a user, so that the user can, for example, configure their restricted access point (s) to serve one or more access terminals. In some implementations, an access terminal may be assigned a temporary identifier. For example, the network may assign permanent and temporary identifiers for access terminal 106 and maintain those identifiers on the network. In addition, the network may send the temporary identifier to access terminal 106 so that access terminal 106 can use that identifier when accessing an access point.
Access terminal 106 can also be provided with the identity of each access point (eg, access point 102) to which access terminal 106 is allowed access. As described in more detail below, this may involve, for example, sending access point identifiers to access terminal 106 (eg, an unsolicited sending pattern) and / or allowing access terminal 106 select the access points accessed by the access terminal 106 (eg, a requested pull pattern). The access terminal 106 can thus maintain a list of authorized access points (for example, a white list or list of preferred user zones) to which the access terminal 106 can refer as it scrolls through different wireless coverage areas.
In some implementations, a user of access terminal 106 may be asked to determine whether or not he or she wishes to enable access terminal 106 to access an access point. In some implementations, access terminal 106 can automatically enable access to an access point. In some implementations, access terminal 106 may determine, based on configuration information in access terminal 106, whether access is automatically enabled or a request from the user is required to allow access. In some implementations, a user can choose to access or choose not to access one or more access terminals. In this case, a list of the access terminal (s) allowed and / or rejected can be maintained in the access terminal 106. In this way, the access terminal 106 can prevent ( for example, automatically prevent) an attempt to access an access point in the list.
As represented by block 204, each restricted access point (eg, access point 102) in a system may be provided to allow communication with one or more access terminals (eg, access terminal 106 ). In the example of FIG. 3, these operations can be performed, for example, by
ES 2 608 454 T3 the operation of the endowment controllers 326 and 328.
For example, a unique identifier can be assigned to access point 102 or to a set of access points (eg, access points 102 and 104). This unique identifier is different from a unique device identifier that can be assigned to identify individual access terminals in a system. As described in more detail below, said identifier may comprise, for example, a special type of network identifier (NID) or subnet identifier, or an identifier assigned to a group of access terminals having the same association properties. restricted (for example, a CSG). In some cases, the network can autonomously assign a unique identifier. In some cases, one or more access points may request an identifier (for example, by determining a proposed identifier and sending it to the network). In these cases, the network can determine whether or not the requested identifier is already in use by one or more different access points. If the requested identifier is already in use, the network can select another identifier (for example, a similar identifier) that is not used by any other access point and send this identifier to the requesting access point (s) ( s).
Access point 102 may also be provided with one or more identifiers associated with each access terminal (eg, access terminal 106) that is allowed to access access point 102. As described in more detail below, this may involve, for example, storing access terminal identifiers in a database managed by a network and / or storing access terminal identifiers in a local access list at access point 102.
In some implementations, the access control list for a given restricted access point may be managed at that restricted access point. For example, as discussed below in conjunction with FIG. 13, a user can configure his access point by means of an access terminal (for example, a cell phone) or by using a password-protected Web page, hosted on the restricted access point.
Alternatively, in some implementations, an access control list for each restricted access point on a network is managed on the network (eg, the core network). For example, as discussed below in conjunction with FIG. 4, an access control list can be managed on a Web page hosted by the network operator. Managing the access control list in the network may provide one or more advantages in some contexts. In some respects, this approach may allow for greater flexibility in criteria. For example, the operator can limit access to restricted access points if desired and the operator can check the logs (eg for access terminals) in the same billing plan. Also, the network can be more reliable than individual access points. Therefore, the reliability of the access control list can be improved. Also, since the access control list may not be sent to the restricted access point, there may be no need to provide a direct interface to the restricted access points (e.g. application software, USB ports, etc. ). On the other hand, by using centralized access control lists, it can be easier to manage multiple restricted access points that belong to a common company.
Once a restricted access point is provisioned, its assigned identifier can be announced over the air. For example, access point 102 may broadcast its identifier as part of its sector parameters, or in some other suitable manner.
As represented by block 206, once an access terminal is provisioned, the access terminal can monitor for signals (eg, pilot / beacon signals) broadcast by nearby access points. As discussed in detail below, if the access terminal 106 identifies signals from the access point 102 (for example, in a scenario where the access terminal 106 is allowed to access the access point 102), the terminal access point 106 can request access to that access point 102. Identifying an access point accessible by access terminal 106 may involve, for example, comparing an identifier associated with access point 102 with a trusted list 338 of authorized access points (eg, the white list). , maintained by the access terminal 106. In the example of FIG. 3, these and other access-related operations can be performed, for example, by operation of the access controller 336.
As represented by block 208, access point 102 and / or one or more network nodes (eg, network node 110) can determine whether or not access terminal 106 is allowed to access the access point. access 102. This access control operation may involve, for example, confirming the identity of the access terminal 106 and comparing an identifier of the access terminal 106 with a list of authorized access terminals, maintained by the access point 102 ( eg, a local access list 340) and / or maintained by network node 110 (eg, a network database access list 342). In the example of FIG. 3, these and other access-related operations can be performed, for example, by the operation of the gatekeeper 334 and / or the gatekeeper 332.
With the above overview in mind, additional details related to provisioning and access control will be described with reference to FIGs. 4 to 13 It should be appreciated, based on the teachings in this document, that
ES 2 608 454 T3 one or more of the operations described in conjunction with a given figure of these figures may be used in conjunction with the operations described in another of these figures. For convenience, these operations will be described with reference to the components of FIG. 1. It should be appreciated that these operations may also be applicable to other nodes in a network.
Referring initially to FIG. 4, various operations related to provisioning a restricted access point are covered.
As represented by block 402, network node 110 assigns an identifier (eg, a unique identifier) for the restricted access point. In some cases, this identifier is guaranteed to be unique within an operator domain (for example, the entire network provided by a cellular operator). For example, a network entity may maintain a database of identifiers that is used to ensure the uniqueness of any assigned identifier.
The identifier can take several forms. In some implementations, this identifier comprises a network identifier (eg, a femto-network identifier, FNID). In some implementations, the identifier may comprise a closed subscriber group identifier (CSG ID). As mentioned above, a set of restricted access points (for example, associated with the same administrative domain) can share a common identifier (for example, a CSG ID). In some implementations, a set of the FNIDs may be associated with a common CSG. For example, a CSG can be assigned to a company and different FNIDs can be assigned to different access points throughout the company (for example, in different buildings). In some implementations, additional identifiers that can be human-readable (for example, text-based) can also be used.
The unique identifier can be endowed in various ways. For example, in some cases, an identifier is chosen and configured when a user activates a restricted access point. Here, the identifier can be configured by an operator, at the point of purchase, or in some other way.
As represented by block 404, a list of access terminals that are authorized to access access point 102 (and, if applicable, any other access point in a defined set of access points) is generated. This access list may include, for example, the access terminal identifiers, as discussed in this document. Therefore, such an identifier can identify an individual access terminal (for example, a NAI or IMSI or MS ISDN) or a set of one or more access terminals (for example, one or more access terminals associated with a certain CSG). In addition, the access list can specify permissions (eg, access conditions) associated with a given access terminal.
In some implementations, the access list may be managed through the use of a Network 344 site (eg, accessible by a computer, telephone, or some other suitable device). In this way, the owner or user of access point 102 can access the Web site to add, delete or edit access terminal entries in the access list. For example, to allow an access terminal, local or guest, (for example, access terminal 108) to access access point 102, a user can add a permanent NAI of the access terminal to the access list via a web page. Here, various naming conventions (eg, user-readable identifiers, such as Joe's phone and the like) can be associated with a unique access terminal identifier (eg, NAI or MS ISDN) and one or more of these Identifiers can be displayed on the Web page after they are added to the Web page.
As represented by block 406, in some implementations, the access list is hosted by the network operator. For example, an operator may maintain a server for the Web site of the access list. In this way, the operator can approve any modification of the access list (for example, denying entries for the access terminals of other operators).
As represented by block 408, the access list information can then be sent to each access point or to other network nodes that perform access control associated with a given access list. For example, the server may unilaterally send the access list information to the access point 102 or the access point 102 may unilaterally extract the access list information from the server. As an example of an unsolicited forwarding model, the access list can be forwarded from the operator's web site to a configuration server which then forwards the access list to access point 102.
As another example, the access list can be sent from the operator's Web site, over the Internet, to application software at access point 102. As an example of a one-sided pull model, access point 102 can check with the configuration server to receive the latest version of the access list. Such a query can take place, for example, every time the access point 102 connects to the operator's network (for example, it establishes a new IPSec connection). Thus, in the event that the access point 102 goes offline for a period of time, it can be ensured that the access point 102 receives the most recent version of the access list each time it reconnects to the network. .
ES 2 608 454 T3
By maintaining the access list in a location other than access point 102, access point 102 is relieved of the burden of maintaining the access list. This approach can provide better access list management, as the access list can be updated even when the access point 102 is offline. Furthermore, such an approach can simplify the management of an access list that is associated with more than one access point. For example, a single access list can be defined for a set of access points (eg associated with a particular CSG). In this case, the access points can acquire the access list from a single source, rather than having to coordinate with each other to manage (for example, update) the access list between all access points.
Using a centralized access list can also facilitate the use of temporary identifiers. For example, access point 102 may use a given identifier for as long as a given IPSec tunnel is established. When a new IPSec tunnel is established, the access list can be configured with a different set of identifiers. In this case, the new set of identifiers may or may not identify the same access terminals as the previous version of the access list.
As represented by block 410, access point 102 broadcasts its identifier (eg, FNID or CSG ID) over the air. In this way, any access terminal that enters the coverage area of access point 102 can identify access point 102 and determine whether or not it is allowed to access access point 102.
Referring now to FIGS. 5 and 6, various operations that can be used to equip an access terminal are described. In particular, these figures describe techniques for providing an access terminal with the identity of one or more restricted access points, which the access terminal can access.
FIG. 5 illustrates various operations that can be performed to unilaterally send access list information to an access terminal (ie, unsolicited sending pattern). In this example, it is assumed that a unique identifier has been assigned to the access terminal (eg, as discussed above).
As represented by block 502, at some point in time an access terminal may be designated as authorized for access to one or more access points. For example, the owner of one or more access points can add a guest access terminal to the access list associated with the access point (s), as discussed above in conjunction with FIG. Four.
As represented by block 504, the operator sends a message to the access terminal indicating that the access terminal is now authorized to access an access point or set of access points. This message may include an identifier associated with the access point (s) (for example, an FNID or a CSG ID), as well as any limitations that may be applicable (for example, time limits for the access of guests). Such a message can be sent, for example, when an identifier from access terminal 108 is added to an access list associated with access point 102. Such a message can also be sent in various ways. For example, the network may send an SMS message, an application protocol message (for example, Open Mobile Alliance device management), a radio link message, a page, or some other type of message, to the access terminal to transmit the access point information (eg, a query asking the access terminal 108 whether or not it wishes to access the access point 102).
As represented by block 506, access terminal 108 may then inform the user of access terminal 108 that he or she is eligible to access the access point (s). For example, the access terminal 108 may display an indication of the identity of the access point (s), or provide some other form of indication. Such an indication may comprise, for example, the identifier assigned to the access point (s), or an alternative name (for example, user-readable identifiers such as Sue's house or the like) that has been associated with the identifier.
As represented by block 508, the user can then determine whether or not to enable (eg, using an input device at access terminal 108) the requested access to the access point (s). . Based on the user's decision, the access terminal 108 may update a list (eg, a white list) that it maintains of the access points that it is authorized (eg, enabled) to access. As discussed below, access terminal 108 can use this list to determine which access points it can access as access terminal 108 roams the network. In this case, the user may not have to provide any additional access authorization in case the access terminal enters the coverage area of an access point in the list, as the access terminal can automatically remember this access point. In some implementations, the whitelist can be updated only after approval from the network operator.
In some implementations, the access terminal 108 may send the operator a message indicative of the user's decision. In this way, the operator can choose to modify the access list for the access point (s), if desired.
ES 2 608 454 T3
By allowing an access terminal user to accept or reject access to an access point, an access point user can be prevented from unilaterally enabling an access terminal (for example, a neighbor's access terminal) to access that access point. Thus, the user of an access terminal can be sure that his information is not sent to an unauthorized access point.
