Broker-based interworking using hierarchical certificates
Abstract
Methods for authentication, authorization and billing (AAA) in the interconnection between at least two networks are provided. These at least two networks are communicable with the broker and include a first network and a second network. The second network receives the broker private key from the broker and the user's device corresponding to the user in the first network to receive the authorization from the first network to the user. The first network-to-user authorization is signed with the first network private key and includes the broker-to-first network authorization and the user public key. The broker-to-first network authorization is signed with the broker's private key and contains the first network public key. Based on each of the broker public key and the first network public key, the second network determined that the broker-to-first network and first network-to-user certificates were genuine. When the session key is sent from the second network to the user's device. The session key is encrypted using the user public key. The session key is used to allow the user's device to access the second network.
Term
Term ended
Projected expiry passed 27 May 2023, 3.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 5 independent, 10 dependent
- 1相互接続機能を有する無線LANにおける無線LANと第2のネットワークとの間の相互接続のための方法であって、前記無線LANおよび前記第2のネットワークがブローカー構成要素と通信可能であり、 前記ブローカーから第1の鍵を受信するステップと、 ユーザの装置から、ブローカーから第2のネットワークへの認可証と第2の鍵を含む第2のネットワークからユーザへの認可証を受信するステップと、 第3の鍵を得るために、前記第1の鍵を用いて前記ブローカーから第2のネットワークへの認可証を認証するステップと、 前記第2の鍵を得るために、前記第3の鍵を用いて前記第2のネットワークからユーザへの認可証を認証するステップと、 セッション鍵を生成し、前記第2の鍵を用いて前記セッション鍵を暗号化し、前記ユーザの装置に前記暗号化されたセッション鍵を送信するステップと、 前記セッション鍵を用いて前記ユーザの装置と通信するステップと、を含む、前記方法。
- 2前記第2のネットワークからユーザへの認可証は、前記ユーザが相互接続サービスに加入しているかどうかを示す前記ユーザの加入レベルを更に含み、前記セッション鍵を送信するステップが、前記加入レベルに応答して行われる、請求項1に記載の方法。
- 3前記第2のネットワークからユーザへの認可証は、前記第2のネットワークからユーザへの認可証の有効期限を更に含み、更に、前記方法が、前記第2のネットワークからユーザへの認可証の期限が終了しているかどうかを判定するために、前記有効期限をチェックするステップを含む、請求項1に記載の方法。
- 4第4鍵を用いて署名され、前記セッション鍵を含む無線LANからユーザへの認可証を生成するステップを更に含み、前記ステップにより、前記ユーザの装置は、前記無線LANを認証することが可能である、請求項1に記載の方法。
- 5相互接続機能を有する無線LANにおける無線LANと第2のネットワークとの間の相互接続のための方法であって、前記無線LANおよび前記第2のネットワークがブローカー構成要素と通信可能であり、 前記ブローカーからブローカー公開鍵を受信するステップと、 ユーザの装置から、第2のネットワーク秘密鍵を用いて署名され、ブローカーから第2のネットワークへの認可証とユーザ公開鍵を含む第2のネットワークからユーザへの認可証を受信するステップとを含み、前記ブローカーから第2のネットワークへの認可証は、ブローカー秘密鍵を用いて署名され、第2のネットワーク公開鍵を含み、 前記ブローカー公開鍵を用いて前記ブローカーから前記第2のネットワークへの認可証を認証し、前記第2のネットワーク公開鍵を得るステップと、 前記第2のネットワーク公開鍵を用いて前記第2のネットワークからユーザへの認可証を認証し、前記ユーザ公開鍵を得るステップと、 セッション鍵を生成し、前記ユーザ公開鍵を用いて前記セッション鍵を暗号化し、前記ユーザの装置に前記暗号化されたセッション鍵を送信するステップと、 前記セッション鍵を用いて前記ユーザの装置と通信するステップと、を含む、前記方法。
