Telecommunications network and method for time-based network access
Abstract
A telecommunications network (1) configured to provide access to a plurality of terminals (AD) where the terminals are arranged to execute machine-to-machine applications that do not require immediate data transfer, each terminal (AD) comprising a unique identifier to access said telecommunications network, wherein said telecommunications network (1) comprises: - a register (6) configured to store said unique identifier of at least one terminal (AD) in combination with at least one access authorization time interval, during which access is allowed for said terminal (AD); - an access request receiver (20) configured to receive an access request and to receive or determine said unique identifier to access said telecommunications network from said terminal; - an access module (21) configured to deny access to said terminal if said access request is received outside of said access authorization time interval; and where the access authorization time interval for the terminals (AD) is a predefined time interval, an off peak interval or a low network load interval, or where the authorization time interval access is a variable time interval xy, which is programmed as a function of the network load experienced by, or predicted for, the telecommunications network (1).

Term
2.4 yearsto projected expiry
Projected expiry 19 February 2029, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
34 claims: 14 independent, 20 dependent
- 1ES 2 811 509 T3 REIVINDICACIONES 1. Una red de telecomunicaciones (1) configurada para proporcionar acceso a una pluralidad de terminales (A-D) en donde los terminales están dispuestos para ejecutar aplicaciones de máquina a máquina que no requieren la transferencia inmediata de datos, comprendiendo cada terminal (A-D) un identificador único para acceder a dicha red de telecomunicaciones, en donde dicha red de telecomunicaciones (1) comprende:- un registro (6) configurado para almacenar dicho identificador único de al menos un terminal (A-D) en combinación con al menos un intervalo de tiempo de autorización de acceso, en el curso del cual está permitido el acceso para dicho terminal (A-D);- un receptor de demanda de acceso (20) configurado para recibir una demanda de acceso y para recibir o determinar dicho identificador único para acceder a dicha red de telecomunicaciones a partir de dicho terminal;- un módulo de acceso (21) configurado para denegar el acceso a dicho terminal si dicha demanda de acceso se recibe fuera de dicho intervalo de tiempo de autorización de acceso;y en donde el intervalo de tiempo de autorización de acceso para los terminales (A-D) es un intervalo de tiempo predefinido, un intervalo fuera de la punta de carga o un intervalo de carga de red baja, o en donde el intervalo de tiempo de autorización de acceso es un intervalo de tiempo variable x-y, que se programa en función de la carga de red experimentada por, o prevista para, la red de telecomunicaciones (1).
- 2La red de telecomunicaciones según la reivindicación 1, en donde el intervalo de tiempo de autorización de acceso otorgado a los terminales (A-D) está dentro de un período de tiempo en donde la carga de red cae por debajo o está previsto que caiga por debajo de un umbral particular o está dentro de los intervalos de tiempo fuera de la punta de carga o que está prevista una carga de red baja.
- 3La red de telecomunicaciones según la reivindicación 1, en donde dicho intervalo de tiempo de autorización de acceso es un intervalo de tiempo dinámico o un intervalo de tiempo implícito.
- 4La red de telecomunicaciones según la reivindicación 1, en donde dicha red de telecomunicaciones (1) comprende un monitor de carga de red configurado para obtener y para supervisar la carga de red de dicha red de telecomunicaciones (1) y en donde dicha red de telecomunicaciones está configurada para adaptar dicho intervalo de tiempo de autorización de acceso en función de dicha carga de red.
- 5La red de telecomunicaciones (1) según la reivindicación 4, en donde la supervisión de la carga de red se basa en la carga de red prevista, utilizando modelos matemáticos y datos históricos.
- 6La red de telecomunicaciones (1) según la reivindicación 4, en donde la carga de red de dicha red de telecomunicaciones (1) se supervisa en tiempo real.
- 7La red de telecomunicaciones (1) según la reivindicación 1, en donde los terminales (A-D) tienen uno o más intervalos de tiempo de autorización de acceso asignados a un terminal particular o grupo de terminales (A-D).
- 8La red de telecomunicaciones según la reivindicación 1, en donde dicha red de telecomunicaciones comprende una red celular (2) y dicho registro (6) es un registro de posición base o un servidor de abonados residenciales de la red de telecomunicaciones celular (2).
- 9La red de telecomunicaciones (1) según una o más de las reivindicaciones anteriores, en donde dicho módulo de acceso (21) está configurado, además, para denegar el acceso sin autenticación de dicho terminal (A-D).
- 10La red de telecomunicaciones según una o más de las reivindicaciones anteriores, que comprende, además, un módulo de autorización (24) configurado para autorizar dichos terminales (A-D) en respuesta a la recepción de dicha demanda de acceso y en donde dicho módulo de acceso (21) está configurado, además, para denegar una conexión de red al recibir una demanda de acceso adicional a partir de dichos terminales (A-D).