Also, this unsolicited sending model does not require the access terminal to be in close proximity to an access point to add an access point to its whitelist. In addition, since the access terminal can receive the unsolicited send message only when it has been added to an access list, the possibility of a user selecting the wrong access point (for example, one that is not connected to) can be reduced. allow access to the access terminal).
FIG. 6 illustrates various operations that can be performed to unilaterally extract access list information for an access terminal (ie, an unsolicited extraction pattern). Once again, it is assumed that a unique identifier has been assigned to the access terminal.
As represented by block 602, at some point in time, a user of an access terminal (eg, access terminal 108) initiates a search for nearby access points. To this end, access terminal 108 may include an input device that the user can control (eg, a menu option) to cause receiver 318 to monitor one or more channels for pilot or other signals from a access point.
As represented by block 604, access terminal 108 informs the user of any access point that was detected as a result of the search. For example, access terminal 108 may display an indication of the identity of the detected access point (s), or provide some other form of indication. Again, such an indication may comprise an identifier assigned to the access point (s), an alternative name, or some other suitable information.
As represented by block 606, the user can choose to enable access to one or more detected access points. For example, the user may control an input device at access terminal 108 to select one or more access points to be displayed by access terminal 108.
The access terminal then attempts to access the selected access point, if desired. As discussed below, in the event that the user has selected the wrong access point (eg one that the access terminal is not authorized to access), the access point may deny access. The access point can then relay this information to the access terminal (for example, to prevent this from happening again in the future).
As represented by block 608, in some implementations, access terminal 108 may update a list it maintains of access points that it is allowed to access (eg, a white list), based on the decision of the user. In this way, the access terminal 108 can remember a selected access point such that user input is not required for future visits to this access point (for example, the access terminal 108 can connect to the access point without the need for the user to initiate another search).
As represented by block 610, in some implementations, a one-sided pull model may be used to allow access terminal 108 to access an access point conditionally (eg, on a pay-as-you-go basis). For example, multiple access points (for example, owned by a common owner, such as a hotel or other business) may all advertise the same unique identifier (for example, FNID or CSG ID). When the access terminal is close to one of these access points and the user of the access terminal 108 initiates a search, the user may choose to connect to one of these access points (eg, the access point 102). When access terminal 108 tries to connect to access point 102, access point 102 cannot check its local access control list to see whether or not access terminal 108 is authorized for access but can instead allowing access terminal 108 to make an initial connection. This initial connection may, however, involve redirecting the user to a page on the Web, through which the access terminal 108 can only receive service from the access point 102 if certain conditions are met (for example, if a pay). Using this model, any access terminal (unlike certain designated access terminals) can gain access to the associated set of access points.
As mentioned above, an access point and / or a network node can control whether or not a given access terminal is allowed to access the access point. In some implementations, access control for a given restricted access point may be administered at that restricted access point. In some implementations, access control for a given restricted access point can be managed at that restricted access point with the help of a centralized access control manager (eg, implemented on a network node). FIGs. 7 through 11 illustrate various techniques that can be used to control
ES 2 608 454 T3 said access.
Referring initially to FIG. 7, various operations are described in connection with a scenario where an access point controls access to it. In some respects, the access granted by the access point may be conditional. For example, if the access point determines that access should not be granted to a particular service, the requested access may be unilaterally denied. However, if the access point determines that access should be granted to a particular service, the access point can send a request to the network to confirm whether or not it should allow access.
In some implementations, an access point can control (for example, unilaterally control) access to a local service. For example, an access terminal may attempt to access a service provided on a local network associated with the access point. Such services may include, for example, access to a local server (eg, access to audio, video, data, or other content), access to a printer, etc.
As represented by block 702 of FIG. 7, at some point in time, an access terminal (eg, access terminal 108) begins establishing communication with a restricted access point (eg, access point 102). In conjunction with this operation, access terminal 108 may attempt to open a session (or route) to access point 102. In addition, the associated session information may be stored on the network (eg, on the network node 110). To facilitate the access point 102 to confirm the identity of the access terminal 108, in some cases, an identifier of the access terminal 108 may be part of the session information (for example, be included in the context information of the point access). This identifier may comprise, for example, a permanent identifier (eg, a NAI), as set forth herein.
As represented by block 704, access point 102 may obtain information to confirm the identity of access terminal 108. For example, in some cases, access point 102 may receive an identifier (eg, a temporary identifier ) or other suitable information directly from access terminal 108 (eg, over the air). In some cases, the access point 102 may retrieve the aforementioned session information, including the access terminal identifier (eg, a temporary or permanent identifier), from the network (eg, from the SRNC). Advantageously, in the latter scenario, the transmission of the identifier (for example, the permanent NAI) over the air can be avoided.
In cases where a temporary identifier is used (eg, a temporary NAI), the access point 102 may cooperate with the network to ensure the validity of the identifier. For example, in some implementations, access point 102 sends the temporary identifier to an AAA entity that authenticates the identifier. In some implementations, access point 102 sends the temporary identifier to the network and receives the associated permanent identifier in response. In this case, the access point 102 may use the permanent identifier to authenticate the access terminal 108.
As represented by block 706, access point 102 compares the access terminal information (eg, a temporary or permanent identifier) with the information in its local access list (eg, represented by the access list local 340 in FIG. 3). As discussed above, the local access list can be configured to include a unique identifier associated with the access terminal 108 (eg, NAI, CSG ID, etc.).
As represented by block 708, access point 102 can then allow or deny the requested access based on the comparison in block 706. Here, access point 102 can send a reject message to the terminal. access point 108 and / or access point 102 may redirect access terminal 108 to a different access point (eg, by sending a redirect message identifying the local macro access point).
As described below, in some implementations, access terminal 102 may cooperate with the network to authenticate access terminal 108. For example, in the case that the access terminal identifier is not in the local access list, the access point 102 can send a request to a network node, such as an AAA entity, which provides authentication, etc. ., for restricted access points (eg a AAA femto-entity implemented, eg, as a standalone entity, or by incorporating corresponding functionality into a traditional network AAA entity). Here, the network node may maintain an access control list for the access point 102 that the network node uses to authenticate the access terminal 108 (eg, in a similar manner as discussed above). Furthermore, if appropriate, the network node can cooperate with another network node (for example, an AAA entity for the access terminal 108) to obtain a permanent identifier associated with the access terminal 108, based on the identifier that was sent. to access point 102 by access terminal 108. The access point 102 may then allow or deny the requested access based on a response it receives from the network node, indicative of whether or not the access terminal 108 is authorized to access the access point 102. According to the teachings in the In this document, the access control functions can be performed at the access point or other network entity, such as a gateway, a mobile switching center (MSC), a support node of the
ES 2 608 454 T3
GPRS server (SGSN), a packet data service node (PDSN), or an MME, in various implementations
Referring now to FIG. 8, various operations are described referring to a scenario in which the network sends a list of access terminal identifiers (for example, the access point's access list) to an access point, so that the access point can determine whether or not to grant an access request from an access terminal. In this example, the operations of blocks 802 and 804 may be similar to the operations of blocks 702 and 704, described above. In this scenario, however, the access point 102 may not retrieve the session information in some cases.
As represented by block 806, access point 102 sends a request to the network (eg, to a network node 110) to authenticate access terminal 108. In the event that the access point 102 has obtained the session information (for example, including access terminal identifier information, such as an MS ISDN, a CSG ID, or an nAI), the access point 102 it can send this information to network node 110 in conjunction with the request (eg, included in the request message). In some implementations, this operation may involve a request for the access terminal identifier list. In practice, the access point 102 may request this list at different times (for example, each time the access point is activated or connects to a network, whenever an access terminal tries to access the access point, accordingly. periodically, etc.).
As represented by block 808, network node 110 obtains an identifier associated with access terminal 108. This identifier may comprise, for example, a list of identifiers indicating one or more access groups associated with the access terminal. For example, the identifier may comprise a list of closed groups of subscribers, of which the access terminal 108 is a member, a list of access terminals that have permission to access the access point 102 (for example, an access list access point 102), or a list of access point identifiers that can be accessed by access terminal 108. Determining the identifier by network node 110 may comprise, for example, receiving the identifier from another network node (eg, an HSS) or obtaining the identifier from a local database. In some implementations, determining the identifier may involve determining a permanent identifier, as discussed herein (eg, based on a received temporary identifier). Network node 110 sends the identifier, or identifiers, obtained at block 808 to access point 102 at block 810.
As represented by block 812, access point 102 can then determine whether the requested access is allowed or denied based on the received identifier (s). For example, the access point may compare the received identifier (eg, a CSG ID), indicative of the sets to which the access terminal 108 belongs, with the information (eg, a CSG ID) in the local access list of access point 102, which is indicative of the sets to which access point 102 belongs. Access point 102 may then allow or deny the requested access based on this comparison.
Referring now to FIG. 9, various operations are described in connection with a scenario where a network controls access to an access point. In this example, the operations of blocks 902, 904, and 906 may be similar to the operations of blocks 802, 804, and 806, described above. Again, access point 102 may not retrieve session information in some cases. In addition, in some cases, the access point 102 may send its local access list to the network for use in the authentication operation.
As represented by block 908, in implementations that use temporary identifiers to identify one or more nodes (eg, access terminals), network node 110 (eg, a AAA femto-entity) may determine a permanent identifier. associated with access terminal 108, based on a temporary identifier associated with access terminal 108. For example, access point 102 may have obtained a temporary identifier from the access terminal (eg, at block 902) or from session information (eg, at block 904). In such a case, the access point 102 may send a temporary identifier (eg, a temporary NAI) for the access terminal 108, along with an identifier (eg, an FNID) of the access terminal 102, to the network node. 110, in conjunction with the request at block 906. As discussed in conjunction with FIG. 7, the network node 110 can then cooperate with another network node to obtain a permanent identifier from the access terminal 108 from the temporary identifier.
As represented by block 910, network node 110 determines whether or not access terminal 108 is allowed to access access point 102. For example, network node 110 may compare an identifier of access terminal 108 (for example, a NAI, a CSG ID, etc.) with an access list of access point 102. In this case, the access list can be the local list obtained from the access point 102 or it can be an access list maintained by the network (for example, based on information obtained from a server on the Network , as discussed above). Network node 110 can then determine whether the requested access is allowed or denied based on this comparison.
As represented by block 912, network node 110 sends an indication of this determination to the
ES 2 608 454 T3 access point 102. Access point 102 may then allow or deny the requested access based on the received indication (block 914). Advantageously, in implementations of this type, the access point 102 does not need to be aware of the actual identity of the access terminals accessing the access point 102. Furthermore, it is not necessary to send the access control list for the point. access point 102 to access point 102. In such an implementation, access control is carried out entirely at the network node, transparently to the access point.
Various techniques can be used to manage access terminal identifiers in a network. As mentioned above, an access point can store the valid identifier (eg, the NAI) used by an access terminal. In some implementations, this identifier may remain valid for a defined period of time. Here, if an access terminal returns to an access point within the time period (that is, the access terminal has the same identifier during this time), the access point can accept the access terminal without the need to obtain the authorization from the network (for example, AAA's femto-entity). In some implementations, an operator may choose to use a temporary identifier or a permanent identifier for the access terminals. If a permanent identifier is used, the permanent identifiers can be stored in the access points (eg, in the local access list 340) such that the access point can independently authenticate the access terminals. If a temporary identifier is used, the operator can control how often access points are checked against the network (eg, AAA femto-entity) to verify identifiers stored in local access list 340.
FIG. 10 illustrates an example of access control operations that can be performed in an application that uses long-term evolution (LTE) or other similar technology. In this example, the network (eg, the core network, as compared to the radio access network) controls whether or not an access terminal is allowed to access an access point. In addition, techniques are described for providing access terminals and access points with CSG subscription information (for example, match information), the enforcement of access control (for example, for idle mode or active mode. ), the modification of the equipment of an access point or access terminal, and the imposition of a list of CSG, when an access terminal carries out operations such as power-on, updating the scrolling area and handover.