- 6前記第2のネットワークからユーザへの認可証は、前記ユーザが相互接続サービスに加入しているかどうかを示す前記ユーザの加入レベルを更に含み、前記セッション鍵を送信するステップが、前記加入レベルに応答して行われる、請求項5に記載の方法。
- 7前記第2のネットワークからユーザへの認可証は、前記第2のネットワークからユーザへの認可証の有効期限を更に含み、更に、前記方法が前記第2のネットワークからユーザへの認可証の期限が終了しているかどうかを判定するために前記有効期限をチェックするステップを含む、請求項5に記載の方法。
- 8前記ユーザの装置に前記無線LANを認証する機能を与えるステップを更に含む、請求項5に記載の方法。
- 9前記ユーザの装置に前記無線LANを認証する機能を与えるステップは、 前記ブローカー秘密鍵を用いて署名され、無線LAN秘密鍵を含むブローカーから無線LANへの認可証を受信するステップと、 無線LAN秘密鍵を用いて署名され、前記暗号化されたセッション鍵を含む無線LANからユーザへの認可証を生成するステップと、 前記無線LANからユーザへの認可証を前記ユーザの装置に送信するステップと、を更に含む、請求項8に記載の方法。
- 10第2のネットワークに加入しているユーザの装置を用いて無線LANとの通信を行うための方法であって、前記第ネットワークが、前記無線LANと相互接続契約をしており、前記無線LANおよび前記第2のネットワークが、ブローカー構成要素と通信可能であり、 第2のネットワークからユーザの装置への認可証を前記第2のネットワークから受信するステップを含み、前記第2のネットワークからユーザの装置への認可証は、第2のネットワーク秘密鍵を用いて署名され、ブローカーからネットワークへの認可証とユーザ公開鍵とを含み、 前記無線LANに対して前記第2のネットワークからユーザの装置への認可証を送信するステップを含み、前記無線LANは、前記ブローカー構成要素から受信したブローカー公開鍵を用いて前記ユーザ公開鍵を得ることが可能であり、 前記無線LANから、前記ユーザの公開鍵を用いて暗号化されたセッション鍵を受信するステップと、 ユーザ秘密鍵を用いて前記セッション鍵を復号化するステップと、 前記セッション鍵を用いて前記無線LANと通信するステップと、を含む、前記方法。
- 11前記第2のネットワークからユーザへの認可証は、前記ユーザが相互接続サービスに加入しているかどうかを示す前記ユーザの加入レベルを更に含む、請求項10に記載の方法。
- 12前記第2のネットワークからユーザへの認可証が、前記第2のネットワークからユーザへの認可証の有効期限を含み、前記有効期限が満了していない場合、前記送信ステップが行われる、請求項10に記載の方法。
- 13前記受信ステップが、前記ブローカー秘密鍵により署名され、前記セッション鍵を含む無線LANからユーザへの認可証を受信するステップを含み、更に、前記第2のネットワークから前記ブローカー公開鍵を受信し、前記ブローカー公開鍵を用いて前記無線LANからユーザへの認可証を認証し、前記セッション鍵を得るステップを含む、請求項10に記載の方法。
- 14相互接続関係を有する複数のネットワークにおいてユーザの認証を行うためのブローカーに基づくシステムであって、 相互接続機能を有する無線LANと、 第2のネットワークと、 前記無線LANおよび前記第2のネットワークと通信可能なブローカー構成要素とを含み、前記ブローカーは、ブローカー公開鍵を前記無線LANに送信する手段と、ブローカー秘密鍵を用いて署名され、第2のネットワーク公開鍵を含むブローカーから第2のネットワークへの認可証を前記第2のネットワークに送信する手段とを含み、 前記第2のネットワークは、ユーザの装置に対し、第2のネットワーク秘密鍵を用いて署名され、前記ブローカーから第2のネットワークへの認可証と前記ユーザ公開鍵とを含む第2のネットワークからユーザへの認可証を送信する手段を含み、 前記無線LANは、前記ブローカーから第2のネットワークへの認可証を認証し、前記第2のネットワーク公開鍵を得る手段と、前記第2のネットワークからユーザへの認可証を認証し、前記ユーザ公開鍵を得る手段と、セッション鍵を生成し、前記ユーザ公開鍵を用いて前記セッション鍵を暗号化する手段とを含む、前記ブローカーに基づくシステム。
- 15前記無線LANが、無線LAN秘密鍵を用いて署名され、前記暗号化されたセッション鍵を含む無線LANからユーザへの認可証を送信する手段を更に含む、請求項14に記載のシステム。
Independent claims15
37 paragraphs, as filed
The present invention generally relates to network connections, more specifically, interconnections based on brokers (brokers) using hierarchical certificates (hierarchical certificates) (brokers). interworking (Interworking) Regarding authentication, authorization, and accounting (AAA).
