Method for controlling access rights in a mobile radio communications system
10 claims: 2 independent, 8 dependent
- 1REVENDICATIONS 1. Procédé pour le contrôle de droits d'accès dans un système de radiocommunications mobiles, procédé comportant des étapes selon lesquelles ;- une entité serveuse de réseau cœur reçoit d'une base de données d'utilisateurs mobiles, différents types de données d'authentification suivant le type de services autorisés pour lesdits utilisateurs, - ladite entité serveuse utilise lesdites données d'authentification pour un contrôle de droits d'accès desdits utilisateurs, suivant le type de services autorisés.
- 2Procédé selon la revendication 1, dans lequel différents tyes de services incluent des services de deuxième génération et des services de troisième génération.
- 3Procédé selon l'une des revendications 1 ou 2, dans lequel dans le cas de services de deuxième génération, lesdites données d'authentification correspondent à des vecteurs ayant trois composantes.
- 4Procédé selon l'une des revendications 1 ou 2, dans lequel dans le cas de services de troisième génération, lesdites données d'authentification correspondent à des vecteurs ayant cinq composantes.
- 5Procédé selon l'une des revendications 1 à 4, incluant en outre des étapes selon lesquelles :à la suite dudit contrôle de droits d'accès, effectué au cours de la mise en œuvre d'une procédure d'accès à des services non autorisés, ladite entité serveuse de réseau cœur émet une réponse négative, ladite réponse négative déclenche la mise en œuvre d'une procédure d'accès à des services autorisés.
- 6Procédé selon la revendication 5, dans lequel ladite procédure d'accès correspond à une procédure de mise à jour de localisation et ladite réponse négative correspond à un rejet de mise à jour de localisation incluant une cause de rejet appropriée.
- 7Procédé selon l'une des revendications 1 à 6, dans lequel ladite entité serveuse de réseau cœur reçoit lesdites données d'authentification dans le cadre d'une procédure de mise à jour de localisation.
- 8Entité serveuse de réseau coeur pour système de radiocommunications mobiles, ladite entité comportant des moyens pour mettre en œuvre un procédé selon l'une des revendfications 1 à 7. 105450/MA/MND L:\Salle\F105450\PREMDEP\FIT\proietbr.doc
- 9Entité selon Ια revendication 8, correspondant, dans le cas de domaine circuit, à une entité de type MSC/VLR.
- 10Entité selon la revendication 8, correspondant, dans le cas de domaine paquet, à une entité de type SGSN. 105450/MA/MND L:\Solle\Fl 05450\PREMDEP\FIT\proietbr.doc
Independent claims10
87 paragraphs in 11 sections, as filed
i
PROCEDURE FOR THE CONTROL OF ACCESS RIGHTS IN A MOBILE RADIOCOMMUNICATIONS SYSTEM
The present invention relates generally to mobile radio communication systems.
In general, mobile radiocommunication systems are subject to standardization, and for more information, reference can be made to the corresponding standards, published by the corresponding standardization bodies.
The general architecture of such a system is briefly recalled in relation to FIG. 1. Such a system comprises a mobile radio communications network 1 communicating with mobile terminals 2 and with external networks (not specifically illustrated). The network 1 itself comprises a radio access network 3 (or RAN, for “Radio Access Network”) responsible mainly for the transmission and management of radio resources on the radio interface between the network and the mobile terminals, and a core network 4 (or CN, for “Core Network”) responsible mainly for routing and managing communications.
Developments in needs and in technology generally lead to a distinction between different types of systems, in particular second generation systems and third generation systems.
A typical example of a second generation system is GSM (“Global System for Mobile communication”). Initially, GSM was primarily intended to provide circuit-type services. Packet-type services were then introduced, thanks to the GPRS (“General packet Radio Service”) functionality.
In a system such as GSM for example, the mobile terminal is called MS (“Mobile Station”), the radio access network (or RAN) is made up of subsets called BSS (“Base Station Subsystem”), and the network core (or CN) comprises in particular, for the domain linked to circuit switching (or “CS Domain” in English), network elements of the 2G-MSC type (where 2G is used for “2<sup>nd</sup> Generation "and MSC is used for" Mobile Switching Center ") and, for the domain related to packet switching (or" PS Domain "in English), network elements of type 2G-SGSN (where 2G is used for" 2<sup>nd</sup> Generation ”and SGSN is used for“ Serving GPRS Support Node ”).