The network (eg, a home subscription server, HSS, or a CSG subscription server) may maintain CSG subscription information for access terminals and restricted access points in the network. In a manner similar to that described above, an operator may provide a Web server that allows a user to manage CSG subscription information for their restricted access point (s). For example, a user can modify his subscription information (for example, MS ISDNs) using a web site. The network can then approve modifications (for example, access terminal entries) made by the user and the Network server can send subscription information to network (eg HSS). Here, the MS ISDN can be converted to an IMSI. The network may then send the CSG information (eg, a unique CSG identifier) to the corresponding restricted access point (s). Furthermore, the network may send the CSG subscription information to an MME when an associated access terminal is registered with the MME.
Also, as described above, the provision of an access terminal (eg with a list of unique CSG IDs) may be approved by the owner of the access terminal. In addition, the operator can also approve the provision of the access terminal. Here, a given CSG ID may be associated with a set of one or more access terminals that are authorized to receive at least one service from a set of at least one restricted access point. In other words, the set of access terminals and the set of access points are associated with a common CSG ID. It should also be appreciated that a given access terminal, or access point, may also be associated with multiple CSGs. In some aspects, the network (eg, HSS) may maintain information indicative of the correlation between an identifier of an access terminal and the subscriber CSG ID. Also, since the HSS is connected to the MME, the MME can retrieve the CSG information and relay it to the restricted access points, if desired.
Again, manning the access terminal may involve an unsolicited delivery model or a one-sided pull model. For example, in the above case, the network (for example, a network node) can send an SMS message to the access terminal, to inform the access terminal of a new subscription (for example, identifying one or more IDs of CSG), and the user accepts or rejects the subscription. In the latter case, the user can initiate a manual search and the access terminal displays a list of nearby access points (for example, user-readable CSG IDs or other types of access point identifiers), so that the user can select one or more entries from the list, if desired.
As represented by block 1002 of FIG. 10, at some point in time, the access terminal begins to access the restricted access point. For example, when the access terminal 108 determines that it is in the vicinity of the access point 102 (for example, where the access point 102 advertises a CSG ID that is also associated with the access terminal 108), the access terminal 108 can send a registration request or other suitable message to access point 102.
ES 2 608 454 T3
As represented by block 1004, access point 102 sends a request to the network (eg, one or more nodes of network 110) to authenticate access terminal 108. In this case, the node (s) Network (s) 110 may comprise a mobility management entity (MME) or some other suitable network entity (s). Access point 102 may also send an identifier (eg, a CSG ID associated with access point 102) to network node 110, in conjunction with the request (eg, included in the request message). Additionally, the request may include information received from access terminal 108 (eg, at block 1002).
As represented by block 1006, network node 110 obtains context information associated with access terminal 108 (eg, from a previous MME for access terminal 108, or from the HSS). This context information can include, for example, a set of identifiers associated with access terminal 108. For example, the context information can include a list of all CSG IDs associated with access terminal 108. In some implementations, network node 110 may maintain its own list of CSG IDs for each of its restricted access points. In this case, the network node 110 can update its list each time an entry is changed on the network server.
As represented by block 1008, network node 110 determines whether or not access terminal 108 is allowed to access access point 102. For example, network node 110 determines whether an identifier of access point 102 (for example, indicative of a CSG to which access point 102 belongs) is or is not in a list of identifiers associated with access terminal 108 (for example, indicative of all CSGs to which access terminal 108 belongs) .
The determination of block 1008 can be performed at different network nodes. For example, in some implementations, this determination can be made at an MME that obtains and / or maintains the identifiers associated with access point 102 and access terminal 108.
In some implementations, this determination can be made at another network node, such as an HSS. For example, the MME may send a request to the HSS to determine whether or not the access terminal 108 is authorized to access the access point 102. In conjunction with such a request, the MME may send information (for example, identifiers such such as an IMSI and CSG ID) to the HSS in some cases. Also, in some cases, HSS may obtain and maintain such information itself. After determining whether or not access is allowed, the HSS sends a corresponding response back to the MME.
As represented by block 1010, the MME sends a response to the access point 102 based on the determination of the MME or based on the determination of another network node (eg, an HSS). Based on this response, access point 102 may then allow or deny access via access point 108.
FIG. 11 illustrates operations that can be used in conjunction with a handover operation. For example, access terminal 108 may initially receive service from access point 104 and, at a later point in time, access terminal 108 is handed over to access point 102 and then receives service from that node.
As represented by block 1102, the network (eg, an HSS) can maintain context information for each access terminal in the system. As mentioned above, this context information may include a list (eg, a white list) indicative of all access sets (eg, CSGs), to which the access terminal 108 belongs.
As represented by block 1104, the network (eg, an MME) captures the context for the given access terminal and provides the context to a restricted access point when that access terminal is activated at the restricted access point. . With reference to the example of FIG. 3, when the access terminal 108 is activated (eg, turned on) at the access point 104, the network node 110 can send the context information for the access terminal 108 to the access point 104. In this way , the access terminal 108 may initially receive service from the access point 104.
As represented by block 1106, at some point in time, access terminal 108 may be handed over to access point 102. For example, if access terminal 108 moves away from access point 104, Measurements from the access terminal 108 may indicate that the signal strength of the signals received from the access point 102 is now higher than the signal strength of the signals received from the access point 104. In this case, the network may initiate a handover from access point 104 to access point 102.
As represented by blocks 1106 and 1108, in conjunction with this handover, access point 104 (that is, the source access point) may receive an identifier associated with the destination access point (that is, the point access code 102), such as a CSG ID. For example, this information can be received from access terminal 108. Access point 104 can then determine whether or not access terminal 108 is authorized to access access point 102 based on this identifier. For example, him
ES 2 608 454 T3 access point 104 can compare the identifier with a list that specifies the access points that are allowed to access the access terminal 108 (for example, a white list, such as a list of CSG IDs , from the context information for the access terminal 108).
As represented by block 1110, if the access terminal 108 is not authorized to access the access point 102 (for example, the CSG ID of the access point 102 is not in the list of the terminal's CSG IDs port 108), the handover operation cannot be performed. For example, access point 102 may send a message to network node 110 to complete the handover operation. Additionally, or alternatively, access point 102 may send a rejection and / or redirection message to access point 108 (eg, as discussed above).
As represented by block 1112, the handover operation may proceed if access terminal 108 is authorized to access access point 102 (for example, the CSG ID of access point 102 is in the list of IDs. of CSG of access terminal 108). Consequently, the network (eg, the MME) may send the context information for the access terminal 108 to the access point 102 or the access point 102 may receive this information from the access point 104.
As represented by block 1114, access point 102 can determine whether or not access terminal 108 is authorized to access access point 102. For example, similar to what was discussed above, the access point 102 may compare its identifier (for example, a CSG ID) against a list that specifies the access points that are allowed to access the terminal. access 108 (eg, a list of the CSG IDs from the context information for the access terminal 108).
As represented by block 1116, in some implementations, access point 102 may send a request to the network (for example, the MME) to confirm whether or not the handover should be performed (for example, in conjunction with a request path switching). For example, as discussed above, access point 102 may send a request (eg, optionally including an identifier associated with access terminal 108 and the CSG ID for the access point, if necessary) to the node. network 110 to determine whether or not access terminal 108 should be allowed access to access point 102.
In situations where an access terminal needs to access the destination access point without prior handover preparation (for example, during a radio link failure), a destination access point can capture the access terminal context from the source access point. As mentioned above, this context includes a list of the access terminal's CSGs. Therefore, the destination access point can determine whether or not the access terminal is allowed to access the destination access point.
As represented by block 1118, based on the determination at block 1114 (and optionally block 1116), the handover is allowed or denied. If handover is allowed, access point 102 then becomes the service access point for access terminal 108. Conversely, if handover is not allowed, handover may be terminated (eg, as discussed above). set forth above in conjunction with block 1110).
Referring now to FIG. 12, in some implementations, a restricted access point may be used to equip an access terminal. For illustrative purposes, the following examples describe examples in which an access terminal is provided (eg configured) with a preferred roaming list (PRL). It should be appreciated, however, that an access terminal may be provided with other types of information, in accordance with the teachings herein.
As represented by block 1202, access terminals in a network (for example, any access terminals, that can access a restricted access point) may initially be configured with a default PRL (for example, the list comprises or specify a default configuration). For example, access terminal 106 can be configured by the network operator when access terminal 106 is purchased by a user. Such a PRL may specify, for example, a default system identifier (SID), a default network identifier (NID), and a default frequency for the initial acquisition of any restricted access point that may be deployed on the network. Here, all the above access terminals can be configured with the default PRL. In this way, each access terminal can locate, and access, a restricted access point for provisioning operations. In some aspects, the default PRL information (for example, SID and / or NID) may correspond to one or more access points associated with a highest priority. For example, the access terminal may be configured to search (eg search first) for a specified preferred access point, or specified preferred access points (eg source access points).
In some respects, the default PRL parameters can be reserved for operations related to restricted access points. For example, the default SID may be reserved for access points restricted by the network operator. By using such a SID, access terminals that are not configured to access restricted access points (for example, access terminals configured only for use in a macro-network) can be prevented from attempting to register at points restricted access. In addition, the
ES 2 608 454 T3
Default NID can be reserved for initialization procedures related to restricted access points. Furthermore, the default frequency can be defined as a common frequency, to be used by restricted access points in the network, for the transmission of beacons for provisioning procedures. In some cases, the default frequency may be the same as the operating frequency of a macro access point, or an operating frequency of a restricted access point.
The default PRL can also include macro-system selection information. For example, the default PRL may include identifiers and frequencies that can be used to access macro-access points on the network.
As represented by block 1204, restricted access points in the system (eg, access point 102) are configured to transmit a start beacon. In some aspects, this start-up beacon may comprise a temporary beacon that is used in conjunction with the envelope provided by the access point 102. Here, the start beacon can be broadcast based on the generic PRL parameters discussed above (for example, the beacon can understand or specify a default configuration). For example, the startup beacon (for example, a default beacon) can be transmitted at the default frequency, and can include the default SID and the default NID (for example, sent in overload messages).
The start beacon can be transmitted at a very low power level that is much lower than the beacon transmit power during normal access point operations (for example, when the access point is configured in a non-operating mode). initialization, such as a normal operating mode). For example, the transmission power of the starter beacon can result in a range of coverage (eg, a radius) for the starter beacon, on the order of one meter or less.
In some implementations, the access point 102 may transmit start beacons when the access point is in a provisioning mode (eg, configuration or initialization). In some implementations, a user may use an input device to place access point 102 in configuration mode when the user wishes to initially provision, or re-provision, access terminal 106. For example, an access terminal can be provided when an access point is installed for the first time, when an access terminal is purchased for the first time or when the PRL of an access terminal was updated by a macro-network (for example , in conjunction with a change in the roaming list, international travel, etc.), which resulted in the PRL endowed by the access point being overwritten (as discussed below).
As represented by block 1206, when the access terminal 106 equipped with the default PRL is placed near the restricted access point 102, operating in a provisioned mode, the access terminal 106 can receive the transmitted start beacon. by access point 102. In response, access terminal 106 may send a message to access point 102 to initiate provisioning operations. In some implementations, this message may include the PRL currently used by access terminal 106. In some implementations, a user of access terminal 106 can initiate provisioning by selecting a corresponding feature on the access terminal (eg, dialing a defined number).
As represented by block 1208, access point 102 (eg, provisioning controller 328) may define a new PRL for access terminal 106 (eg, for normal mobile operations). The new PRL can include macro-system information as in the default PRL, but the initialization information of the default PRL can be removed. Instead, new PRL information can be added (for example, the list comprises or specifies a new configuration). In some aspects, the new PRL information may be specific to the access point 102 (eg, the new PRL may be different than the PRL provided by other access points). For example, a new PRL can specify the SID that is reserved for all restricted access points, as discussed above, an NID that is unique to access point 102 (for example, a femto-NID, FNID), and a frequency parameter indicating the operating frequency of the access point 102. This frequency parameter may be the same as, or different from, the default frequency. In some aspects, the new PRL information (eg, SID and / or NID) may correspond to one or more access points associated with a higher priority. For example, access terminal 106 may be configured to search (eg, search first) for a specified preferred access point, or specified preferred access points (eg, home access points).