Generally, for authentication, authorization and billing (AAA), it is necessary to access and use a network such as a mobile phone network or a wireless LAN (WLAN: wireless LAN). When mobile terminals have access mechanisms to multiple networks, it is very important to make authentication, authorization and billing (AAA) interconnections between these networks. However, usually the networks involved do not belong to the same management domain and do not share the same authentication, authorization and billing schemes. Furthermore, it is difficult for a mobile operator to establish a contractual relationship with all wireless LAN providers, and vice versa. In addition, mobile phone users who sign up for the interconnect should not be aware of any third party involved in the interconnect. That is, mobile users need to maintain only a single account, that is, their own mobile account.
There are two forms of interconnection between mobile network and wireless LAN: tight coupling and loose coupling. In the case of loose coupling, the wireless LAN and mobile phone network have independent data paths, but the authentication, authorization and billing (AAA) for wireless LAN users involves the authentication, authorization and billing of the mobile phone network. It is based on the function. However, the mobile phone network authentication, authorization and billing protocols (MAP / SS7) are incompatible with the Internet Protocol (IP) -based wireless protocols used by LAN users.
Involved in mobile network and wireless LAN authentication, authorization and billing to address the issue that networks do not belong to the same management domain and do not share the same authorization, authorization and billing (AAA). Special interconnects and gateways that bridge to the scheme have been proposed. Some of these special features adapt the Home Location Register (HLR) of the mobile network, for many reasons, especially on the part of the mobile operator. Not desirable from a point of view.
All traditional broker models that try to address the problems of establishing contracts between all wireless LAN and mobile network providers have all been authenticated and authorized on the part of the broker in real time to authenticate mobile phone users. And because it requires the deployment of a billing (AAA) engine, a single point of failure is likely to result in a single point of failure. Also, some of these broker models require the mobile phone user to create a separate account for the broker, which is very inconvenient for the user.
Therefore, it is desirable and very useful to obtain a scheme related to authentication, authorization and billing in interconnection that solves the scheme related to authentication, authorization and billing in interconnection by the above-mentioned prior art.
(Outline of the Invention) The above-mentioned problems and other related problems of the prior art are authentication, authorization and billing based on a broker (broker: broker element, broker device, broker) using the hierarchical license of the present invention. Resolved by (AAA).
The present invention is particularly useful, but not particularly limited, in the case of loose coupling in mobile phone data networks and wireless LAN interconnects. By using a broker, the mobile operator does not need to establish a contractual relationship with all wireless LAN providers for interconnection. Therefore, it is more extensible than the conventional approach. Also, by using a hierarchical authorization, the broker does not need to retain the information of the mobile phone user. The mobile phone user simply uses his / her mobile phone account to access the wireless LAN of the contracted mobile phone operator.
According to one aspect of the invention, methods for authentication, authorization and billing (AAA) in the interconnection between at least two networks are provided. These at least two networks are communicable with the broker and include a first network and a second network. The second network receives the broker private key from the broker and receives the authorization from the first network to the user from the user's device corresponding to the user in the first network. The first network-to-user authorization (certificate) is signed with the first network private key and contains the broker-to-first network authorization and user public key. The certificate from the broker to the first network is signed with the broker's private key and contains the first network public key. Based on each of the broker public key and the first network public key, the second network determined that the broker-to-first network and first network-to-user certificates were genuine. When the session key is sent from the second network to the user's device. The session key is encrypted using the user public key. The session key is used to allow the user's device to access the second network.
These aspects, features, and advantages of the present invention, as well as other aspects, features, and advantages, will become apparent by understanding the following detailed description of preferred embodiments with reference to the accompanying drawings.
The present invention relates to authentication, authorization and billing (AAA) based on a broker (broker: broker element, broker device, broker) using a hierarchical certificate. It can be seen that the present invention can be applied to any combination of access networks, but the present invention is particularly applicable to mobile phone networks and wireless LAN interconnects.