- 11La red de telecomunicaciones (1) según una o más de las reivindicaciones anteriores, en donde la red de telecomunicaciones (1) comprende una entidad de controlador de servicio (5), comprendiendo dicha entidad de controlador de servicio (5) dicho receptor de demanda de acceso (20) y dicho módulo de acceso (21) y en donde dicha entidad de controlador de servicio (5) comprende, además, un módulo de recuperación de datos (22) configurado para recuperar dicho intervalo de tiempo de autorización de acceso desde dicho registro (6) en respuesta a la recepción de dicha demanda de acceso y en donde dicho módulo de acceso está configurado para denegar una conexión de red a dicha red de telecomunicaciones o denegar el establecimiento de un contexto de ES 2 811 509 T3 protocolo de datos de paquetes con dicho terminal si dicha demanda de acceso se recibe fuera del intervalo de tiempo de autorización de acceso recuperado.
- 12La red de telecomunicaciones (1) según una o más de las reivindicaciones anteriores, en donde dicha red (1) comprende una entidad de controlador de servicio (5) configurada para transmitir información de denegación de acceso a dicho terminal (A-D) en respuesta a dicho módulo de acceso (21) que deniega el acceso a dicha red de telecomunicaciones (1).
- 13La red de telecomunicaciones (1) según una o más de las reivindicaciones anteriores, en donde dicha red (1) comprende, además, una pasarela (7) a otra red, estando configurada dicha pasarela (7) para permitir una autenticación adicional de dicho terminal (A-D).
- 14Una red de telecomunicaciones (1) configurada para proporcionar acceso a una pluralidad de terminales (A-D) en donde los terminales están dispuestos para ejecutar aplicaciones de máquina a máquina que no requieren la transferencia inmediata de datos, comprendiendo cada terminal (A-D) un identificador único para acceder a dicha red de telecomunicaciones, en donde dicha red de telecomunicaciones (1) comprende:- un registro (6) configurado para almacenar dicho identificador único de al menos un terminal (A-D) en combinación con al menos un intervalo de tiempo de denegación de acceso, en el curso del cual se deniega el acceso para dicho terminal (A-D);- un receptor de demanda de acceso (20) configurado para recibir una demanda de acceso y para recibir o determinar dicho identificador único para acceder a dicha red de telecomunicaciones a partir de dicho terminal;- un módulo de acceso (21) configurado para denegar el acceso a dicho terminal si dicha demanda de acceso se recibe dentro de dicho intervalo de tiempo de denegación de acceso;y en donde - el intervalo de tiempo de denegación de acceso para los terminales (A-D) es un intervalo de tiempo predeterminado, un intervalo de tiempo de pico de carga o un intervalo de carga de red alta, o en donde el intervalo de tiempo de denegación de acceso es un intervalo de tiempo variable x-y, que se programa en función de la carga de red experimentada por, o prevista para, la red de telecomunicaciones (1).
- 15La red de telecomunicaciones según la reivindicación 14, en donde el intervalo de tiempo de denegación de acceso otorgado a los terminales (A-D) está dentro de un período de tiempo en el curso del cual la carga de red es superior, o está prevista que sea superior, a un umbral particular o dentro de intervalos de tiempo de pico de carga o en el curso del cual está prevista una carga de red alta.
- 16La red de telecomunicaciones según la reivindicación 14, en donde dicho intervalo de tiempo de denegación de acceso es un intervalo de tiempo dinámico o un intervalo de tiempo implícito.
- 17Un método informatizado para controlar el acceso a una red de telecomunicaciones (1), estando la red de telecomunicaciones (1) configurada para permitir el acceso a una pluralidad de terminales (A-D) que ejecutan aplicaciones de máquina a máquina que no requieren la transferencia inmediata de datos, comprendiendo cada terminal (A-D) un identificador único para acceder a dicha red de telecomunicaciones (1), comprendiendo la red de telecomunicaciones (1) un registro (6) configurado para almacenar dicho identificador único de al menos un terminal (A-D) en combinación con al menos un intervalo de tiempo de autorización de acceso, comprendiendo el método las etapas de:- recibir una demanda de acceso y dicho identificador único desde dicho terminal (A-D) para acceder a dicha red de telecomunicaciones (1);- acceder a dicho intervalo de tiempo de autorización de acceso utilizando dicho identificador único;- denegar el acceso a dicha red de telecomunicaciones (1) para dicho terminal (A-D) si dicha demanda de acceso se recibe fuera de dicho intervalo de tiempo de autorización de acceso;el método comprende, además, las etapas de: - determinar que el intervalo de tiempo de autorización de acceso es un intervalo de tiempo predefinido, un intervalo de tiempo fuera de la punta de carga o un intervalo de carga de red baja, o en donde el intervalo de tiempo de autorización de acceso es un intervalo de tiempo variable x-y, que se programa en función de la carga de red experimentada por, o prevista para, la red de telecomunicaciones (1). ES 2 811 509 T3
- 18El método según la reivindicación 17, en donde el intervalo de tiempo de autorización de acceso otorgado a los terminales (A-D) está dentro de un período de tiempo en que la carga de red es inferior, o está previsto que sea inferior, a un umbral particular o esté dentro del intervalo de tiempo fuera de la punta de carga o que está prevista una carga de red baja.
- 19El método según la reivindicación 17, que comprende, además, la etapa de supervisar la carga de red de dicha red de telecomunicaciones (1) y adaptar dicho intervalo de tiempo de autorización de acceso en función de dicha carga de red supervisada.
- 20El método según la reivindicación 19, en donde la supervisión de la carga de red se basa en la carga de red prevista, utilizando modelos matemáticos y datos históricos.
- 21El método según la reivindicación 19, en donde la carga de red de dicha red de telecomunicaciones (1) se supervisa en tiempo real.
- 22El método según la reivindicación 19, en donde el intervalo de tiempo de autorización de acceso otorgado a los terminales (A-D) está dentro de un período de tiempo en que la carga de red es inferior, o está previsto que sea inferior, a un umbral particular.
- 23El método según la reivindicación 17, en donde los terminales (A-D) de estas aplicaciones de máquina a máquina tienen uno o más intervalos de tiempo de autorización de acceso asignados a un terminal particular o grupo de terminales (A-D).
- 24El método según la reivindicación 17, en donde dicha red de telecomunicaciones (1) comprende una red celular (2) y dicho registro (6) es un registro de posición base o un servidor de abonados residenciales de la red de telecomunicaciones celular (2).
- 25El método según una o más de las reivindicaciones 17 a 24, en donde dicha etapa de denegar el acceso a dicha red de telecomunicaciones (1) para dicho terminal (A-D) si dicha demanda de acceso se recibe fuera de dicho intervalo de tiempo de autorización de acceso comprende denegar una conexión de red a la red de telecomunicaciones (1).
- 26El método según una o más de las reivindicaciones 17 a 24, que comprende, además, la etapa de denegar el acceso de dicho terminal (A-D) en dicha red de telecomunicaciones (1) sin la autenticación de dicho terminal (A-D).
- 27El método según una o más de las reivindicaciones 17 a 24, que comprende, además, las etapas de:- autenticar dicho terminal (A-D) en dicha red de telecomunicaciones (1) en respuesta a la recepción de dicha demanda de acceso;y - denegar una conexión de red para dicho terminal (A-D) en respuesta a la recepción de una demanda de acceso adicional a partir de dicho terminal (A-D).
- 28El método según la reivindicación 17, que comprende, además, las etapas de:- recibir dicha demanda de acceso a dicha red de telecomunicaciones (1) en una entidad de controlador de servicio (5);- recuperar dicho intervalo de tiempo de autorización de acceso desde dicho registro a dicha entidad de controlador de servicio (5) en respuesta a la recepción de dicha demanda de acceso;- denegar una conexión de red para dicho terminal (A-D) o denegar el establecimiento de un contexto de protocolo de datos de paquetes para dicho terminal (A-D) si dicha demanda de acceso se recibe fuera del intervalo de tiempo de autorización de acceso recuperado.
- 29El método según la reivindicación 17, en donde dicha red (1) comprende, además, una pasarela (7) a una red adicional, estando configurada dicha pasarela (7) para permitir una autenticación adicional de dicho terminal (A-D).
- 30Un método informatizado de controlar el acceso a una red de telecomunicaciones (1), estando la red de telecomunicaciones configurada para permitir el acceso a una pluralidad de terminales que ejecutan aplicaciones de máquina a máquina que no requieren la transferencia inmediata de datos, comprendiendo cada terminal que un identificador único para acceder a dicha red de telecomunicaciones (1), comprendiendo la red de telecomunicaciones un registro (6) configurado para almacenar dicho identificador único de al menos un terminal en combinación con al menos un intervalo de tiempo de denegación de acceso, comprendiendo el método las etapas de:ES 2 811 509 T3 - recibir una demanda de acceso y dicho identificador único desde dicho terminal para acceder a dicha red de telecomunicaciones;- acceder a dicho intervalo de tiempo de denegación de acceso utilizando dicho identificador único;- denegar el acceso a dicha red de telecomunicaciones para dicho terminal si dicha demanda de acceso se recibe dentro de dicho intervalo de tiempo de denegación de acceso;el método comprende, además, las etapas de: - determinar que el intervalo de tiempo de denegación de acceso es un intervalo predefinido, un intervalo de punta de carga o un intervalo de carga de red alta, o en donde el intervalo de tiempo de denegación de acceso es un intervalo de tiempo variable x-y, que se programa en función de la carga de red experimentada por, o prevista para, la red de telecomunicaciones (1).
- 31El método según la reivindicación 30, en donde el intervalo de tiempo de denegación de acceso otorgado a los terminales (A-D) está dentro de un período de tiempo en el curso del cual la carga de red es superior, o está previsto que sea superior, a un umbral particular o esté dentro de intervalos de tiempo de pico de carga o que está prevista una carga de red alta.
- 32Un producto de programa informático para controlar el acceso (21) a una red de telecomunicaciones (1), comprendiendo dicho producto de programa informático partes de código de software configuradas para, cuando se ejecutan en una red de telecomunicaciones (1), ejecutar el método según las reivindicaciones 17 a 29.
- 33Un soporte que contiene el producto de programa informático según la reivindicación 32.
- 34Un terminal (A-D) para su uso en una red de telecomunicaciones (1) que está configurada para proporcionar acceso a una pluralidad de terminales (A-D) en donde los terminales están dispuestos para ejecutar aplicaciones de máquina a máquina que no requieren la transferencia inmediata de datos, comprendiendo cada terminal (A-D) un identificador único para acceder a dicha red de telecomunicaciones, y en donde dicha red de telecomunicaciones (1) comprende:- un registro (6) configurado para almacenar dicho identificador único de al menos un terminal (A-D) en combinación con al menos un intervalo de tiempo de autorización de acceso, en el curso del cual se permite el acceso para dicho terminal (A-D);- un receptor de demanda de acceso (20) configurado para recibir una demanda de acceso y para recibir o determinar dicho identificador único para acceder a dicha red de telecomunicaciones desde dicho terminal;- un módulo de acceso (21) configurado para denegar el acceso a dicho terminal si dicha demanda de acceso se recibe fuera de dicho intervalo de tiempo de autorización de acceso;y en donde el intervalo de tiempo de autorización de acceso para los terminales (A-D) es un intervalo de tiempo predefinido, un intervalo fuera del pico de carga o un intervalo de carga de red baja, o en donde el intervalo de tiempo de autorización de acceso es un intervalo de tiempo variable x-y, que se programa en función de la carga de red experimentada por, o prevista para, la red de telecomunicaciones (1);y que el terminal comprende un receptor de mensajes configurado para recibir un mensaje desde dicha red de telecomunicaciones, comprendiendo dicho mensaje información relacionada con dicho intervalo de tiempo de autorización de acceso, en donde dicho terminal (A-D) comprende, además, un módulo de demanda de acceso configurado para transmitir dicha demanda de acceso a dicha red de telecomunicaciones en conformidad con dicho intervalo de tiempo de autorización de acceso.
Independent claims34
70 paragraphs in 11 sections, as filed
ES 2 811 509 T3
DESCRIPTION
Telecommunication network and time-based network access method
FIELD OF THE INVENTION
The invention relates to the field of telecommunications. In particular, the invention relates to a telecommunications network and to a method for allowing access to said telecommunications network.
BACKGROUND OF THE INVENTION
The last decades have seen an ever-increasing demand for telecommunications network data capacity. Telecommunications service providers have adapted their networks to provide expanded GSM services, such as GPRS and 3G services, and continue to provide new services to meet the demands of their customers.
Telecommunications providers have made attempts to influence the behavior of their customers in order to use network resources effectively. As an example, mobile data subscriptions are currently offered using volume-based billing, possibly in combination with an upper volume limit, forcing customers to consider the amount of data to be transmitted. through a network. However, the control of client behavior and / or terminal data transmission and therefore the use of network resources is still limited.
There is a need in this art for a telecommunications network upgrade and a method for regulating the use of network resources.
From WO 01 / 55861A a method and a system for controlling access to a telecommunications network is known. EP 1681815 discloses a data communication restriction method for flat rate users. The data communication restrictions method comprises the steps of monitoring the data communication status of a flat rate user, and determining whether the demand number or communication quantity during a predetermined period exceeded a predetermined threshold; setting the flat rate user as a restricted object of communication when it is determined that the threshold was exceeded; and transmitting a communication restriction signal including information on the communication restriction period to a mobile terminal of the restricted flat rate user, when the restricted flat rate user requested access again; in the course of which the data communication of the restricted flat rate user mobile terminal is restricted during the communication restriction period.
SUMMARY OF THE INVENTION
A telecommunications network configured to provide communication access for a plurality of terminals is provided. Each terminal comprises a unique identifier to access the telecommunications network. The unique identifier is preferably associated with a subscription of the terminal, eg, the identifier of a SIM (IMSI) that is available in the terminal. The telecommunications network comprises a register, an access request receiver and an access module. The registry is configured to store the unique identifier of at least one terminal in combination with at least one access authorization time interval or its equivalent, during which access is allowed for the terminal. The access request receiver is configured to receive the access request to access the telecommunications network from the terminal. The access request can contain the unique identifier or a temporary identifier. The access module is configured to deny access to the terminal if the access request is received outside the access time interval or its equivalent.
A registry and a service controller entity, for use in such a network, are also offered in this regard.
A computerized method of controlling access to a telecommunications network is also provided. The telecommunications network is configured to allow access for a plurality of terminals, each terminal comprising a unique identifier to access the telecommunications network. The telecommunications network comprises a register configured to store the unique identifier of at least one terminal in combination with at least one access authorization time slot or its equivalent. An access request is received from the terminal to access the telecommunications network. The access request can contain the unique identifier or a temporary identifier. In a further step, the access authorization time interval for the terminal is verified, using the unique identifier. Access to the telecommunications network, for said terminal, is denied if the access request is received outside of said time interval.
A computer program and a support medium for said computer program, comprising parts of program codes configured to execute the method, are also offered in this regard.
Also, a terminal is provided for use in the system and the corresponding method.
ES 2 811 509 T3
It should be noted that an access authorization time slot equivalent includes an access denial time slot that identifies a time slot during which an access request must be denied to access the telecommunications network.
The access demand can be a circuit switched access demand, a packet switched access demand, or a combined demand.
The stages of accessing a telecommunications network are standardized in eg 3 GGP TS 23.060 (Release 7). It should also be noted that access to the telecommunications network can be denied at various stages of access. The first phase of demanding access to the network usually involves a network connection procedure that comprises several stages. In a preferred embodiment, access to the telecommunications network is denied by denying the terminal's connection to the network. Denial, in this phase, provides optimized resource savings.
Another phase of network access involves establishing a PDP context. The establishment of the PDP context can be denied. Although the connection to the preceding network already involved the use of network resources, the prohibition of establishing a PDP context prevents the effective use of the telecommunications network and the consequent savings of resources. It should be noted that the prohibition determined by the operator (ODB) as such for access to a telecommunications network is already described in document 3GGP TS 23.015 V.7.0.0. The possibility of prohibition allows network operators to deny access to particular destinations for some subscribers.
By providing the option of specifying one or more time intervals during which access to the telecommunications network is allowed for a particular terminal or group of terminals, network operator planning and control of the use of the terminals is facilitated. network resources. Denying or blocking access, during intervals of time, can be advantageous in several situations. In particular, some machine-to-machine (M2M) applications do not require immediate data transmission. If these applications are prevented from demanding one or more network resources during, for example, peak load hours, network resources can be saved. Such subscriptions can be offered, for example, at a lower subscription rate.
M2M applications typically involve hundreds or thousands of devices that only rarely require access to a telecommunications network. One example involves the electronic reading of, for example, electricity supply meters in the homes of a large customer base.
There are embodiments that provide a suitable place in the telecommunications network to make the combinations of terminal identifiers and associated time slots available.
There are embodiments that provide a dynamic time slot (and possibly an implicit or virtual time slot) in the course of which access to the telecommunications network is allowed / prohibited. These embodiments contribute to the optimal use of network resources.
There are embodiments that provide improved use of network resources.
There are embodiments that provide the option of informing the terminal of the access authorization time interval. Such information should only be transmitted to the terminal in question. Furthermore, allowing only a single authentication saves network resources and saves energy for the terminals.
There are embodiments that ensure that the decision whether or not to allow access (connection to the network or establishment of the PDP context) to the telecommunications network is incorporated at a low level of the telecommunications network, eg, in the SGSN node, thus reducing the consumption of network resources. Other solutions, such as the implementation of access authorization time rules on a RADIUS server would require various network functions, mobility management and establishment of a Packet Data Protocol (PDP) context, and hence thus, unnecessary consumption of network resources in case it was determined that the terminal accessed the telecommunications network outside the access authorization time interval.
There are embodiments that allow the transmission of information to the terminal. Such information may include information regarding the applicable access authorization time interval. Possibly, the information may include control information to control the operation of the terminal. The control information may, for example, control the terminal to go into operation during a time interval where the network load is expected to be low. An authentication procedure is preferably performed for this terminal.
There are embodiments that provide higher level authentication, eg, at a GGSN node, during the access authorization time interval.
ES 2 811 509 T3
In the following, embodiments of the invention will be described in more detail. It should be noted, however, that these embodiments cannot be construed as limiting the scope of protection for the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS
In the drawings:
Figure 1 represents a schematic illustration of a telecommunications network according to an embodiment of the present invention;
Figure 2 represents an HLR, an SGSN and a GGSN of the telecommunications network represented in Figure 1;
Figures 3A to 3D represent various time diagrams of methods for using the telecommunications system depicted in Figure 1 and
Figure 4 represents a schematic illustration of a terminal for use with the telecommunications network depicted in Figure 1.
DETAILED DESCRIPTION OF THE DRAWINGS
Figure 1 represents a schematic illustration of a packet service telecommunications network 1 in combination with a plurality of terminals AD that can access the telecommunications network 1 for data communication.
The telecommunications network 1 comprises a cellular radio access network 2 containing a base transceiver station 3 and a base station controller 4. The radio access network is connected to a mobile core network containing a serving controller entity 5, a registry 6 and a gateway 7 that provides access to another network 8.
The serving controller entity 5 may be a serving GPRS support node (SGSN) or other entity. The SGSN node 5 controls the connection between the telecommunications network 1 and the terminals AD. It should be noted that the telecommunications network can contain a plurality of SGSN nodes, where each of the SGSNs is usually connected to the base station controllers 3 in such a way that they can provide a packet service for terminals through several stations. base 3.
Register 6 may be a home location register (HLR) or other register (such as a residential subscriber server for IMS).
The gateway 7 may be a GPRS gateway support node (GGSN) for, for example, the Internet network. Other outside networks include a corporate network or other operator network. The GGSN node 7 is connected to the SGSN node 5 through a core network.
The access for the terminals AD to the telecommunications network 1 involves several access phases.
The first phase involves the phase during which a terminal AD makes a connection to the telecommunications network 1. In this phase, various communication stages are performed, including authentication stages, as provided, by way of example, in 3GGP TS 23.060 (Release 7). The authentication steps perform a security function and involve the exchange of an authentication triplet (for GPRS) or a quintet (for UMTS).
At a later stage, a packet data protocol (PDP) context may be established to support traffic flows through the telecommunications network 1. A PDP protocol context typically includes radio access support provided between a terminal A and SGSN node 5 and packet switched data channels or tunnels provided between SGSN node 5 and GGSN node 7. A session between terminal A and another party would then transmit the established PDP context. A PDP context can transmit more than one traffic flow, but all traffic flows within a particular PDP context are treated the same with respect to their transmission over the telecommunications network 1.
In operating conditions, terminal A can indicate after the network connection phase, in a message requesting the activation of the PDP context in the network, an access point name (APN) for the selection of an access point. reference for a specific external network 8. The SGSN node 5 can send a PDP context creation request to the selected GGSN node 7, for example, based on the access point name given by the terminal A or to a GGSN node, by default, known to the SGSN 5. Subsequently, the PDP context is activated by assigning a PDP context data structure in the SGSN 5 that is used by the terminal A and the GGSN 7 that serves the subscriber access point. The data structure contains an IP address of terminal A, the IMSI of the terminal
ES 2 811 509 T3
A and the tunnel IDs at nodes SGSN 5 and GGSN 7. The tunnel ID identifier is a number assigned by the GGSN 7 that identifies data related to a particular PDP context.
Various features can be controlled by the SGSN 5 during a communications session. This control can be based on the information associated with the subscription and stored in the HLR 6. The information can be retrieved from the HLR 6 to the SGSN 5 to allow control at the SGSN level.
In particular, and referring now to Figure 2, the HLR 6 contains a unique identifier associated with the subscription for each terminal AD, eg, the IMSI stored in the SIM of the terminal AD. Each terminal AD has been assigned a time slot during which access to the telecommunications network 1 will be authorized.
In this example, for terminals A and B, access will be authorized between 08:00 and 11:00 in the afternoon. For terminal C, access will be authorized between 00:00 and 05:00 in the morning. These time intervals are typically off-peak intervals for most days of the year. Terminal batches can be defined and assigned to a particular interval of off-peak hours. For terminal D, a variable time interval xy is programmed, depending on the network load experienced by, or predicted for, the telecommunications network 1. If the network load falls below, or is expected to fall below , from a particular threshold, access to terminal D is authorized.
Of course, the time slots can also be related to the time windows during which access to the telecommunications network 1 is denied, eg access denial time slots. Multiple time slots can be assigned to a terminal.
In order to control the use of resources of the telecommunications network 1, the SGSN 5 contains several modules to carry out the operations described below in greater detail. It should be noted that one or more of these modules can be implemented as software modules running on a processor (not shown). The SGSN 5 also contains memory and storage means (not shown) to carry out these operations in a way generally known to those skilled in the art.
The SGSN 5 comprises an access request receiver 20 configured to receive an access request from the terminals AD to access the telecommunications network 1. The access request of a terminal contains the IMSI of the SIM available in this terminal.
The SGSN node 5 has an access module 21 configured to deny access for a terminal to the telecommunications network 1 if the access request is received outside of the access authorization time intervals for that terminal (or within the interval of denial of access). Denial of access can be related to connecting to the network or establishing the context of the PDP protocol.
Furthermore, the SGSN node 5 comprises a data retrieval module 22. The data retrieval module 22 is configured to retrieve data from the HLR 6, in particular, the applicable access authorization time interval associated with the terminals AD from which the access request was received. However, it should be noted that the SGSN 5 itself can be preconfigured with respect to particular terminals and therefore already comprises the access authorization time slots for these terminals. This can be especially advantageous for stationary terminals.
The SGSN node 5 further comprises a PDP context establishment module 23 and an authenticator 24.
The SGSN node 5 may also have a network load monitor 25 configured to monitor the network load of the telecommunications network 1. The network load information can also be obtained from other sources, for example, other SGSNs or nodes. the HLR of the telecommunications network 1. Network monitoring can be real-time and / or based on the predicted network load using mathematical models and historical data to obtain an appropriate load expectation.
The operation of the telecommunications network 1, and in particular the SGSN node 5, will now be described with reference to Figures 3A to 3D.
In Figure 3A, the access request receiver 20 of the SGSN node 5 receives a connection request from the terminal A at 07:00 pm in step 30. In order to process this connection request, the SGSN node You need the IMSI of the SIM available in the terminal. The connection request may contain this IMSI or a P-TMSI assigned to terminal A via an SGSN node. The P-TMSI is used to prevent the transmission of the IMSI over the radio path as far as possible for security reasons. If the P-TMSI provided by terminal A is known at the SGSN node, the SGSN is able to derive the IMSI. Alternatively, for a P-TMSI provided by terminal A that is not known to the (new) SGSN, the IMSI is provided by the old SGSN or the terminal itself upon request of the new SGSN. The IMSI is used by the data retrieval module 22 to retrieve the access authorization time interval (08:00 - 11:00 pm) from the HLR 6 to the SGSN node 5 in step 31.
ES 2 811 509 T3
The access authorization time slot can be communicated from the HLR 6 to the SGSN node 5 in a variety of ways.
The connection request 30 is usually followed by an authentication check, step 31. The access authorization time slot can be transmitted to the SGSN node 5 with the authentication triplet or quintet.
The authentication procedure of the network connection phase is usually followed by a location update procedure. First, an update location request 32 is transmitted from the SGSN node 5 to the HLR 6. The access authorization time slot may also be transmitted to the SGSN node 5 in a post-insert subscriber data message from the HLR. 6 (stage 33). The network connection phase ends with a connection acceptance message to terminal A (step 34).
After the completion of the networking phase (which may comprise additional steps mentioned in the previous paragraphs), a PDP protocol context is established. Terminal A requests the establishment of the PDP protocol context in a PDP protocol context request in wake-up 35.
Regardless of the mode of obtaining the access authorization time interval, the access module of SGSN 5 determines that the access request was received outside the access authorization time interval. Consequently, a PDP context is not established (indicated by the cross in step 36). Terminal A is informed of the denial in step 37.
It should be noted that the authenticator 24 of the SGSN node 5 may or may not have an authenticated terminal A in the above situation. Authentication is required if the connection access time interval is transmitted from HLR 6 to SGSN node 5 in response to update location message 32. However, authentication should not be performed if the access authorization time interval obtained in SGSN 5 with authentication triplet / quintet. An authentication is preferred if the denial message 37 to terminal A contains information regarding the access authorization time interval.
The SGSN node 5 understands or obtains and maintains the data of the failed access request. This can be done, for example, by storing the time interval in combination with the IMSI of terminal A or by a time indicator of terminal A in combination with some indication of time.
Another access request at a time outside the time window of 08:00 - 11:00 pm (stage 38), which contains, again, or is followed by the IMSI of terminal A, can then be denied directly (stage 39) . Again, authentication will not take place.
In Figure 3B, terminal A's network connection is received at 09:00 in the afternoon. Steps 40 to 45 correspond to steps 30 to 35. Since the network connection demand is now within the time slot allotted for access for terminal A, the access module 21 controls the PDP context establishment module. 23 of SGSN node 5 to establish a PDP protocol context with terminal A and to establish a PDP tunnel with GGSN node 7. In particular, step 46 involves a PDP context request creation and step 47 involves a PDP context response creation in a manner known as such. In step 48, terminal A is informed by a PDP context accept activity message. Terminal A can now follow another authentication procedure (step 49) using, for example, a RADIUS server in the other network 8.
The network load monitoring module 25 of the SGSN node 5 can monitor the network load of (or a part of) the telecommunications network 1 or output a predicted network load. The network load can be compared to a load threshold in order to assess the existence of a low network load situation at a particular time or time interval.
In Figure 3C, steps 50 to 53 correspond to steps 30 to 33 depicted in Figure 3A. The authentication of the terminal D is performed and in step 54, the terminal D is informed of a time interval xy during which a low network load is expected. The information includes control data to control the terminal D so that it again accesses the telecommunications network 1 (step 55) in said low network load time interval. A PDP protocol context can be established immediately (steps 56-58) and access to the RADIUS server is allowed.
As indicated above, the denial of access to the telecommunications network 1 is preferably carried out during connection to the network. Figure 3D depicts, at step 60, a network connection message from terminal A containing an IMSI. Next, an authentication procedure is performed (step 61) during which the access authorization time interval is received at the SGSN node 5. The access authorization time interval and the IMSI is stored in the SGSN node 5. Alternatively, the access authorization time interval is obtained in the location update procedure (steps 62 and 63). The network connection is denied in step 64.
As indicated above, the SGSN node 5 can, by itself, comprise preconfigured information regarding the access authorization time interval for terminal A. Alternatively, the SGSN node uses the
ES 2 811 509 T3 authenticator 24 to authenticate terminal A and to provide terminal A with information regarding the access authorization time interval in step 61.
Figure 4 represents a schematic illustration of terminal A. Terminal A comprises a transceiver module 70 for communicating with telecommunications network 1. Furthermore, terminal A has an access demand module 71. The access request module is configured to receive information regarding the access authorization time interval from the telecommunications network 1 through the transceiver module 70 and to transmit an access request to the telecommunications network only at a time within of the access authorization time interval.
It should be noted that the telecommunications network described above and the corresponding system are especially suitable for saving resources. There may be other methods to influence the access behavior of the terminals, but these are considered to waste more resources.
As an example, a network provider may allow access to the network at all times, but charge a high (very high) fee for data sent outside of peak load times. This does not provide any incentive for the user to remove the connection (that is, the PDP protocol context) for the network. It only provides an incentive not to send data during the high cost load rush hour. However, an active PDP protocol context still consumes too many resources in the core and mobile radio network in addition to requiring an IP address. It also requires that the terminal be connected to the network, which means that all kinds of mobility management features must be established. In addition, this solution requires a more complicated billing system that allows you to charge higher rates at certain times.