Access point 102 can obtain macro-system PRL information in various ways. In some implementations, access point 102 may request this PRL information from the macro-access point (eg, through network node 110 or over the air). In some implementations, access point 102 may receive this PRL information from an access terminal (eg, access terminal 108). For example, access point 102 may include an over-the-air feature. In this case, the access point 102 may send a message (for example, an SSPR configuration request) to request the current PRL from the access terminal (which may include the current PRL macro-information, as discussed above. ), and the access terminal can respond by sending its current PRL over the air to access point 102.
ES 2 608 454 T3
Once the access point 102 defines a new PRL, the access point 102 sends (for example, unilaterally sends) the PRL to the access terminal 106. For example, the access point 102 may send a PRL to the access terminal over the air (for example, via OTASP or OTAPA).
Advantageously, by providing access terminal 106 via access point 102, as discussed above, the network operator does not need to maintain access terminal specific information (eg PRL information). It may be desirable, however, to configure access point 102 to make periodic updates to the PRL of the access terminal. For example, the PRL can be updated nightly and sent to access terminal 106 over the air. Also, to prevent one access point from a set of related access points from overwriting the PRL information envelope with another access point in the set, each access point can be configured to simply update the terminal's current PRL information access. For example, access point 102 may query access terminal 106 for its PRL information, whereby access point 102 will add its own PRL system information to the current PRL of access terminal 106, at instead of overwriting the current PRL information.
As represented by block 1210, once access terminal 106 is provided with the new PRL information, access terminal 106 will use this information to identify access points that it can access. For example, in the event that the access terminal 106 determines that the access point 102 is in proximity (for example, after the access point has been configured for a normal mode of operation), the access terminal 106 may give preference to being served by access point 102 over any other access point (eg, a macro access point) that is detected by access terminal 106.
Referring now to FIG. 13, various techniques for restricted access control (eg, association) at an access point are described. In this example, an access point can be configured with a local list of access terminals that are allowed to access one or more services provided by the access point. The access point can then grant or deny access based on the local list. Advantageously, in some aspects, such a scheme may allow the owner of an access point to temporarily service guest access terminals (for example, adding / removing these access terminals to / from the list) without the participation of a network operator.
As represented by block 1302, a restricted access point (eg, access point 102) is configured with an access list (eg, represented by local access list 340 in FIG. 3). For example, the owner of access point 102 may configure a list of identifiers (eg, telephone numbers) of access terminals that are allowed to use one or more services provided by access point 102. In some implementations, control over which access terminals can access access point 102 may thus rest with the owner of access point 102, rather than a network operator.
Access point 102 can be provisioned in various ways. For example, the owner may use a Network interface hosted by access point 102 to configure access point 102.
Furthermore, the different access terminals can receive different levels of access. For example, guest access terminals can be given temporary access based on various criteria. Also, in some implementations, a home access terminal may be assigned a better quality of service than a guest access terminal. In addition, some access terminals (for example, guest access terminals) can access certain services (for example, local services, such as a multimedia server or some other type of information server) without the participation of authentication. by a network operator. Also, in some cases, the local access list 340 can be used as an initial stop gap at the access point 102, whereby the actual authentication (for example, for a phone call) can be performed by the network to avoid that network security is compromised.
As represented by block 1304, access point 102 may send the access terminal identifier information that was configured in block 1302 (eg, local access list 340) to a network database ( for example, an authentication center or a local location registry, AC / HLR) and request other associated identification information from the corresponding access terminals. For example, access point 102 may send a telephone number from access terminal 106 to network node 110 (eg, comprising an HLR database) and receive an electronic serial number (ESN) or identity. International Mobile Subscriber Number (IMSI) that is assigned to access terminal 106 from network node 110.
As represented by block 1306, access point 102 may advertise its identifying information (eg, as set forth herein). For example, access point 102 may advertise SID and FNID information, as discussed above.
As represented by block 1308, an access terminal that is equipped to access access point 102 can determine that it is in the vicinity of access point 102 upon receiving the information.
ES 2 608 454 T3 of announced identification. For example, access terminal 106 may be provided with a PRL, via access point 102, as discussed above, or access terminal 106 may be provided with a PRL that includes the SID of the restricted access point, an NID wildcard and one or more operating frequencies that are used by access point 102, or access terminal 106 can be provided in some other way that allows it to identify access point 102 (for example, provided with a list of preferred user zones). Access terminal 106 may then attempt to register with access point 102, as a result of receiving a different SID (eg, which may represent a different zone of the macro-zone for zone-based registration). Thus, in some cases, the access terminal may automatically attempt to access the access point 102. In other cases, however, a user can control whether or not access terminal 106 accesses access point 102 (for example, the user provides input via an input device in response to an indication of detected access points, issued by the access terminal 106). In conjunction with this registration, the access terminal 106 can send its identifier (eg, its ESN, IMSI, etc.) to the access point 102 (eg, via an access channel).
As represented by blocks 1310 and 1312, access point 102 determines whether or not access terminal 106 is allowed to access access point 102. For example, access point 102 can determine whether the identifier received from access terminal 106 is or is not listed in local access list 340. It should be appreciated that authentication information other than ESNs and IMSIs may be used in different implementations. For example, access point 102 may receive call origin number information via idle messages, and use this information for authentication (eg, to compare it with a caller number received from access terminal 106 via message. registration, or in some other way).
As represented by block 1314, if access terminal 106 is not allowed access (for example, the received access terminal identifier is not in local access list 340), access point 102 may deny the access. For example, access point 102 may send a registration refusal message to access terminal 106. In addition, or alternatively, access point 102 may send a service redirection message to access terminal 106. This message may include, for example, information (eg, SID, NID, frequency of operation) that identifies an alternative access point (eg, a local macro-network) that can be accessed by access terminal 106.
As represented by block 1316, if access terminal 106 is allowed access (for example, the received access terminal identifier is in local access list 340), access point 102 may grant access to certain services. For example, as discussed above, access point 102 may grant access to local services offered by a local network.
In addition, or alternatively, access point 102 may pass registration information to network node 110 (eg, macronet HRL) for authentication and registration of access terminal 106. Network node 110 You can then respond with a registration acceptance or rejection message. In response, access point 102 may send a corresponding message to access terminal 106. If authorized, the access point 106 then obtains the request service from the access point 102 (eg, access to the network).
It should be appreciated that the above techniques can be implemented in various ways according to the teachings in this document. For example, authentication information, which is different from the information specifically mentioned above (eg, ESN, IMSI, CSG IDs), can be used in an apparatus or procedure practiced based on the teachings herein.
In some aspects, the teachings herein can be used in a network that includes macro-scale coverage (for example, a wide area cellular network, such as a 3G network, commonly referred to as a macro-cellular network, or a WAN). and smaller-scale coverage (eg, a home or building-based network environment, typically referred to as a LAN). As an access terminal travels through such a network, the access terminal can receive service at certain locations via access points that provide macro coverage, while the access terminal can receive service in other locations through access points that provide coverage on a smaller scale. In some respects, the lower coverage nodes can be used to provide incremental capacity growth, coverage within a building, and different services (for example, for a more robust user experience). In the description provided herein, a node that provides coverage over a relatively large area may be referred to as a macro-node. A node that provides coverage in a relatively small area (for example, a home) can be called a femto-node. A node that provides coverage in an area that is smaller than a macro-area and larger than a femto-area can be called a pico-node (for example, providing coverage within a shopping mall).
A cell associated with a macro-node, a femto-node or a pico-node can be called a macro-cell, a femto-cell or a pico-cell, respectively. In some implementations, each node may be associated with (eg, divided into) one or more cells or sectors.
ES 2 608 454 T3
In various applications other terminology may be used to refer to a macro-node, a femto-node, or a pico-node. For example, a macro-node can be configured, or mentioned, as an access node, a base station, an access point, an eNodeB, a macro-cell, etc. Also, a femto-node can be configured or referred to as a home NodeB, a home eNodeB, an access point base station, a femto-cell, etc.
FIG. 14 illustrates a wireless communication system 1400, configured to support a number of users, in which the teachings herein can be implemented. System 1400 provides communication for multiple cells 1402, such as, for example, macro cells 1402A through 1402G, where each cell is served by a corresponding access node 1404 (eg, access points 1404A through 1404G). As shown in FIG. 14, access terminals 1406 (eg, access terminals 1406A through 1406L) may be dispersed at various locations throughout the system over time. Each access terminal 1406 may communicate with one or more access points 1404 on a forward link ("FL") and / or a reverse link ("RL") at any given time, depending on whether the access terminal 1406 is active or not, and whether or not it is in a soft handover, for example. The 1400 wireless communication system can serve a large geographic region. For example, macro cells 1402A to 1402G can span a few blocks in a neighborhood or several kilometers in a rural setting.
FIG. 15 illustrates an exemplary communication system 1500, in which one or more femto-nodes are deployed within a network environment. Specifically, system 1500 includes multiple femto-nodes 1510 (eg, femto-nodes 1510A and 1510B) installed in a relatively small-scale network environment (eg, one or more user homes 1530). Each femto-node 1510 may be coupled to a wide area network 1540 (e.g., the Internet) and a central mobile operator network 1550, via a DSL router, cable modem, wireless link, or other means of connectivity ( not shown). As will be discussed later, each femto-node 1510 may be configured to serve associated access terminals 1520 (for example, access terminal 1520A) and, optionally, foreign access terminals 1520 (for example, access terminal 1520 1520B). In other words, access to femto-nodes 1510 can be restricted so that a given access terminal 1520 can receive service from a set of designated femto-nodes 1510 (e.g., home), but cannot receive service from any Undesignated femto-node 1510 (for example, a neighbor femto-node 1510).
FIG. 16 illustrates an example of a coverage map 1600 in which several tracking areas 1602 (or routing areas or location areas) are defined, each of which includes several macro coverage areas 1604. Here, the areas Coverage areas associated with scan areas 1602A, 1602B and 1602C are delimited by thick lines and macro coverage areas 1604 are represented by hexagons. The scan areas 1602 also include femto coverage areas 1606. In this example, each of the femto coverage areas 1606 (for example, the femto coverage area 1606C) is displayed within a macro coverage area. 1604 (for example, the macro-coverage area 1604B). However, it should be appreciated that a femto coverage area 1606 may not completely fall within a macro coverage area 1604. In practice, a large number of femto coverage areas 1606 may be defined with a given scan area 1602 or macro coverage area 1604. In addition, one or more pico-coverage areas (not shown) may be defined within a given scan area 1602 or macro-coverage area 1604.
Referring again to FIG. 15, the owner of a femto-node 1510 may subscribe to a mobile service such as, for example, a 3G mobile service, offered through the central mobile operator network 1550. In addition, an access terminal 1520 may be capable to function both in macro-environments and in smaller-scale network environments (for example, residential). In other words, depending on the current location of the access terminal 1520, the access terminal 1520 may receive service through a macro-cell access point 1560, associated with the central mobile operator network 1550, or by means of any one of a set of femtonodes 1510 (eg, femto-nodes 1510A and 1510b residing within a corresponding user address 1530). For example, when a subscriber is not at home, he receives service from a standard macro access point (for example, the 1560 access point) and, when the subscriber is at home, he receives service from a femto-node (for example, the node 1510A). In this case, it should be appreciated that a femto node 1510 may be backward compatible with existing access terminals 1520.
A femto-node 1510 can be deployed on a single frequency or, alternatively, on multiple frequencies. Depending on the particular configuration, the single frequency, or one or more of the multiple frequencies, may overlap with one or more frequencies used by a macro-access point (eg, an access point 1560).
In some aspects, an access terminal 1520 may be configured to connect to a preferred femto-node (eg, the home femto-node of access terminal 1520) whenever such connectivity is possible. For example, whenever access terminal 1520 is within the home of user 1530, it may be desired that access terminal 1520 communicate only with home femto-node 1510.