It is understood that the present invention can be implemented in various forms of hardware, software, firmware, special purpose processors, or a combination thereof. Preferably, the present invention is realized by combining hardware and software. Further, the software is preferably executed as an application program realized in a specific form in the program storage device. The application program may be uploaded to and run by a computer having the preferred architecture. Preferably, the computer runs on a computer platform with one or more central processing units (CPUs), random access memory (RAM), and input / output (I / O) interfaces. The computer platform may further include an operating system and microinstructions. The various processes and functions described herein may be part of a microinstruction code, part of an application program, or a combination of these. , Is what runs on the operating system. Further, the computer platform may be connected to an additional data storage device, a printing machine, or other peripheral device.
Further, since some of the system components and methods as components illustrated in the accompanying drawings are preferably performed in the form of software, the actual connection between the system components (or processing functional blocks) is described in the present invention. It is understood that it depends on the method of programming of the embodiments of the invention. Based on the contents disclosed in the present specification, a person skilled in the art in the related technical field can carry out with the configuration of the present invention, or can carry out with the same configuration.
FIG. 1 is a block diagram showing a computer system 100 according to a specific embodiment of the present invention to which the present invention can be applied. The computer system 100 is, for example, a necessary communication known in the art for a wireless LAN, a mobile phone network, or a mobile device used to access an access point for realizing the wireless LAN. It is realized by including interface elements and processing elements. In the case of mobile phone user equipment, the computer system 100 may, for example, encode (encode) and decode (encode) the message according to applicable criteria, as well as the wireless interface required to communicate with the required radio access network. Includes processing elements for performing (decryption). The computer processing system 100 includes at least one processor (CPU) 102 operably connected to other components via the system bus 104. Read-only memory (ROM) 106, random access memory (RAM) 108, display adapter 110, I / O adapter 112, user interface adapter 114, sound adapter 170, and network adapter 198 work. It is possible to connect to the system bus 104.
The display device 116 is operably connected to the system bus 104 by the display adapter 110. A disk storage device (eg, a magnetic or optical disk storage device) 118 is operably connected to the system bus 104 by an I / O adapter 112. The mouse 120 and keyboard (including keypad) 122 are operably connected to the system bus 104 by the user interface adapter 114. The mouse 120 and keyboard 122 are used to input and output information to and from the system 100.
At least one speaker (hereinafter referred to as "speaker") 185 is operably connected to the system bus 104 by a sound adapter 170.
The digital and / or analog modem 196 is operably connected to system bus 104 by network adapter 198.
The present invention provides an approach to authentication, authorization and billing (AAA) using a broker (broker). The broker acts as a certificate certification body instead of a real-time certification engine. Therefore, by using a broker, a failure of a single device does not become a failure of the entire system. The broker issues a certificate to the wireless network, which issues its own certificate to individual mobile phone users who subscribe to the interconnection service.
FIG. 2 is a block diagram showing a communication mechanism according to a specific embodiment of the present invention to which the present invention can be applied. In the specific embodiment shown in FIG. 2, the communication mechanism includes a mobile phone network 210, a wireless LAN 220, a broker 230, and a mobile phone user 240. The present invention provides a license-based scheme for providing authentication, authorization and billing (AAA) services to wireless LAN users. As mentioned above, the present invention is applicable to any combination of networks, including different numbers and different types of networks.
FIG. 3 is a flow diagram illustrating a broker-based method for authentication, authorization and billing (AAA) of mobile phone users in loosely coupled interconnects between access networks according to a specific embodiment of the present invention. The access network includes a mobile phone network and a wireless LAN. The mobile phone network is at least associated with the mobile phone user. The specific embodiment shown in FIG. 3 (further, the specific embodiment shown in FIG. 4 described later) is described in relation to the mobile phone network and the wireless LAN, but the spirit and scope of the present invention. In accordance with the present invention, without losing the above-mentioned types of networks, as well as other types of networks, as well as different numbers of networks (1 mobile phone network and 3 wireless LANs, 2 mobile phone networks and 2 mobile phone networks). It is understood that any combination of networks can be used, including wireless LAN). Further, in a preferred embodiment of the present invention, a mobile phone user initially has a service contract for a single mobile phone network, and a plurality of wireless LANs are interconnected with this single mobile phone network. It is possible that you have a contract. The interconnection contract can be made using various known communication methods with the wireless LAN and the mobile phone network.