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ proietbr.doc
A typical example of a third generation system is UMTS (“Universal Mobile Telecommunication System”).
In a system such as UMTS for example, the mobile terminal is called UE (“User Equipment”), the radio access network (or RAN) is called UTRAN (“UMTS Terrestrial Radio Access Network”), and the network core (or CN) comprises in particular, for the domain linked to circuit switching (or “CS Domain” in English), network elements of the 3G-MSC type (where 3G is used for “3<sup>rd </sup>Generation "and MSC is used for" Mobile Switching Center ") and, for the domain related to packet switching (or" CS Domain "in English), network elements of the 3G-SGSN type (where 3G is used for" 3<sup>rd</sup> Generation ”and SGSN is used for“ Serving GPRS Support Node ”).
Both in second generation systems (such as GSM for example) and in third generation systems (such as UMTS for example), the core network also comprises registers or databases of mobile users, such as in particular HLR (“Home Location Register”) and VLR (“Visitor Location Register”), these registers or databases containing subscription data and user location data. For the circuit domain, the VLR is generally associated with the MSC, hence the use of the term MSC / VLR. For the packet domain, the VLR is usually integrated with the SGSN.
Both in second generation systems (such as GSM for example) and in third generation systems (such as UMTS for example), a mobile terminal is also associated with a subscriber identification module, also called a card. SIM (“Subscriber Identification Module”) in the case of GSM for example, or USIM (“Subscriber Identification Module”) in the case of UMTS for example.
In general, these systems have a cellular architecture, and mechanisms are provided to permanently choose a better server cell.
Furthermore, in order to extend the geographical coverage of these systems and / or the services offered, a plurality of networks or PLMNs is generally provided, generally associated with different operators. Mechanisms are also provided for permanently choosing a better server network, if roaming agreements are foreseen between the operators concerned. We usually use the term nominal network or HPLMN (for "Home
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ pro<sub>]</sub>etbrdoc
PLMN ”) to designate the network with which a user has a subscription relationship, and visited network or VPLMN (for“ Visited PLMN ”) to designate a network other than the HPLMN, under whose coverage this user is located.
In addition, the cells of a given network are generally grouped together by geographic areas, for the purpose of user mobility management and access rights control. These geographic areas are generally called location areas (or LA, for “Location Area” in the case of circuit domain) or routing areas (or RA, for “Routing Area” in the case of packet domain).
In what follows, we will consider, by way of example, the case of the circuit domain, and the cell selection or re-selection mechanisms implemented in standby mode (or “idle mode”).
A mobile terminal is able to recognize, from the information broadcast in each cell, whether a new cell re-selected by the mobile terminal belongs to the same location area as its current server cell. If so, this new cell becomes the new server cell. Otherwise, the terminal notifies the network beforehand, by means of a so-called location update procedure, in order to have the user's right to access the new cell checked.
As part of this location update procedure, the mobile terminal transmits to the network a so-called location update request message (or “Location Area Updating Request”).
In the case of a positive response from the network, the message returned by the network to the mobile terminal is a so-called location update acceptance message (or “Location Area Updating Accept”). The user is then registered in the new one. location zone, and the re-selected cell becomes the new server cell.
In the case of a negative response from the network, the message returned by the network to the mobile terminal is a so-called location update rejection message (or “Location Area Updating Reject”) which indicates the cause of the rejection.
Likewise, a registration procedure is provided for during the initial selection of a server cell, when the terminal is powered on.
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ projectbr.doc
Access rights can therefore be checked, in particular during a registration or location update procedure. Procedures or protocols are provided for this purpose, involving, in particular:
- signaling exchanges between the terminal and a core network server entity (such as in particular an MSC / VLR type entity for the circuit domain),
- signaling exchanges between said core network server entity, and a database of mobile users, such as HLR (“Home Location Register”).
In addition, at least in their initial phase of deployment, third generation networks will supplement existing second generation infrastructures. In other words, the same system can then include a second generation radio access network and a third generation radio access network with overlapping of the second generation radio coverage by the third generation radio coverage. This allows in particular, for services supported jointly by these two generations, such as in particular telephony type services, continuity of service, by benefiting from the existing coverage provided by a second generation network.
However, in this context, new problems may arise, which can be illustrated by means of the following example.