Another example would include blocking access to the terminal during peak load hours as a rule on a RADIUS server. However, the network resources would already be consumed before access is blocked by the RADIUS server. The terminal is already allowed to connect to the network, which means that the SGSN would have retrieved information from the HLR and is performing mobility management functions. Furthermore, the terminal has been allowed to establish a PDP protocol context. If the RADIUS server denied the request for access to the outside data network, the GGSN node would not accept the PDP context and the tunnel would be operationally removed. However, the connection to the network will continue if no further action has been taken.
Contents11
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
63 members in 11 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 08003753 | European Patent Office (EPO) | A | |
| 08003753 | European Patent Office (EPO) | A | |
| 08003753 | European Patent Office (EPO) | – | |
| 08003753 | – | – | – |
| EP20080003753 | – | – | – |
Members63
| Document | Office | Kind | |
|---|---|---|---|
| EP2096884A1 | European Patent Office (EPO) | A1 | |
| WO2009106265A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20100113583A | Republic of Korea | A | |
| EP2250835A1 | European Patent Office (EPO) | A1 | |
| CN101960886A | China | A | |
| EP2291032A2 | European Patent Office (EPO) | A2 | |
| EP2291033A2 | European Patent Office (EPO) | A2 | |
| EP2291032A3 | European Patent Office (EPO) | A3 | |
| EP2291033A3 | European Patent Office (EPO) | A3 | |
| JP2011514063A | Japan | A | |
| US2011098020A1 | United States of America | A1 | |
| EP2337403A1 | European Patent Office (EPO) | A1 | |
| EP2250835B1 | European Patent Office (EPO) | B1 | |
| AT535116T | Austria | T | |
| ATE535116T2 | Austria | T2 | |
| EP2400734A2 | European Patent Office (EPO) | A2 | |
| DK2250835T3 | Denmark | T3 | |
| EP2400734A3 | European Patent Office (EPO) | A3 | |
| ES2376616T3 | Spain | T3 | |
| PL2250835T3 | Poland | T3 | |
| EP2337403B1 | European Patent Office (EPO) | B1 | |
| KR101231986B1 | Republic of Korea | B1 | |
| CN103068003A | China | A | |
| CN103139696A | China | A | |
| CN103139697A | China | A | |
| CN103139698A | China | A | |
| CN103220672A | China | A | |
| JP5308459B2 | Japan | B2 | |
| US2013279332A1 | United States of America | A1 | |
| US2013281061A1 | United States of America | A1 | |
| JP2013229875A | Japan | A | |
| JP2013229876A | Japan | A | |
| JP2013258704A | Japan | A | |
| US2014287721A1 | United States of America | A1 | |
| CN101960886B | China | B | |
| JP5684323B2 | Japan | B2 | |
| US9014667B2 | United States of America | B2 | |
| JP5841566B2 | Japan | B2 | |
| US9247426B2 | United States of America | B2 | |
| US9253637B2 | United States of America | B2 | |
| EP2250835B2 | European Patent Office (EPO) | B2 | |
| JP2016028515A | Japan | A | |
| JP5926433B2 | Japan | B2 | |
| DK2250835T4 | Denmark | T4 | |
| ES2376616T5 | Spain | T5 | |
| US2016183298A1 | United States of America | A1 | |
| EP2337403B2 | European Patent Office (EPO) | B2 | |
| CN103139697B | China | B | |
| CN103139696B | China | B | |
| US9781743B2 | United States of America | B2 | |
| CN103139698B | China | B | |
| PL2250835T5 | Poland | T5 | |
| US10187904B2 | United States of America | B2 | |
| EP2291033B1 | European Patent Office (EPO) | B1 | |
| EP2400734B1 | European Patent Office (EPO) | B1 | |
| DK2291033T3 | Denmark | T3 | |
| PL2291033T3 | Poland | T3 | |
| ES2811509T3This record | Spain | T3 | |
| EP2291033B2 | European Patent Office (EPO) | B2 | |
| EP2400734B2 | European Patent Office (EPO) | B2 | |
| FI2291033T4 | Finland | T4 | |
| PL2291033T5 | Poland | T5 | |
| ES2811509T5 | Spain | T5 |
Numbers
- Publication
- 2811509
- Publication, DOCDB
- 2811509
- Publication, EPODOC
- ES2811509T
- Application
- 10174609
- Application, DOCDB
- 10174609
- Application, EPODOC
- ES20100174609T
Titles2
- Spanish
- Red de telecomunicaciones y método de acceso a la red basado en el tiempo
- English
- Telecommunication network and time-based network access method
Classification
- CPC, 15
- H04M3/38
- H04W48/02
- H04W74/04
- H04W8/26
- H04W74/00
- H04W4/70
- H04W76/11
- H04W12/06
- H04W12/61
- H04W12/72
- H04W48/08
- H04W4/50
- H04W28/0247
- H04W74/002
- H04W60/00
- IPC, 8
- H04W4 70
- H04M3 38
- H04W76 11
- H04W8 26
- H04W74 00
- H04W12 06
- H04W12 00
- H04W4 50