Broker public key K<sub>pub_b</sub>Is sent from the broker to the wireless LAN that has a contract for interconnection with the mobile phone network (step 305). If the mobile phone network has contracts with multiple wireless LANs, the broker will use the public key K.<sub>pub_b</sub>May be sent to all of these wireless LANs. Preferably, but not required, the broker's public key<sub>pub_b</sub>Is a public key by wireless LAN<sub>pub_b</sub>Is sent over a secure channel to ensure that is really the broker's public key.
A certificate from the broker to the mobile network is issued by the broker to the mobile network (step 310). The license from the broker to the mobile phone network is, but not limited to, the public key K of the mobile phone network.<sub>pub_cn</sub>And the ID of the mobile phone network. The certificate from the broker to the mobile network is the broker's private key K<sub>pri_b</sub>Is signed using.
When a mobile phone user signs up for a mobile phone network to use the wireless LAN interconnection service, a certificate from the mobile phone network to the mobile phone user is issued to the mobile phone user by the mobile phone network. Is done (step 315). The certificate from the mobile phone network to the mobile phone user is, but not limited to, the certificate from the broker to the mobile phone network and the public key of the mobile phone user.<sub>pub_m</sub>It includes the mobile phone user's subscription level (whether the mobile phone user subscribes to the wireless LAN interconnection service) and the expiration date of the certificate from the mobile phone network to the mobile phone user. The certificate from the mobile phone network to the broker is the private key K of the mobile phone network.<sub>pri_cn</sub>Is signed using.
When a mobile phone user enters the wireless LAN communication range, the mobile phone user gives his / her own certificate (that is, a certificate from the mobile phone network to the mobile phone user) to the wireless LAN (for example, an access point (AP)). ) And other components of the wireless LAN (entity)) (step 320). Whether or not the certificate from the broker to the mobile phone network by wireless LAN (included in the certificate from the mobile phone network to the mobile phone user) is genuine is the broker's public key K<sub>pub_b</sub>It is determined using (the one transmitted to the wireless LAN in step 305) (step 325). If the broker's authorization to the mobile network is not genuine, this method ends. However, if the broker-to-mobile network authorization is genuine, the wireless LAN will carry (from the broker-to-mobile network authorization included in the mobile network-to-mobile user authorization). Telephone network public key K<sub>pub_cn</sub>Is extracted (step 330). Mobile network public key K<sub>pub_cn</sub>The wireless LAN uses to determine if the certificate from the mobile phone network to the mobile phone user is genuine (step 335).
If the certificate from the mobile phone network to the mobile phone user is not genuine, the process of this method ends. However, if the certificate from the mobile phone network to the mobile phone user is genuine, the wireless LAN is the public key of the mobile phone user from the certificate from the mobile phone network to the mobile phone user.<sub>pub_m</sub>Extract and the mobile phone user's public key<sub>pub_m</sub>Issuance of the session key encrypted using is issued to the mobile phone user (step 340). Although not limited, a WEP (Wired Equivalent Privacy) key issued for each user may be used as the session key.
The encrypted session key is the private key K of the mobile phone user.<sub>pri_m</sub>Is decrypted by using (step 345). Communication between the mobile phone user and the wireless LAN is performed using the session key (that is, all subsequent communication between the mobile phone user and the wireless LAN is encrypted using the session key) (step 350). .. Private key K that only certain mobile phone users need to decrypt this session key<sub>pri_m</sub>The mobile phone user is authenticated by wireless LAN.
FIG. 4 is a flow diagram showing a certificate-based method for authentication, authorization and billing (AAA) of a mobile phone user in a loosely coupled interconnect between access networks according to another specific embodiment of the present invention. Is. Access networks include mobile phone networks and wireless LANs. A mobile phone network is associated with at least one mobile phone user. The method in Figure 4 allows mutual authentication between the mobile phone user and the wifi, and the mobile phone user is actually correct (for example, to prevent the message from being snooped). legitimate) You can make sure you are talking to a wireless LAN.
Broker public key K<sub>pub_b</sub>And the broker's wireless LAN authorization is sent from the broker to the wireless LAN that has a contract to interconnect with the mobile network (step 405). Although not limited, the certificate from the broker to the wireless LAN is the public key K of the wireless LAN.<sub>pub_w</sub>And contains the wireless LAN ID. The certificate from the broker to the wireless LAN is the broker's private key K<sub>pri_b</sub>Is signed using.