As part of the functionality known as SIM roaming (or "SIM roaming") it is possible that a user who has taken out a subscription only for second generation services (for example, in what follows, GSM) inserts his card. SIM in a third generation terminal (for example, in the following, UMTS) and attempts to access a PLMN (which can either be its HPLMN or a VPLMN with which the HPLMN has roaming agreements) through the radio access network (UTRAN in this example) of that PLMN. However, it is possible that the operator wishes to reserve access to this PLMN via the UTRAN only to users who have taken out a subscription for UMTS. A problem to be solved is then to prohibit a user who has taken out a subscription only for GSM from registering in a PLMN via the UTRAN, while leaving him the possibility of registering in this PLMN via the network of GSM radio access. It should be noted that this problem arises more
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ projetbr.doc especially in the case where the same PLMN code is used for both GSM and UMTS.
FIG. 2 thus illustrates by way of example the case of the location update procedure in the case where a third generation mobile terminal (denoted UE) associated with a second generation SIM card (denoted 2G-SIM) attempts to '' access an HPLMN via a third generation radio access network (denoted UMTS RAN). This PLMN can be either an HPLMN or a VPLMN. These two possibilities have been illustrated by means of the letters A and B in FIG. 2, the elements of the PLMN considered being in this case denoted UMTS RAN-A and 3G MSC / VLR-A, and the HLR being denoted HLR AB.
By way of example, FIG. 2 corresponds to the case of configuration of PLMN where MSC / VLR dedicated to UMTS (denoted 3G MSC / VLR) are provided, in addition to MSC / VLR dedicated to GSM (denoted 2G MSC / VLR).
Figure 3 is similar to Figure 2 (the same references being used in these two figures) and differs only by the fact that it corresponds to the configuration case of PLMN where the same MSC / VLR (denoted 2G / 3G MSC / VLR) jointly supports GSM and UMTS.
The location update procedure illustrated for example in FIG. 2 includes the following steps.
In a step 1, the terminal UE transmits a location update request to a 3G MSC / VLR via the UMTS RAN. By way of example, we consider the case where the location update involves a change of server MSC / VLR, and where the new MSC / VLR must therefore first interrogate the HLR for access rights control.
On receipt of this location update request, the 3G MSC / VLR does not know whether it is a GSM or UMTS subscriber, and, in a step 2, therefore transmits a corresponding request to the HLR.
In a step 3, a procedure (not recalled in detail) is implemented, by which the new MSC obtains subscription data from the HLR, to be stored in the associated VLR.
As indicated above, a problem to be solved is then to prohibit a user who has taken out a subscription only for GSM from registering in a PLMN via the UTRAN. In other words, a problem to be solved is to find a way to allow the 3G MSC / VLR to detect if the considered user is
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ proietbr.doc a GSM subscriber or a UMTS subscriber. Indeed, if the 3G MSC / VLR cannot detect whether the user in question is a GSM subscriber or a UMTS subscriber, in a step 5 it transmits to the UE a location update acceptance message (in assuming, moreover, that the subscription taken out by the user does not include other restrictions, such as for example geographic restrictions, prohibiting access to this new location area).
According to the current state of the 3GPP (“3rd Generation Partnership Project”) standard, the subscription data transferred by the HLR to the 3G MSC / VLR does not include an indication allowing the latter to detect whether the user is a GSM subscriber or UMTS subscriber.
To allow the 3G MSC / VLR to detect whether the user is a GSM subscriber or a UMTS subscriber, it could be envisaged, as described for example in patent application WO 02/091784, that the HLR transmits to the 3G MSC / VLR subscription data including a list of authorized services (such as in particular GSM and UMTS services) for the user in question.
However, such a solution is not optimal, in particular because it increases the quantity of signaling exchanged between HLR and 3G MSC / VLR, and in addition, as observed by the applicant, it does not make optimal use of the signals. existing procedures.
The object of the present invention is in particular to avoid such drawbacks. More generally, one of the aims of the present invention is to optimize the access rights control procedures, in particular in systems in which different types of services can be offered, such as in particular second generation services (such as in particular GSM type services) and third generation services (such as in particular UMTS type services).
One of the objects of the present invention is a method for controlling access rights in a mobile radiocommunications system, a method comprising steps according to which:
a core network server entity receives, from a database of mobile users, different types of authentication data depending on the type of services authorized for said users,
said server entity uses said authentication data for controlling the access rights of said users, depending on the type of authorized services.