In some aspects, if the access terminal 1520 operates within the macro-cellular network 1550, but does not reside in its most preferred network (for example, as defined in a preferred roaming list), the access terminal 1520
ES 2 608 454 T3 can continue to search for the most preferred network (for example, the preferred femto node 1510) using a Best System Re-selection ("BSR"), which may involve a periodic scan of available systems, to determine if whether or not there are better systems currently available, and subsequent actions for association with such preferred systems. With the acquisition input, the access terminal 1520 can limit the search for specific band and channel. For example, the search for the most preferred system can be repeated periodically. Upon discovering a preferred femto node 1510, access terminal 1520 selects femto node 1510 to establish itself within its coverage area.
A femto-node can be limited in some respects. For example, a given femto-node can only provide certain services to certain access terminals. In deployments with so-called restricted (or closed) association, a given access terminal can only be served via the mobile macro-cell network and via a defined set of femto-nodes (for example, the femto-nodes 1510 that reside within the corresponding 1530 user address). In some implementations, a node may be limited to not providing, for at least one node, at least one of: signaling, data access, registration, paging, or service.
In some aspects, a restricted femto-node (which may also be referred to as a Closed Subscriber Group Home NodeB) is one that provides service to a restricted endowed set of access terminals. This set can be expanded temporarily or permanently as required. In some aspects, a closed subscriber group (CSG) can be defined as the set of access points (eg, femtonodes) that share a common access control list of access terminals. A restricted access point can include a CSG that allows multiple access terminals to connect to it. A single access terminal may have the ability to connect to multiple restricted access points. A channel in which all femto-nodes (or all restricted femto-nodes) function in a region can be called a femto-channel.
Therefore, several relationships can exist between a given femto-node and a given access terminal. For example, from the perspective of an access terminal, an open femto-node can refer to a femto-node without any restricted association (eg, the femto-node allows access to any access terminal). A restricted femto-node can refer to a femto-node that is restricted in some way (for example, restricted for association and / or registration). A home femto-node can refer to a femto-node to which the access terminal is authorized to access and on which it can perform operations (for example, permanent access is provided for a defined set of one or more access terminals) . A guest femto-node can refer to a femto-node that an access terminal can access, or with which it can operate, temporarily. A foreign femtonode may refer to a femto-node that the access terminal cannot access, nor can it operate with, except, perhaps, in emergency situations (for example, calls to 112).
From the perspective of a restricted femto-node, a home access terminal may refer to an access terminal that is authorized to access the restricted femto-node (eg, the access terminal has permanent access to the femto-node). A guest access terminal can refer to an access terminal with temporary access to the restricted femto-node (for example, limited based on a deadline, usage time, octets, connection count or some, or some , other criteria (s)). A foreign access terminal may refer to an access terminal that does not have permission to access the restricted femto-node, except perhaps in emergency situations, for example, such as calls to 112 (for example, an access terminal that does not have credentials or permissions to register on the restricted femto-node).
For convenience, the present disclosure describes various functionality in the context of a femtonode. However, it should be appreciated that a pico-node can provide the same or similar functionality for a larger coverage area. For example, a pico-node can be restricted, a home pico-node can be defined for a given access terminal, and so on.
A multiple access wireless communication system can simultaneously support communication for multiple wireless access terminals. As mentioned above, each terminal can communicate with one or more base stations by transmissions on the forward and reverse links. Forward link (or downlink) refers to the communication link from the base stations to the terminals, and the reverse link (or uplink) refers to the communication link from the terminals to the base stations. This communication link can be established using a single input single output system, a multiple input multiple output (MIMO) system, or some other type of system.
A MIMO system uses multiple (Nt) transmit antennas and multiple (Nr) receive antennas for data transmission. A MIMO channel made up of the Nt transmitting antennas and the Nr receiving antennas can be decomposed into Ns independent channels, which are also called spatial channels, where Ns min {Nt, Nr}. Each of the Ns independent channels corresponds to a dimension. The MIMO system can provide improved performance (eg, higher throughput and / or increased reliability) by utilizing the additional dimensions created by multiple transmit and receive antennas.
ES 2 608 454 T3
A MIMO system can support time division duplex (TDD) and frequency division duplex (FDD). In a TDD system, the transmissions on the forward link and the reverse link are in the same frequency region, so the reciprocity principle allows estimation of the forward link channel from the reverse link channel. This allows the access point to extract a transmission beamforming gain on the forward link when multiple antennas are available at the access point.
The teachings herein can be incorporated into a node (eg, a device) that uses various components for communication with at least one other node. FIG. 17 illustrates several sample components that can be used to facilitate communication between nodes. Specifically, FIG. 17 illustrates a wireless device 1710 (eg, an access point) and a wireless device 1750 (eg, an access terminal) of a MIMO 1700 system. At device 1710, traffic data for a number of data streams is provided from a data source 1712 to a transmission data processor (TX) 1714.
In some aspects, each data stream is transmitted through a respective transmitting antenna. The TX data processor 1714 formats, encodes, and interleaves the traffic data for each data stream based on a particular encoding scheme selected for that data stream, to provide encoded data.
The encoded data for each data stream can be multiplexed with pilot data using OFDM techniques. Pilot data is typically a known data pattern that is processed in a known way and that can be used in the receiving system to estimate the channel response. The multiplexed pilot data and encoded data for each data stream are then modulated (e.g. symbol mapped) based on a particular modulation scheme (e.g. BPSK, QSPK, M-PSK, or M-QAM) selected for that data stream to provide modulation symbols. The data transfer rate, encoding, and modulation for each data stream can be determined by instructions carried out by a processor 1730. A data memory 1732 can store program code, data, and other information used by processor 1730 or other components of device 1710.
The modulation symbols for all data streams are then provided to a TX 1720 MIMO processor, which can further process the modulation symbols (eg, for OFDM). The TX MIMO processor 1720 then provides Nt modulation symbol streams to Nt transceivers (XCVR) 1722A through 1722T. In some aspects, the TX 1720 MIMO processor applies beamforming weights to the symbols in the data streams and to the antenna from which the symbol is being transmitted.
Each 1722 transceiver receives and processes a respective symbol stream to provide one or more analog signals, and further conditions (for example, amplifies, filters, and increases in frequency) the analog signals to provide a modulated signal suitable for transmission on the broadcast channel. MIME. The Nt modulated signals from transceivers 1722A through 1722T are then transmitted from Nt antennas 1724A through 1724T, respectively.
In device 1750, the transmitted modulated signals are received by Nr antennas 1752A through 1752R and the received signal from each antenna 1752 is provided to a respective transceiver (XCVR) 1754A through 1754R. Each transceiver 1754 conditions (eg, filters, amplifies, and downgrades) a respective received signal, digitizes the conditioned signal to provide samples, and further processes the samples to provide a corresponding received symbol stream.
Next, a receive data processor (RX) 1760 receives and processes the Nr symbol streams received from the Nr transceivers 1754 based on a particular receiver processing technique to provide Nt detected symbol streams. The RX 1760 data processor then demodulates, de-interleaves, and decodes each detected symbol stream to recover the traffic data for the data stream. Processing by the RX 1760 data processor is complementary to that performed by the TX 1720 MIMO processor and the TX 1714 data processor of the 1710 device.
A 1770 processor periodically determines which pre-encoding matrix to use (discussed later). Processor 1770 formulates a reverse link message that comprises an array index portion and a rank value portion. A data memory 1772 can store the program code, data, and other information used by the 1770 processor or other components of the 1750 device.
The reverse link message may comprise various types of information related to the communication link and / or the received data flow. The reverse link message is then processed by a TX data processor 1738, which also receives traffic data for a number of data streams from a data source 1736, is modulated by a modulator 1780, is conditioned by the transceivers 1754A to 1754R and transmitted back to device 1710.
ES 2 608 454 T3
At device 1710, modulated signals from device 1750 are received by antennas 1724, conditioned by transceivers 1722, demodulated by a demodulator ("DEMOD") 1740, and processed by an RX data processor 1742 to extract the link message. inverse transmitted by device 1750. Next, processor 1730 determines which precoding matrix to use to determine beamforming weights and then processes the extracted message.
FIG. 17 also illustrates that the communication components may include one or more components that perform access control operations, as indicated herein. For example, an access control component 1790 may act in conjunction with processor 1730 and / or other components of device 1710 to send / receive signals to / from another device (for example, device 1750), as described in present document. Also, an access control component 1792 may cooperate with processor 1770 and / or other components of device 1750 to send / receive signals to / from another device (eg, device 1710). It should be appreciated that, for each device 1710 and 1750, the functionality of two or more of the described components can be provided by a single component. For example, a single processing component can provide the functionality of the 1790 access control component and the 1730 processor, and a single processing component can provide the functionality of the 1792 access control component and the 1770 processor.
The teachings herein can be incorporated into various types of communication systems and / or system components. In some aspects, the teachings herein can be used in a multiple access system capable of supporting communications with multiple users, sharing available system resources (for example, specifying one or more of the bandwidth, power transmission, encoding, interleaving, etc.). For example, the teachings herein can be applied to any one, or combinations, of the following technologies: Code Division Multiple Access Systems (CDMA), Multi-Carrier CDMA (MCCDMA), Broadband CDMA (W-CDMA), High Speed Packet Access Systems (HSPA, HSPA +), Division Multiple Access Systems time (TDMA), frequency division multiple access (FDMA) systems, single carrier FDMA (SC-FDMA) systems, orthogonal frequency division multiple access (OFDMA) or other multiple access techniques. A wireless communication system using the teachings herein can be designed to implement one or more standards, such as IS-95, cdma2000, IS-856, W-CDMA, TDSCDMA, and other standards. A CDMA network may implement radio technology such as Universal Terrestrial Radio Access (UTRA), cdma2000, or some other technology. The UTRA includes the W-CDMA and the low speed chip (LCR). The cdma2000 technology encompasses the IS-2000, IS-95, and IS-856 standards. A TDMA network can implement radio technology such as the Global System for Mobile Communications (GSM). An OFDMA network can implement radio technology such as Evolved UTRA (E-UTRA), IEEE 802.11, IEEE 802.16, IEeE 802.20, Flash-OFDM_, etc. UTRA, EUTRA and GSM are part of the Universal Mobile Telecommunications System (UMTS). The teachings herein can be implemented in a 3GPP Long Term Evolution (LTE) system, an Ultra-mobile Broadband (UMB) system, and other types of systems. LTE is a version of UMTS that uses the E-UTRA. Although certain aspects of the disclosure may be described using 3GPP terminology, it should be understood that the teachings herein may apply to 3GPP technology (Re199, Re15, Re16, Re17) as well as 3GPP2 technologies (IxRTT, 1xEV-DO ReIO , RevA, RevB) and other technologies.
The teachings herein may be incorporated into (eg, implemented within, or carried out by) various apparatus (eg, nodes). In some aspects, a node (eg, a wireless node) implemented in accordance with the teachings herein may comprise an access point or an access terminal.
For example, an access terminal may comprise, be implemented as or be called, a user equipment, a subscriber station, a subscriber unit, a mobile station, a mobile, a mobile node, a remote station, a remote terminal, a user terminal, a user agent, a user device or using other terminology. In some implementations, an access terminal may comprise a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop station (WLL), a personal digital assistant (PDA), a wireless capable handheld device or some other suitable processing device connected to a wireless modem. Accordingly, one or more aspects disclosed herein may be incorporated into a telephone (eg, a cell phone or a smart phone), a computer (eg, a laptop), a portable communications device, a portable computing device (for example, a personal data assistant), an entertainment device (for example, a music device, a video device, or a satellite radio), a Global Location System device or any other suitable device that is configured to communicate over a wireless medium.
An access point may comprise, be implemented as or be called, a NodeB, an eNodeB, a radio network controller (RNC), a base station (BS), a radio base station (RBS), a base station controller ( BSC), a base transceiver station (BTS), a function transceiver (TF), a radio transceiver, a
ES 2 608 454 T3 radio router, a basic service set (BSS), an extended service set (ESS) or using other similar terminology.
In some aspects, a node (eg, an access point) may comprise an access node for a communication system. Such an access node can provide, for example, connectivity to or with a network (eg, a wide area network such as the Internet or a cellular network) via a wired or wireless communication link to the network. Consequently, the access node may allow another node (eg, an access terminal) to access a network, or some other functionality. Furthermore, it should be appreciated that one or both of the nodes may be portable or, in some cases, relatively non-portable.