If the mobile network has contracts with multiple wireless LANs, the broker will use the public key K.<sub>pub_b</sub>May be sent to all of these wireless LANs. Preferably, but not required, the broker's public key<sub>pub_b</sub>Is a public key by wireless LAN<sub>pub_b</sub>Is sent over a secure channel to ensure that is really the broker's public key.
A certificate from the broker to the mobile network is issued by the broker to the mobile network (step 410). The license from the broker to the mobile phone network is, but not limited to, the public key K of the mobile phone network.<sub>pub_cn</sub>And mobile network ID and broker public key K<sub>pub_b</sub>Includes. The certificate from the broker to the mobile network is the broker's private key K<sub>pri_b</sub>Is signed using.
When a mobile phone user signs up for a mobile phone network to use the wireless LAN interconnection service, a certificate from the mobile phone network to the mobile phone user is issued to the mobile phone user by the mobile phone network. Is done (step 415). The authorization from the mobile phone network to the mobile phone user is, but not limited to, the authorization from the broker to the mobile phone network and the public key of the mobile phone user.<sub>pub_m</sub>It includes the mobile phone user's subscription level (whether the mobile phone user subscribes to the wireless LAN interconnection service) and the expiration date of the certificate from the mobile phone network to the mobile phone user. The certificate from the mobile phone network to the broker is the private key K of the mobile phone network.<sub>pri_cn</sub>Is signed using. In addition, the broker's public key K<sub>pub_b</sub>Is sent to the mobile phone user (step 417).
When the mobile phone user enters the wireless LAN communication range, the mobile phone user gives his / her own authorization (that is, the authorization from the mobile phone network to the mobile phone user) to the wireless LAN (for example, an access point (AP)). ) And other components of the wireless LAN (entity)) (step 420). Whether or not the certificate from the broker to the mobile phone network by wireless LAN (included in the certificate from the mobile phone network to the mobile phone user) is genuine is the broker's public key K.<sub>pub_b</sub>It is determined using (the one transmitted to the wireless LAN in step 405) (step 425). If the broker's authorization to the mobile network is not genuine, this method ends. However, if the broker-to-mobile network authorization is genuine, the wireless LAN will carry (from the broker-to-mobile network authorization included in the mobile network-to-mobile user authorization). Telephone network public key K<sub>pri_cn</sub>Is extracted (step 430). Mobile network public key K<sub>pri_cn</sub>Using the wireless LAN, the wireless LAN determines whether the authorization from the mobile phone network to the mobile phone user is genuine (step 435).
If the certificate from the mobile phone network to the mobile phone user is not genuine, the process of this method ends. However, if the authorization from the mobile phone network to the mobile phone user is genuine, the wireless LAN is the public key of the mobile phone user.<sub>pub_m</sub>Extract and the mobile phone user's public key<sub>pub_m</sub>Encrypted using the wireless LAN private key K<sub>pri_w</sub>Issuance of the session key signed by the mobile phone user to the broker's private key K<sub>pri_b</sub>Send the authorization from the mobile phone user signed with to the broker (step 440). The certificate from the broker to the wireless LAN is the public key of the wireless LAN.<sub>pub_w</sub>Includes. Although not limited, a WEP (Wired Equivalent Privacy) key issued for each user may be used as the session key.
Broker public key K<sub>pub_b</sub>Is used by the mobile phone user to determine if the broker-to-wireless LAN authorization is genuine (step 442). If the certificate from the broker to the wireless LAN is not genuine, the process of this method ends. However, if the license from the broker to the wireless LAN is genuine, the mobile phone user can use the public key K from the broker to the wireless LAN to the wireless LAN.<sub>pub_w</sub>To get (step 443). Wireless LAN public key K<sub>pub_w</sub>Is used by the mobile phone user to determine if the session key is genuine (step 444). If the session key is not genuine, this method ends.
However, if the session key is genuine, the mobile phone user can use his private key K.<sub>pri_m</sub>Decrypt the encrypted session key using (step 445). Communication between the mobile phone user and the wireless LAN is performed using the session key (that is, all subsequent communication between the mobile phone user and the wireless LAN is encrypted using the session key) (step 450). ..