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ projectbr.doc
Another object of the present invention is a core network server entity for a mobile radio communications system, comprising means for implementing such a method.
Other objects and characteristics of the present invention will become apparent on reading the following description of an exemplary embodiment, given in relation to the accompanying drawings in which:
FIG. 1 recalls the general architecture of a mobile radiocommunications system, FIGS. 2 and 3 are intended to illustrate a problem solved by the present invention, FIGS. 4 and 5 are intended to illustrate an example of a solution according to the present invention .
In the example illustrated in FIGS. 2 and 3, the present invention suggests, in particular, in order to solve the problem explained above, that a server entity of a core network (such as for example a server entity of the MSC / VLR type for in the case of the circuit domain) uses, to detect whether the user is a GSM subscriber or a UMTS subscriber, authentication data, these data being also called authentication vectors and making it possible to implement an authentication procedure.
For example, in the case of a location update procedure as recalled in the example illustrated in FIGS. 2 and 3, said authentication data (or vectors) are received from the HLR, in a procedure (not recalled in detail) implemented in a step marked 4.
The present invention suggests taking advantage of the fact that the authentication data (or vectors) are of different types depending on the type of authorized services, in this case depending on whether the authorized services correspond to second generation services (for example GSM ) or third generation services (eg UMTS), as will now be recalled. Authentication data is requested by the MSC / VLR and provided by the HLR before other subscription data.
It is recalled that the authentication procedure is a procedure allowing the network to verify, in a secure manner, the identity of a user.
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ projectbr.doc
The main steps of this authentication procedure are recalled in what follows, first of all for a second generation system (for example GSM).
The authentication procedure comprises a parameter calculation called SRES (for “Signed RESult”), using a calculation algorithm with as input parameters of this algorithm a secret key K associated with the user and a random value of a parameter called RAND ("RANDom number").
Such a calculation is carried out on the one hand in the network (in an AuC authentication center (“Authentication Center” associated with the HLR), and on the other hand in the terminal (in the SIM card), using the same algorithm. calculation and the same input parameters of this algorithm (the secret key K being known both in the network and in the terminal, and the value of the RAND parameter being communicated by the network to the terminal).
The result of the calculation carried out in the terminal is communicated to the network which checks whether it corresponds to the calculation which it itself carried out. If so, the authentication procedure ends positively.
In a third generation system (UMTS for example) the authentication procedure differs mainly from that thus recalled for a second generation system (for example GSM) by the following points:
- In addition to the calculation of the SRES parameter in the manner recalled above, a parameter calculation called MAC (“Message Authentication Code”) is also carried out, implementing a calculation algorithm with the RAND parameters as input parameters of this algorithm and K mentioned above, as well as the given components of a parameter called AUTN (“AUthentication TokeN”). This calculation of the MAC parameter is carried out on the one hand in the network and on the other hand in the terminal, using the same calculation algorithm and the same input parameters of this algorithm, the AUTN parameter also being communicated to the terminal through the network.
- In addition to the fact that the network checks whether the SRES parameter that it has calculated corresponds to the SRES parameter received from the terminal, so as to enable it to verify, in a secure manner, the identity of the terminal, the terminal also checks whether the parameter MAC it calculated corresponds to the MAC parameter received from the network
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ projectbr.doc server, so as to allow it to verify, in a secure manner, the identity of the server network.
In general, the verifications carried out in the network for the implementation of the authentication procedure are carried out in a core network server entity, such as for example MSC / VLR for the circuit domain case, on the basis authentication data communicated to it by the HLR / AuC. These authentication data (or vectors) are generally communicated by the HLR / AuC to the MSC / VLR during a location update procedure involving a change of server MSC / VLR. In addition, they are generally communicated in sufficient number to avoid such a transfer of authentication data (or vectors) each time the MSC / VLR needs to implement the authentication procedure.
In the case of authorized second generation services (eg GSM), an authentication vector (also called a “triplet”) comprises three components, namely (RAND, SRES, CK), the RAND and SRES parameters being those recalled below. above, and the CK parameter also corresponding to an encryption key (or “ciphering key”).
In the case of authorized third-generation services (for example UMTS), an authentication vector (also called a “quintet”) comprises five components, namely (RAND, AUTN, SRES, CK, IK), the parameters RAND, AUTN, SRES, CK being those recalled above, and the IK parameter also corresponding to an integrity key.
The present invention therefore suggests taking advantage of the fact that the authentication data (or vectors) are of different types depending on the type of authorized services, namely second generation services (for example GSM) or third generation services ( eg UMTS).
FIGS. 4 and 5, corresponding respectively to the examples illustrated in FIGS. 2 and 3, illustrate an example of a solution according to the present invention.
The steps denoted 1 ', 2', 3 ', 4' illustrated in Figures 4 and 5 can be similar to steps 1, 2, 3, 4 illustrated in Figures 2 and 3.
In the examples illustrated in Figures 4 and 5, the 3G MSC / VLR detects, on the basis of the authentication data (or vectors) received from the HLR, whether the user is a GSM subscriber or a UMTS subscriber.
105450 / MA / MND
L: \ Solle \ F105450 \ PREMDEP \ FIT \ projectbr.doc ίο
If the authentication vectors correspond to triplets, the user is considered to be a GSM subscriber and the 3G MSC / VLR then sends the UE, in a step 5 ′, a location update rejection message.
In addition, if the terminal is a dual-mode terminal, denoted UE / MS, the cause of rejection of the location update via the UMTS RAN is such that a location update can then be attempted via the GSM RAN, as illustrated by the following steps:
In a step 6 ′, the UE / MS terminal transmits a location update request to a 2G MSC / VLR via the GSM access network.
On receipt of this location update request, the 2G MSC / VLR, in a step 7 ′, transmits a corresponding request to the HLR.
In a step 8 ′, a procedure is implemented, by which the new MSC obtains subscription data from the HLR, to be stored in the VLR which is associated with it.
In a step 9 ′, a procedure is implemented, by which the new MSC obtains authentication data from the HLR allowing it to implement an authentication procedure.
In a step 10 ′, the 2G MSC / VLR transmits to the UE / MS a location update acceptance message (assuming, moreover, that the subscription taken out by the user does not include other restrictions. , such as for example geographical restrictions, prohibiting access to this new location area).
One of the objects of the present invention is thus a method for controlling access rights in a mobile radiocommunications system, a method comprising steps according to which:
a core network server entity receives, from a database of mobile users, different types of authentication data depending on the type of services authorized for said users,
said server entity uses said authentication data for controlling the access rights of said users, depending on the type of authorized services.
Another object of the present invention is a server entity of the core network (such as for example a server entity of the MSC / VLR type for the case of the
105450 / MA / MND
L: \ Room \ F 105450 \ PREMDEP \ FIT \ projetbr.doc circuit domain, or SGSN for the case of the packet domain), comprising means for implementing such a method.
These different means can operate according to the method described above; since their particular embodiment does not present any particular difficulty for those skilled in the art, such means do not need to be described here in more detail than by their function.
105450 / MA / MND
L: \ Room \ F105450 \ PREMDEP \ FIT \ proietbr.doc
Contents11
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
7 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0450372 | France | A | |
| 0450372 | France | A | |
| FR20040050372 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| CN1662094A | China | A | |
| FR2867006A1 | France | A1 | |
| US2005197100A1 | United States of America | A1 | |
| EP1578164A1 | European Patent Office (EPO) | A1 | |
| FR2867006B1This record | France | B1 | |
| US8559920B2 | United States of America | B2 | |
| EP1578164B1 | European Patent Office (EPO) | B1 |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of lapseLapsedST | ST | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Change of addressCA | CA | |
| Change of addressCA | CA | |
| Lien (pledge) cancelledRG | RG | |
| Lien (pledge) constitutedGC | GC | |
| Change of name or company nameCD | CD |
Numbers
- Publication
- 2867006
- Publication, DOCDB
- 2867006
- Publication, EPODOC
- FR2867006
- Application
- 450372
- Application, DOCDB
- 0450372
- Application, EPODOC
- FR20040050372
Titles2
- French
- PROCEDE POUR LE CONTROLE DE DROITS D'ACCES DANS UN SYSTEME DE RADIOCOMMUNICATIONS MOBILES
- English
- METHOD FOR CONTROLLING ACCESS RIGHTS IN A MOBILE RADIO COMMUNICATION SYSTEM
Classification
- CPC, 5
- H04W12/06
- H04L63/10
- H04W8/02
- H04W12/08
- H04W88/02
- IPC, 2
- H04W12 06
- H04W88 02