Furthermore, it should be appreciated that a wireless node may be capable of transmitting and / or receiving information non-wirelessly (eg, via a wired connection). Therefore, a receiver and transmitter, such as those discussed herein, may include suitable communication interface components (eg, electrical or optical interface components) for communicating over a non-wireless medium.
A wireless node may communicate via one or more wireless communication links that are based on, or otherwise support, any suitable wireless communication technology. For example, in some aspects, a wireless node can be associated with a network. In some aspects, the network may comprise a local area network or a wide area network. A wireless device may support, or otherwise use, one or more of various wireless communication technologies, protocols, or standards, such as those discussed herein (e.g., CDMA, TDMA, OFDM, OFDMA, WiMAX, Wi-Fi, etc.). Similarly, a wireless node may support, or otherwise use, one or more of several corresponding modulation or multiplexing schemes. Thus, a wireless node can include suitable components (eg, air interfaces) for establishing and communicating via one or more wireless communication links, using the above or other wireless communication technologies. For example, a wireless node may comprise a wireless transceiver with associated transmitting and receiving components, which may include various components (eg, signal generators and signal processors) that facilitate communication over a wireless medium.
The components described herein can be implemented in multiple ways. Referring to FIGs. 18-28, the 1800, 1900, 2000, 2100, 2200, 2300, 2400, 2500, 2600, 2700, and 2800 apparatuses are represented as a series of interrelated functional blocks. In some aspects, the functionality of these blocks can be implemented as a processing system that includes one or more processing components. In some aspects, the functionality of these blocks can be implemented using, for example, at least a part of one or more integrated circuits (for example, an ASIC). As discussed herein, an integrated circuit can include a processor, software, other related components, or some combination thereof. The functionality of these blocks can also be implemented differently from how it is taught in this document. In some aspects, one or more of the dashed blocks of FIGs. 18 to 28 are optional.
Apparatus 1800, 1900, 2000, 2100, 2200, 2300, 2400, 2500, 2600, 2700, and 2800 may include one or more modules that can perform one or more of the functions described above with respect to the various figures. For example, a receiving / sending means 1802 may correspond, for example, to a communication controller, as discussed herein. A means of determining an identifier 1804 may correspond, for example, to a gatekeeper, as discussed herein. An allowed service determination means 1806 may correspond, for example, to a gatekeeper, as discussed herein. A receiving means 1902 may correspond, for example, to a communication controller, as discussed in this document. A delivery medium 1904 may correspond, for example, to a gatekeeper, as discussed in this document. An identifier determination means 1906 may correspond, for example, to a gatekeeper, as discussed herein. A delivery medium 2002 may correspond, for example, to a gatekeeper, as discussed in this document. A reception means 2004 may correspond, for example, to a communication controller, as discussed in this document. A means of determining allowed service 2006 may correspond, for example, to a gatekeeper, as discussed in this document. A configuration means 2102 may correspond, for example, to a provisioning controller, as discussed herein. A means of obtaining 2104 can correspond, for example, to a gatekeeper, as discussed in this document. A receiving means 2106 may correspond, for example, to a communication controller, as discussed in this document. A determination means 2108 may correspond, for example, to a gatekeeper, as discussed in this document. An identifier determination means 2202 may correspond, for example, to a provisioning controller, as discussed herein. A sending means 2204 may correspond, for example, to a communication controller, as discussed in this document. An allocation means 2206 may correspond, for example, to a provisioning controller, as discussed herein. A receiving means 2302 may correspond, for example, to a provisioning controller, as discussed herein. A transmission medium 2304 may correspond, for example, to a communication controller, as discussed herein. An identifier determination means 2402 may correspond, for example, to a provisioning controller, as discussed herein. A means of delivery
ES 2 608 454 T3
2404 it may correspond, for example, to a communication controller, as discussed in this document. A receiving means 2502 may correspond, for example, to a communication controller, as discussed in this document. An access enablement determination means 2504 may correspond, for example, to a gatekeeper, as discussed herein. A configuration-based determination means 2506 may correspond, for example, to a gatekeeper, as discussed herein. A list maintenance means 2508 may correspond, for example, to a gatekeeper, as discussed in this document. A configuration means 2602 may correspond, for example, to a provisioning controller, as discussed herein. A transmission medium 2604 may correspond, for example, to a communication controller, as discussed herein. A receiving means 2606 may correspond, for example, to a communication controller, as discussed in this document. A dispatch means 2608 may correspond, for example, to a provisioning controller, as discussed herein. A definition means 2610 may correspond, for example, to a provisioning controller, as discussed herein. A monitoring means 2702 may correspond, for example, to a receiver, as discussed herein. A beacon receiving means 2704 may correspond, for example, to a receiver, as discussed herein. A sending means 2706 may correspond, for example, to a communication controller, as discussed herein. A roaming list receiving means 2708 may correspond, for example, to a provisioning controller, as discussed herein. A configuration means 2802 may correspond, for example, to a provisioning controller, as discussed herein. A beacon receiving means 2804 may correspond, for example, to a receiver, as discussed herein. A sending means 2806 may correspond, for example, to a communication controller, as discussed in this document. An authorization receiving means 2808 may correspond, for example, to a gatekeeper, as discussed in this document. A solicitation means 2810 may correspond, for example, to a gatekeeper, as discussed in this document. A display medium 2812 may correspond, for example, to a gatekeeper, as discussed herein.
It should be understood that any reference to an item herein, using a designation such as first, second, etc., does not generally limit the number or order of those items. Instead, these designations may be used herein as a convenient way to distinguish between two or more items or instances of an item. Therefore, a reference to first and second elements does not mean that only two elements can be used there, or that the first element must precede the second element in some way. In addition, unless otherwise indicated, an item set may comprise one or more items.
Those skilled in the art will understand that the information and signals can be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols and chips that may have been mentioned throughout the above description, can be represented by voltages, currents, electromagnetic waves, fields or magnetic particles, optical fields or particles, or any combination thereof.
Those skilled in the art will further appreciate that any of the various illustrative logic blocks, modules, processors, media, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware (e.g., a digital implementation , an analog implementation or a combination of the two, which can be designed using source encoding or some other technique), as various forms of program or design code that include instructions (which may be referred to herein, for convenience, as "software" or software module "), or as combinations of the foregoing. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above, generally with respect to their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and the design limitations imposed on the entire system. Those skilled in the art may implement the described functionality in different ways for each particular application, but such implementation decisions should not be construed as a departure from the scope of the present disclosure.
The various illustrative logic blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented within, or carried out by, an integrated circuit (IC), an access terminal, or an access point. The IC may comprise a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, logic logic. discrete or transistor gates, discrete hardware components, electrical components, optical components, mechanical components or any combination thereof designed to perform the functions described herein, and may execute codes or instructions that reside on the IC, outside the IC, or both. A general purpose processor can be a microprocessor but, alternatively, the processor can be any conventional processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors together with a
ES 2 608 454 T3 DSP core or any other such configuration.
It should be understood that any specific order or hierarchy of steps in any disclosed process is an example of a sample approach. Based on design preferences, it should be understood that the specific order or hierarchy of stages in processes may be reorganized while remaining within the scope of this disclosure. The accompanying method claims present elements of the various steps in a sample order, and are not intended to be limited to the specific order or hierarchy presented.
The functions described can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions, such as one or more instructions or code, can be stored on, or transmitted by, a computer-readable medium. Computer-readable media includes both computer storage media and communication media, including any medium that facilitates the transfer of a computer program from one place to another. A storage medium can be any available medium that can be accessed by a computer. By way of example, and not by way of limitation, such computer-readable media may comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to transport or store desired program code in the form of instructions or data structures and can be accessed by a computer. Furthermore, any connection is appropriately called a computer-readable medium. For example, if the software is transmitted from a network site, server, or other remote source, using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwave, are included in the definition of medium. Discs, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disc, and Blu-ray disc, where some discs typically they reproduce data magnetically, while other discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media. In summary, it should be appreciated that a computer-readable medium can be implemented in any suitable computer program product.
In view of the above, in some aspects a first communication procedure comprises: determining an identifier for a set of at least one access point that is configured to provide at least one service only to a set of at least one access terminal, wherein the identifier uniquely identifies the set of at least one access point within an operator network; and sending the identifier to each access point in the set of at least one access point. Furthermore, in some aspects at least one of the following may also apply to the first communication method: the identifier comprises a network identifier, and the network comprises a cellular operator domain; the identifier is determined in conjunction with the activation of an access point of the set of at least one access point; the set of at least one access point comprises a plurality of access points belonging to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers; the identifier is text-based; each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; each access point of the set of at least one access point comprises a femto-node or a pico-node; determining the identifier comprises receiving a request for an identifier and determining whether or not the identifier is already in use by at least one other access point; if the requested identifier is already in use by at least one other access point, sending the identifier comprises sending a response to the request comprising an identifier that is not in use by any other access point; each access point of the set of at least one access point provides at least one other service to at least one other access terminal; the method further comprises assigning a unique device identifier for each access point of the set of at least one access point; each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal.
Also in view of the above, in some aspects a second communication procedure comprises: receiving an identifier for a set of at least one access point at an access point of the set, wherein each access point of the set is configured to provide at least one service only for a set of at least one access terminal, and wherein the identifier uniquely identifies the at least one access point within an operator network; and the transmission of the identifier over the air. Furthermore, in some aspects, at least one of the following may also be applied to the second communication method: the method further comprises receiving a registration message from an access terminal, from the set of at least one access terminal, in response to the transmission of the identifier; the identifier comprises a network identifier, and the network comprises a cellular operator domain; the identifier is received as a result of the activation of the access point receiving the identifier; the set of at least one access point comprises a plurality of access points belonging to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers; the identifier is text-based; each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group that
ES 2 608 454 T3 consists of: signaling, data access, registration and service; each access point of the set of at least one access point comprises a femto-node or a pico-node; each access point of the set of at least one access point provides at least one other service to at least one other access terminal; each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal; the identifier is received in response to a request for the identifier; The method further comprises determining a proposed identifier, wherein the request includes the proposed identifier.
Also in view of the above, in some aspects a third communication method comprises: determining the identifiers of the access terminals of a set of access terminals; and sending the identifiers to at least one access point that is configured to provide at least one service only to the set of access terminals. Furthermore, in some aspects at least one of the following may also apply to the third communication method: the identifiers comprise permanent identifiers for the access terminals; the identifiers comprise temporary identifiers for the access terminals; the identifiers comprise the network address identities or ISDN numbers of the mobile station; identifiers are sent in response to a request from an access point of the at least one access point; the determination comprises receiving the identifiers from a network node; the determination comprises receiving the identifiers from a network server that allows a user to specify the access terminals which are allowed to receive the at least one service from the at least one access point; the set of access terminals are associated with a common closed group of subscribers; each access point of the at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; each access point of the at least one access point comprises a femtonode or a pico-node; Each access point of the at least one access point provides at least one other service to at least one other access terminal.
Also in view of the above, in some aspects, a fourth communication method comprises: receiving a message referring to a request from an access terminal to access an access point, in which the message comprises a first identifier associated with the terminal access; determining a second identifier associated with the access terminal based on the first identifier; and determining whether or not the access terminal is allowed to receive service from the access point based on the second identifier and at least one identifier associated with the access point. Furthermore, in some aspects, at least one of the following may also apply to the fourth communication method: the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier; the second identifier comprises a network address identity of the access terminal or a mobile station integrated services digital network number of the access terminal; the second identifier identifies at least one closed group of subscribers to which the access terminal can access, and at least one identifier associated with the access point comprises a closed group identifier of subscribers, associated with the access point; the at least one identifier associated with the access point comprises an access list for the access point and determining whether or not the access terminal is allowed to receive service from the access point comprises determining whether the second identifier is or not in the access list; a network node makes the determination whether or not the access terminal is allowed to receive service from the access point, the message comprises a request from an access point to authenticate the access terminal, and the method further comprises sending , to the access point, of a message indicative of determining whether or not the access terminal is allowed to receive service from the access point; determining the second identifier comprises sending the first identifier to a network node and receiving the second identifier from the network node; the access point makes the determination whether or not the access terminal is allowed to receive service from the access point; the at least one identifier associated with the access point is received from a network node; determining whether or not the access terminal is allowed to receive service from the access point comprises: sending the second identifier and the at least one identifier associated with the access point to a network node, and receiving, from the network node , an indication of whether or not the access terminal is allowed to receive service from the access point; determining whether or not the access terminal is allowed to receive service from the access point comprises: sending the second identifier to a network node, and receiving the at least one identifier associated with the access point from the network node; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also in view of the above, in some aspects, a fifth communication method comprises: receiving a request from an access point for authentication of an access terminal; and sending, to the access point, at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. Furthermore, in some aspects, at least one of the following may also apply to the fifth communication method: the at least one identifier comprises a closed subscriber group identifier; the request comprises a network address identity of the access terminal or a mobile station integrated services digital network number of the access terminal; the method further comprises determining the at least one identifier based on a permanent identifier associated with the access terminal, and determining the permanent identifier based on a temporary identifier associated with the access terminal; the request comprises the temporary identifier; determining the permanent identifier
ES 2 608 454 T3 comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node; the method further comprises receiving the at least one identifier from a network node; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also in view of the above, in some aspects, a sixth communication method comprises: sending, via an access point, an authentication request from an access terminal; and receiving, in response to the request, at least one identifier that identifies at least one set of access points from which the access terminal is allowed to receive at least one service. Furthermore, in some aspects, at least one of the following may also apply to the sixth communication method: the method further comprises determining whether or not the access terminal is allowed to receive service from the access point based on at least an identifier; the at least one identifier comprises a closed subscriber group identifier; the at least one identifier identifies a closed group of subscribers to which the access terminal can access, and the determination comprises determining whether or not the at least one identifier matches a closed group of subscribers identifier associated with the access point; the request is sent based on a determination that the access terminal does not appear in a local access list of the access point; the request comprises a network address identity of the access terminal or a mobile station integrated services digital network number of the access terminal; the request comprises a temporary identifier associated with the access terminal; The method further comprises obtaining session information associated with the access terminal from a network node, wherein: the session information comprises context information for the access terminal and the request comprises context information; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also, in view of the foregoing, in some aspects a seventh communication procedure comprises: sending, through an access point, a request comprising an identifier of a set of at least one access terminal that can receive service from the access point access; and receiving, in response to the request, a list of at least one access terminal authorized to receive service from the access point. Furthermore, in some aspects, at least one of the following may also apply to the seventh communication method: the method further comprises determining whether or not the access terminal is allowed to receive service from the access point based on at least an identifier; the at least one identifier comprises at least one subscriber closed group identifier; the identifier comprises a list of at least one identifier of a closed group of subscribers, associated with the access terminal, and the determination comprises determining whether a closed group identifier of subscribers, associated with the access point, is or is not in the list; the request is sent based on a determination that the access terminal does not appear in a local access list of the access point; the request comprises a network address identity of the access terminal or a mobile station integrated services digital network number of the access terminal; the request comprises a temporary identifier associated with the access terminal; the method further comprises obtaining session information, associated with the access terminal, from a network node, in which: the session information comprises context information for the access terminal, and the request comprises the context information; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femtonode or a pico-node.
Also in view of the above, in some aspects, an eighth communication method comprises: receiving, from a first access point, an identifier of at least one other access point that an access terminal can access; and determining, based on the identifier, whether or not access to the at least one other access point is enabled. Furthermore, in some aspects at least one of the following may also apply to the eighth communication method: the determination comprises requesting a user to determine whether or not access is enabled; determining comprises displaying an indication of the identifier and receiving input from the user, indicative of whether or not access is enabled; the method further comprises determining, based on the configuration information, whether access is automatically allowed or access is allowed in response to a request; the method further comprises maintaining a list of access points that the access terminal is authorized to access, wherein the determination is further based on the list; the method further comprises maintaining a list of access points that a user has chosen not to access, wherein the determination is further based on the list; the identifier comprises a network identifier; the identifier comprises a closed subscriber group identifier; the identifier is received by means of an SMS message, an application protocol message, a radio link message or a page; the identifier is received from a network node; each access point of the at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; Each access point of the at least one access point comprises a femto-node or a pico-node.
Also in view of the above, in some aspects, a ninth communication method comprises: configuring an access point in an initialization mode; transmit a default beacon comprising a default configuration during initialization mode; receive a message from a terminal
ES 2 608 454 T3 access in response to default beacon; and sending a preferred roaming list to the access terminal in response to the message. Furthermore, in some aspects, at least one of the following may also apply to the ninth communication procedure: the default beacon comprising the default configuration is transmitted at a first power level, the procedure further comprising the access point configuration in a different mode of operation, whereby the beacons are transmitted at a second power level that is higher than the first power level; the first power level provides a smaller coverage area than that provided by the second power level; the default configuration comprises a default network identifier that is different from a network identifier that is used for a non-initializing mode of operation; the default configuration specifies the default system and network identifiers of at least one access point of a higher priority and the preferred roaming list specifies other system and network identifiers of the at least one access point of the most high priority; the default beacon is broadcast on a default frequency, and the preferred roaming list specifies another beacon frequency for the access point, which is different from the default frequency; the method further comprises defining the preferred roaming list based on another preferred roaming list, associated with the access terminal; the method further comprises receiving the other preferred roaming list from the access terminal; the method further comprises receiving the other preferred roaming list from a network node; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also in view of the above, in some aspects, a tenth communication method comprises: monitoring, at an access terminal, for beacons, based on a first preferred roaming list that specifies a default configuration; receiving a beacon comprising the default configuration from an access point, as a result of monitoring; sending a message to the access point in response to the received beacon; and receiving a second roaming list from the access point in response to the message, wherein the second roaming list specifies a configuration other than the default configuration. Furthermore, in some aspects at least one of the following factors may also apply to the tenth communication procedure: the first preferred roaming list comprises a default roaming list for initialization operations, and the second preferred roaming list comprises a list roaming for non-initialization operations; the default configuration comprises a default network identifier; the second preferred roaming list comprises another network identifier associated with the access point, which is different from the default network identifier; the beacon is received at a default frequency, specified by the first preferred roaming list, and the second preferred roaming list specifies a carrier frequency for the access point, which is different from the default frequency; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femtonode or a pico-node.
Also in view of the above, in some aspects, an eleventh communication method comprises: configuring an access point with a first identifier of an access terminal; obtaining a second identifier from the access terminal based on the first identifier; receiving a message requesting access from the access terminal; and determining, at the access point, whether or not the requested access is allowed based on the second identifier. Furthermore, in some aspects at least one of the following may also be applied to the eleventh communication method: the first identifier comprises a network address identity or a mobile station integrated services digital network number; the second identifier comprises an electronic serial number or an international mobile subscriber identity; obtaining comprises: sending the first identifier to a network node, and receiving the second identifier from the network node, as a result of sending the first identifier; the determination comprises comparing an identifier received by the message from the access terminal with the second identifier; the determination comprises: sending the second identifier to a network node, and receiving, as a result of sending the second identifier, an indication as to whether or not the requested access is allowed; the access point is configured through a network interface; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also in view of the above, in some aspects a twelfth communication procedure comprises: configuring an access terminal with a preferred roaming list that includes an identifier of a set of access points that are restricted to serving limited sets access terminals; receiving a beacon from one of the access points, in which the beacon comprises the identifier; sending a message to the access point in response to the beacon; and receiving authorization to access the access point in response to the message. Furthermore, in some aspects at least one of the following may also apply to the twelfth communication procedure: the set of access points comprises all access points in a cellular operator domain, which are restricted to serving limited sets of terminals access; the identifier comprises a network identifier; the preferred roaming list specifies a carrier frequency used by all access points; The procedure also comprises requesting a user to determine whether or not to access the access point; the procedure further comprises
ES 2 608 454 T3 displaying an access point indication and receiving user input indicative of whether or not the access point is accessed; the access terminal automatically determines whether or not the access point is accessed; each access point of the set of access points is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; each access point of the set of access points comprises a femto-node or a pico-node.
Also in view of the above, in some aspects a thirteenth communication procedure comprises: receiving a request from an access point for authentication of an access terminal; determining whether or not the access terminal is allowed to receive service from the access point, based on an identifier of a set of at least one access terminal that receives service from the access point; and sending a message indicative of the determination to the access point. Furthermore, in some aspects at least one of the following may also be applied to the thirteenth communication procedure: determining comprises determining whether or not the identifier is in an access list of the access point; the request comprises the access list; the identifier comprises a permanent identifier, the method further comprises determining the permanent identifier based on a temporary identifier of the set of at least one access terminal; determining the permanent identifier comprises sending the temporary identifier to a network node and receiving the permanent identifier from the network node; the identifier comprises a closed subscriber group identifier; the identifier comprises a list of at least one identifier of a closed group of subscribers, associated with the set of at least one access terminal, and the determination comprises determining whether a closed group identifier of subscribers, associated with the access point, is or is not on the list; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
Also in view of the above, in some respects, a fourteenth communication procedure comprises: receiving, at an access point, an access request from an access terminal, in which the access request comprises a first identifier associated with the access terminal; determining a second identifier associated with the access terminal based on the first identifier; and determining whether or not the access terminal is allowed to receive service from the access point based on the second identifier, and a list of at least one access terminal authorized to receive service from the access point. Furthermore, in some aspects, at least one of the following may also be applied to the fourteenth communication procedure: the first identifier comprises a temporary identifier and the second identifier comprises a permanent identifier; the first identifier comprises a network address identity of the access terminal or a mobile station integrated services digital network number of the access terminal; the list is received from a network node and comprises the individual access terminal identifiers; the second identifier comprises a closed subscriber group identifier, associated with the access terminal, and the list comprises a closed subscriber group identifier, associated with the access point; the determination comprises: sending the second identifier and the list to a network node, and receiving, from the network node, an indication of whether or not the access terminal is allowed to receive service from the access point; the determination comprises: sending the second identifier to a network node, and receiving the list from the network node; the access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service; the access point comprises a femto-node or a pico-node.
In some aspects, the functionality corresponding to one or more of the above aspects of the first, second, third, fourth, fifth, sixth, seventh, eighth, ninth, tenth, eleventh, twelfth, thirteenth, and fourteenth communication procedures may be implemented, for example, in an apparatus using the structure as taught herein. In addition, a computer program product may comprise codes configured to cause equipment to provide functionality that corresponds to one or more of the above aspects of these communication procedures.
The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications of these aspects will be immediately apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Therefore, the present disclosure is not intended to be limited to the aspects set forth herein, but is to be granted the broadest scope consistent with the principles and novel features disclosed herein.
Alternative examples
1. A communication method, comprising: determining an identifier for a set of at least one access point that is configured to provide at least one service only for a set of at least one access terminal, where the identifier uniquely identifies the set of at least one access point within an operator network; and sending the identifier to each access point in the set of at least one access point.
two. The procedure of Example 1, in which: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
ES 2 608 454 T3
3. The method of example 2, in which the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers.
Four. The procedure in Example 2, where the identifier is text-based.
5. The procedure of example 2, in which each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, access to data, registration and service.
6. The method of Example 1, wherein determining the identifier comprises receiving a request for an identifier and determining whether or not the identifier is already in use by at least one other access point.
7. The procedure of example 6, in which, if the requested identifier is already in use by the at least one other access point, sending the identifier comprises sending a response to the request that includes an identifier that is not in use by any other access point.
8. The method of Example 1, further comprising assigning a unique device identifier for each access point of the set of at least one access point.
9. The procedure of example 1, in which each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal.
10. An apparatus for communication, comprising: means for determining an identifier for a set of at least one access point that is configured to provide at least one service only for a set of at least one access terminal, where the identifier identifies of uniquely the set of at least one access point within an operator network; and means for sending the identifier to each access point in the set of at least one access point.
eleven. The apparatus of Example 10, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
12. The apparatus of example 11, wherein the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers.
13. The apparatus of Example 11, where the identifier is text-based.
14. The apparatus of example 11, in which each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, access to data, registration and service.
fifteen. The apparatus of Example 10, wherein determining the identifier comprises receiving a request for an identifier and determining whether or not the identifier is already in use by at least one other access point.
16. The apparatus of example 15, in which, if the requested identifier is already in use by the at least one other access point, sending the identifier comprises sending a response to the request comprising an identifier that is not in use by no other access point.
17. The apparatus of Example 10, further comprising means for assigning a unique device identifier to each access point of the set of at least one access point.
18. The apparatus of example 10, in which each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal.
19. An apparatus for communication, comprising: a provisioning controller configured to determine an identifier for a set of at least one access point that is configured to provide at least one service only for a set of at least one access terminal, where the identifier uniquely identifies the set of at least one access point within an operator network; and a communication controller configured to send the identifier to each access point in the set of at least one access point.
twenty. The apparatus of Example 19, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
twenty-one. The apparatus of Example 20, wherein the set of at least one access point comprises a plurality of
ES 2 608 454 T3 access points that are associated with a common closed group of subscribers.
22. Example apparatus 20, in which the identifier is text-based.
2. 3. A computer program product, comprising: a computer-readable medium comprising codes for causing a computer to: determine an identifier for a set of at least one access point that is configured to provide at least one service only for a set of at least one access terminal, wherein the identifier uniquely identifies the set of at least one access point within an operator network; and send the identifier to each access point in the set of at least one access point.
24. The computer program product of Example 23, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
25. A communication method, comprising: receiving an identifier for a set of at least one access point at an access point of the set, wherein each access point of the set is configured to provide at least one service only for a set of at least one access terminal, and wherein the identifier uniquely identifies at least one access point within an operator network; and the transmission of the identifier over the air.
26. The procedure of Example 25, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
27. The method of example 26, in which the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers.
28. The procedure in Example 26, where the identifier is text-based.
29. The procedure of example 26, in which each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, access to data, registration and service.
30. The procedure of example 25, in which each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal.
31. The procedure of Example 25, in which the identifier is received in response to a request for the identifier.
32. An apparatus for communication, comprising: means for receiving an identifier for a set of at least one access point in one access point of the set, wherein each access point of the set is configured to provide at least one service only for a set of at least one access terminal, and wherein the identifier uniquely identifies at least one access point within an operator network; and means for transmitting the identifier over the air.
33. The apparatus of Example 32, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
3. 4. The apparatus of example 33, wherein the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers.
35. The apparatus of Example 33, in which the identifier is text-based.
36. The apparatus of example 33, in which each access point of the set of at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, access to data, registration and service.
37. The apparatus of example 32, in which each access point of the set of at least one access point offers different services, for the set of at least one access terminal, than for at least one other access terminal.
38. The apparatus of Example 32, wherein the identifier is received in response to a request for the identifier.
39. An apparatus for communication, comprising: a provisioning controller configured to receive an identifier for a set of at least one access point, at an access point of the set, wherein each access point of the set is configured to provide at least one service only for a set of at least one access terminal, and wherein the identifier uniquely identifies the at least one access point within an operator network; and a communication controller configured to transmit the identifier over the air.
ES 2 608 454 T3
40. The apparatus of Example 39, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
41. The apparatus of example 40, wherein the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers.
42. The apparatus of Example 40, in which the identifier is text-based.
43. A computer program product, comprising: a computer-readable medium comprising codes to make a computer: receives an identifier for a set of at least one access point in an access point of the set, wherein each access point of the set is configured to provide at least one service only for a set of at least one access terminal, and wherein the identifier uniquely identifies at least one access point within an operator network; and broadcast the identifier over the air.
44. The computer program product of Example 43, wherein: the identifier comprises a network identifier; and the network comprises a cellular operator domain.
Four. Five. A communication method, comprising: determining access terminal identifiers of a set of access terminals; and sending the identifiers to at least one access point that is configured to provide at least one service only for the set of access terminals.
46. The procedure of Example 45, in which the identifiers comprise permanent identifiers for the access terminals.
47. The procedure of Example 45, in which the identifiers comprise temporary identifiers for the access terminals.
48. The procedure of example 45, in which identifiers are sent in response to a request from an access point of the at least one access point.
49. The procedure of example 45, in which the determination comprises receiving the identifiers from a server of the Network that allows a user to specify access terminals that are allowed to receive at least one service from the at least one access point .
fifty. The procedure of Example 45, in which the set of access terminals are associated with a common closed group of subscribers.
51. The procedure of example 45, in which each access point of the at least one access point is restricted to not providing, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service.
52. An apparatus for communication, comprising: means for determining the access terminal identifiers of a set of access terminals; and means for sending the identifiers to at least one access point that is configured to provide at least one service only to the set of access terminals.
53. The apparatus of Example 52, in which the identifiers comprise permanent identifiers for the access terminals.
54. The apparatus of Example 52, in which the identifiers comprise temporary identifiers for the access terminals.
55. Example apparatus 52, wherein identifiers are sent in response to a request from an access point of the at least one access point.
56. The apparatus of example 52, in which the determination comprises receiving the identifiers from a server of the Network that allows a user to specify access terminals that are allowed to receive the at least one service from the at least one point of access. access.
57. The apparatus of Example 52, in which the set of access terminals is associated with a common closed group of subscribers.
58. The apparatus of example 52, in which each access point of the at least one access point is restricted not to provide, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration and service.
ES 2 608 454 T3
59. An apparatus for communication, comprising: a provisioning controller configured to determine the access terminal identifiers of a set of access terminals; and a communication controller configured to send the identifiers to at least one access point that is configured to provide at least one service only to the set of access terminals.
60. The apparatus of example 59, wherein identifiers are sent in response to a request from an access point of the at least one access point.
61. The apparatus of example 59, in which the determination comprises the receipt of identifiers from a network server that allows a user to specify access terminals that are allowed to receive the at least one service from the at least one point of access. access.
62. The apparatus of example 59, in which the set of access terminals is associated with a common closed group of subscribers.
63. A computer program product, comprising: a computer-readable medium comprising codes for causing a computer to: determine the access terminal identifiers of a set of access terminals; and send the identifiers to at least one access point that is configured to provide at least one service only to the set of access terminals.
64. The computer program product of Example 63, in which the determination comprises receiving the identifiers from a server on the Network that allows a user to specify access terminals that are allowed to receive the at least one service from the to minus one access point.
Contents17
22 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22
105 members in 19 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 978363P | United States of America | – | |
| 97836307 | United States of America | P | |
| 25686P | United States of America | – | |
| 2568608 | United States of America | P | |
| 61537P | United States of America | – | |
| 6153708 | United States of America | P | |
| 246388 | United States of America | – | |
| 24638808 | United States of America | A |
Members105
| Document | Office | Kind | |
|---|---|---|---|
| US2009093232A1 | United States of America | A1 | |
| US2009094351A1 | United States of America | A1 | |
| US2009094680A1 | United States of America | A1 | |
| AU2008311002A1 | Australia | A1 | |
| AU2008311003A1 | Australia | A1 | |
| AU2008311004A1 | Australia | A1 | |
| CA2701906A1 | Canada | A1 | |
| CA2701924A1 | Canada | A1 | |
| CA2701961A1 | Canada | A1 | |
| CA2881157A1 | Canada | A1 | |
| WO2009048887A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009048888A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048889A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048888A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200932007A | Taiwan Province of China | A | |
| TW200932008A | Taiwan Province of China | A | |
| TW200935930A | Taiwan Province of China | A | |
| WO2009048889A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2198585A2 | European Patent Office (EPO) | A2 | |
| EP2198586A1 | European Patent Office (EPO) | A1 | |
| EP2198653A2 | European Patent Office (EPO) | A2 | |
| MX2010003753A | Mexico | A | |
| MX2010003754A | Mexico | A | |
| KR20100075627A | Republic of Korea | A | |
| KR20100075628A | Republic of Korea | A | |
| MX2010003752A | Mexico | A | |
| KR20100085095A | Republic of Korea | A | |
| CN101889419A | China | A | |
| CN101889420A | China | A | |
| CN101889464A | China | A | |
| IL204864D0 | Israel | D0 | |
| IL204870D0 | Israel | D0 | |
| IL204871D0 | Israel | D0 | |
| JP2010541514A | Japan | A | |
| JP2010541515A | Japan | A | |
| EP2273755A1 | European Patent Office (EPO) | A1 | |
| EP2273824A2 | European Patent Office (EPO) | A2 | |
| JP2011501917A | Japan | A | |
| RU2010118312A | Russian Federation | A | |
| RU2010118488A | Russian Federation | A | |
| RU2010118515A | Russian Federation | A | |
| AU2008311004B2 | Australia | B2 | |
| UA97019C2 | Ukraine | C2 | |
| HK1150482A1 | Hong Kong, China | A1 | |
| KR20120002611A | Republic of Korea | A | |
| KR20120003957A | Republic of Korea | A | |
| KR20120004534A | Republic of Korea | A | |
| UA97552C2 | Ukraine | C2 | |
| RU2459374C2 | Russian Federation | C2 | |
| AU2012247065A1 | Australia | A1 | |
| SG185280A1 | Singapore | A1 | |
| SG185282A1 | Singapore | A1 | |
| KR101216086B1 | Republic of Korea | B1 | |
| AU2008311003B2 | Australia | B2 | |
| KR20130008627A | Republic of Korea | A | |
| KR20130016405A | Republic of Korea | A | |
| RU2475991C2 | Russian Federation | C2 | |
| TWI391009B | Taiwan Province of China | B | |
| UA101337C2 | Ukraine | C2 | |
| KR101261347B1 | Republic of Korea | B1 | |
| RU2488238C2 | Russian Federation | C2 | |
| CN101889420B | China | B | |
| KR101290186B1 | Republic of Korea | B1 | |
| JP5248617B2 | Japan | B2 | |
| JP2013153485A | Japan | A | |
| EP2273824A3 | European Patent Office (EPO) | A3 | |
| JP5290303B2 | Japan | B2 | |
| KR101327456B1 | Republic of Korea | B1 | |
| TWI415492B | Taiwan Province of China | B | |
| JP2014014122A | Japan | A | |
| KR101385612B1 | Republic of Korea | B1 | |
| KR101410371B1 | Republic of Korea | B1 | |
| MY152239A | Malaysia | A | |
| TWI454110B | Taiwan Province of China | B | |
| JP5623283B2 | Japan | B2 | |
| BRPI0818612A2 | Brazil | A2 | |
| AU2012247065B2 | Australia | B2 | |
| BRPI0818609A2 | Brazil | A2 | |
| BRPI0818611A2 | Brazil | A2 | |
| US9055511B2 | United States of America | B2 | |
| IL204871A | Israel | A | |
| US9167505B2 | United States of America | B2 | |
| IL204864A | Israel | A | |
| EP2273755B1 | European Patent Office (EPO) | B1 | |
| CA2701906C | Canada | C | |
| ES2608454T3This record | Spain | T3 | |
| EP2198585B1 | European Patent Office (EPO) | B1 | |
| HUE029844T2 | Hungary | T2 | |
| CN107027119A | China | A | |
| ES2633107T3 | Spain | T3 | |
| CN107196923A | China | A | |
| US9775096B2 | United States of America | B2 | |
| HUE032328T2 | Hungary | T2 | |
| CA2881157C | Canada | C | |
| CA2701961C | Canada | C | |
| MY164923A | Malaysia | A | |
| CA2701924C | Canada | C | |
| EP2198653B1 | European Patent Office (EPO) | B1 | |
| EP2198586B1 | European Patent Office (EPO) | B1 | |
| EP2273824B1 | European Patent Office (EPO) | B1 |
Numbers
- Publication
- 2608454
- Application
- 10189501
Titles2
- Spanish
- Dotación de nodos de comunicación
- English
- Endowment of communication nodes
Classification
- CPC, 12
- H04L63/104
- H04W12/06
- H04W48/08
- H04W8/26
- H04W12/08
- H04W48/02
- H04W48/10
- H04W48/14
- H04W48/16
- H04W84/045
- H04L63/101
- H04W16/32
- IPC, 8
- H04L29 06
- H04W12 08
- H04W48 08
- H04W8 26
- H04W48 02
- H04W12 06
- H04W48 14
- H04W84 04