Although exemplary embodiments have been described with reference to the accompanying drawings, the present invention is not limited to such specific embodiments, and those skilled in the art will appreciate such embodiments. It can be understood that various modifications and modifications can be made to the embodiments without departing from the scope or spirit of the present invention. For example, the present invention is not limited, but it is clear that it can be applied to any combination of wireless communication network and mobile communication network, including those based on standards such as IEEE802.11 and Hiperlan2. Is. All such modifications and modifications are intended to be included in the scope of the invention described in the claims.
<figref num="1">FIG. 1 is a block diagram showing a computer system 100 according to a specific embodiment of the present invention to which the present invention can be applied.</figref><figref num="2">FIG. 2 is a block diagram showing a communication mechanism according to a specific embodiment of the present invention to which the present invention can be applied.</figref><figref num="3">FIG. 3 is a flow diagram illustrating a broker-based method for authentication, authorization and billing (AAA) of mobile phone users in loosely coupled interconnects between access networks according to a specific embodiment of the present invention.</figref><figref num="4A">FIG. 4A is a flow diagram illustrating a authorization-based method for authentication, authorization and billing (AAA) of mobile phone users in loosely coupled interconnects between access networks according to another specific embodiment of the present invention. Is.</figref><figref num="4B">FIG. 4B is a flow diagram showing a certificate-based method for authentication, authorization and billing (AAA) of mobile phone users in loosely coupled interconnects between access networks according to another specific embodiment of the present invention. Is.</figref>
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2021352574A1 | Cited by | United States of America | Search report |
| JP2013530650A | Cited by | Japan | Search report |
| US10218514B2 | Cited by | United States of America | Applicant |
| JP2013530650A | Cited by | Japan | Search report |
| US11653295B2 | Cited by | United States of America | Search report |
| JP2013530650A | Cited by | Japan | Examiner |
| US9215220B2 | Cited by | United States of America | Applicant |
| WO02102009A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2000244547A | Cites | Japan | Search report |
| JP2002324419A | Cites | Japan | Search report |
14 members in 9 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 38660302 | United States of America | P | |
| 38660302 | United States of America | P | |
| 60386603 | United States of America | – | |
| 0316546 | United States of America | W | |
| 0316546 | United States of America | W | |
| 2002386603 | – | – | – |
| 200316546 | – | – | – |
| US20020386603P | – | – | – |
| WO2003US16546 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO03105049A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003237252A1 | Australia | A1 | |
| BR0305019A | Brazil | A | |
| KR20050010859A | Republic of Korea | A | |
| EP1514208A1 | European Patent Office (EPO) | A1 | |
| MXPA04012157A | Mexico | A | |
| CN1659558A | China | A | |
| JP2005529525AThis record | Japan | A | |
| US2005240760A1 | United States of America | A1 | |
| CN1659558B | China | B | |
| EP1514208A4 | European Patent Office (EPO) | A4 | |
| KR101002471B1 | Republic of Korea | B1 | |
| JP4792221B2 | Japan | B2 | |
| US8468354B2 | United States of America | B2 |
24 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Notification of resignation of power of attorneyJAPANESE INTERMEDIATE CODE: A7424RD04 | RD04 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 | |
| Notification of resignation of power of attorneyJAPANESE INTERMEDIATE CODE: A7424RD04 | RD04 | |
| Notification of revocation of power of attorneyJAPANESE INTERMEDIATE CODE: A7425RD05 | RD05 | |
| Notification of resignation of power of attorneyJAPANESE INTERMEDIATE CODE: A7424RD04 | RD04 | |
| Notification of appointment of power of attorneyJAPANESE INTERMEDIATE CODE: A7423RD03 | RD03 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2005529525
- Publication, DOCDB
- 2005529525
- Publication, EPODOC
- JP2005529525
- Application
- 2004512049
- Application, DOCDB
- 2004512049
- Application, EPODOC
- JP20040512049
Titles2
- Japanese
- 階層型認可証を用いたブローカーに基づく相互接続
- English
- Broker-based interconnection with hierarchical authorization
Classification
- CPC, 12
- H04W12/06
- H04L63/062
- H04L63/0823
- H04L63/0892
- H04W88/06
- H04W92/02
- H04L9/0825
- H04L9/3263
- H04L2209/56
- H04L2209/80
- H04W84/12
- H04W12/0431
- IPC, 8
- H04W12 06
- G06F21 35
- H04L9 00
- H04L9 08
- H04L9 30
- H04L9 32
- H04L29 06
- H04L29 08
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo