Method and system for controlling access to networks
Abstract
The method of accessing both the first and second networks (1, 2) is that the terminal (4) requests access to the first network via the first network (1) (RQ1). A step of providing the first identifier (ID1) while the first network verifies the first identifier and issues a second identifier (ID2) if the verification is successful. The step of providing the second identifier (ID2) while the terminal (4) requests access (RQ2) to the second network (2) via the first network (1), and authentication. A step in which the server (112) verifies the second identifier and issues a third identifier (ID3) if the verification is successful, and the first network (1) is sent to the terminal (4). It has a step of transmitting the third identifier (ID3) and a step of the terminal (4) accessing the second network (2) using the third identifier (ID3). The first identifier (ID1) may be a SIM card identifier, the second identifier (ID2) may be a network address, while the third identifier (ID3) may be configured by a one-time password. ..
Term
0.7 yearsto projected expiry
Projected expiry 19 June 2027, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
14 claims: 5 independent, 9 dependent
- 1端末を使用することにより第1のネットワークおよび第2のネットワークへアクセスする方法であって、 前記端末が、前記第1のネットワークを介して前記第1のネットワークへのアクセスを要求しつつ、第1の識別子を提供するステップと、 前記第1のネットワークが前記第1の識別子を検証し、前記検証が成功である場合に第2の識別子を発行するステップと、 前記端末が、前記第1のネットワークを介して前記第2のネットワークへのアクセスを要求しつつ、前記第2の識別子を提供するステップと、 認証サーバが前記第2の識別子を検証し、前記検証が成功である場合に第3の識別子を発行するステップと、 前記第1のネットワークが前記端末に前記第3の識別子を送信するステップと、 前記端末が前記第3の識別子を使用して前記第2のネットワークへアクセスするステップとを有する方法。
- 2前記第1の識別子がSIMカード識別子である、請求項1に記載の方法。
- 3前記第2の識別子がネットワーク・アドレスであり、好ましくはIPアドレスである、請求項1または2に記載の方法。
- 4前記第3の識別子がワンタイム・パスワードである、請求項1、2または3に記載の方法。
- 5前記第1のネットワークが、無線ネットワーク、好ましくはGPRSネットワークもしくはGSMネットワークであり、および/または前記第2のネットワークが、ローカル・エリア・ネットワーク、好ましくは無線ローカル・エリア・ネットワークである、前記請求項のいずれかに記載の方法。
- 6前記第2の識別子が記憶装置内に格納され、この記憶装置は、前記第2の識別子に関連付けられたユーザ情報も格納している、請求項1ないし5のいずれかに記載の方法。
- 7前記端末に前記認証サーバのネットワーク・アドレスを供給するステップをさらに有する、請求項1ないし6のいずれかに記載の方法。
- 8前記第2のネットワークが第1のノードで前記第3の識別子を受信するステップと、 前記第1のノードが、前記第2のネットワークの選択された第2のノードに前記第3の識別子を転送する、前記第2のノードは前記第1のネットワークと結合された、ステップとをさらに有し、 前記第2のノードが、好ましくは前記受信された第3の識別子を用いて選択される、請求項1ないし7のいずれかに記載の方法。
- 9前記第1のネットワークおよび前記第2のネットワークが異なるオペレータによって運用される、請求項1ないし8のいずれかに記載の方法。
- 10前記端末が第2のネットワークを検出した際に自動的に実施される、請求項1ないし9のいずれかに記載の方法。
- 11請求項1から10のいずれかによる方法を実施するためのコンピュータ・プログラム。
- 12第1のネットワークおよび第2のネットワークへアクセスするためのアクセス制御構成であって、 第1の受信された識別子と第1の割り当てられた識別子とを比較するための第1の検証プロセッサ・ユニットと、 前記第1のネットワークへアクセスするための、前記検証プロセッサ・ユニットに接続された第1のアクセス制御ユニットと、 第2の受信された識別子と第2の割り当てられた識別子とを比較するための第2の検証プロセッサ・ユニットと、 前記第2のネットワークへアクセスするための、前記第2の検証プロセッサ・ユニットに結合された第2のアクセス制御ユニットと を備えるアクセス制御構成。
- 13請求項12に記載のアクセス制御構成を備える通信ネットワーク。
- 14第1のネットワークおよび第2のネットワークを備えるシステムであって、前記第1のネットワークは、 端末から第1のアクセス要求および第1の識別子を受信すると、前記第1の識別子を検証し、前記検証が成功である場合に第2の識別子を発行し、 前記端末から第2のアクセス要求および前記第2の識別子を受信すると、認証サーバを使用して、前記端末から受信された前記第2の識別子を検証し、前記検証が成功である場合に前記端末に第3の識別子を送信することにより前記第2のネットワークへのアクセスを許容する ように構成される、システム。
Independent claims14
54 paragraphs, as filed
The present invention relates to a first network and a method and system for accessing a second network.
Methods and systems that allow access to communication networks are generally known. For example, most computer networks require users to enter a username and password on a terminal and then access the computer network. There is an access control within the computer network, which is often provided as the appropriate computer program run by the network server, which is the username and password. Is compared with an appropriate authentication criterion, and if the entered user name and password meet this authentication criterion, access from the terminal is possible.
However, the user must be informed of what username and password should be used. In a common wired computer network, users are usually told in writing or verbally what username and password they have been assigned. This requires a large number of regular mail to be sent, which is more inconvenient if the assigned passwords change frequently. In addition, it takes a relatively long time for the username and password to be received by the user.
In the art, a system for controlling access to a wireless local area network (WLAN) is known, which is based in Stockholm, Sweden. It is sold under the name of "Orbyte Authentication Manager" by "AB)". The system includes an authentication server that can be accessed by the terminal to obtain a one-time password (OTP). The terminal can access this authentication server via the WLAN gateway node via the Internet. In this regard, WLAN gateway nodes are commonly known as "hotspot gateways" or simply "hotspots." The authentication server goes through this WLAN gateway node to the Subscriber Identification Module. Data can be obtained from the Module) (SIM) card to verify whether the terminal user has subscribed to the WLAN service. If the user is subscribed, the authentication server generates an OTP and sends this assigned OTP to the terminal over the Internet via the WLAN gateway node and thus via the WLAN. The terminal then provides this OTP to the RADIUS server to access the WLAN. The RADIUS server compares this provided OTP with the assigned OTP to determine if access should be granted.
However, the disadvantage of the "Orbite Authentication Management Program" is that the WLAN is used to obtain the OTP before the terminal is actually allowed access to the WLAN. Therefore, the WLAN gateway and other parts of the WLAN are vulnerable to unauthorized access. Furthermore, a wide range of security measures are required to prevent unauthorized access. This is especially annoying if the WLAN is operated by an entity other than the one that runs the SIM card-enabled network. Moreover, the authentication server is accessible via the Internet, which makes the authentication server vulnerable to unauthorized access and therefore also requires extensive security measures.
US Patent Application Published US2004 / 0233893 (Transat Technologies (Transat) Technologies)) discloses systems and methods for transferring wireless network access passwords. In the system disclosed in the publication of the patent application, the access node that transfers and / or assigns the network password is of the first type to and from the first node operating in the WLAN. Includes a first interface for sending and receiving communications. This access node also includes a second interface for sending and receiving a second type of communication to and from a second node in a mobile network, such as a GSM / GPRS network. This access node can receive short message service (SMS) messages over the mobile network from mobile devices that hold mobile MSISDN, and is an OTP (one-time password) assigned for WLAN access. An SMS message can be sent to the mobile device holding the. This assigned OTP can then be entered into the WLAN to access the WLAN.
However, the disadvantage of the system known by this prior art document is that extensive modifications must be made to the authentication server to allow it to generate and receive SMS messages. ..
What's more, for example, to allow wireless clients and mobiles to automatically gain access to generate and send short messages incorporating mobile MSISDN and to be able to extract OTPs from received SMS. Is required, or the user must manually enter the provided OTP within the WLAN.
In this regard, SMS does not use a real circuit-switched GSM network, and SMS messages are sent through the signal channels of the GSM network, that is, the channels through which monitoring and control signals are transmitted from and to the mobile device. It should be noted that it will be sent. Therefore, not only to allow the sending of SMS messages, but also to process messages from signal channels in a manner other than controlling the connection or visually outputting the message to the mobile phone display. Also requires extensive modification.
International Patent Application Publication WO 03/088577 (Nokia) discloses a method for authenticating users of terminals within a wireless local area network (WLAN). In this known method, the user terminal first contacts the WLAN server access point (that is, the "hotspot"), and only then uses the user's mobile communication system to determine whether the user has access. Will be checked. In other words, the messages exchanged between the user terminal and its home mobile communication system travel through the visited system. This requires that the user terminal already has some (limited) access before (full) access is granted. Therefore, appropriate measures must be taken to allow visiting user terminals limited access to service points.
International Patent Application Publication WO 01/17310 (Ericsson) discloses an authentication method that uses GSM security principles to authenticate users requesting access to a packet data network. This method is initiated by the user attempting to access the access network. The authentication entity connected to this access network then sends an authentication request to the authentication server. The authentication token sent to the user over the access network is sent back to the authentication server over the mobile network. Therefore, the access network is involved in the authentication process before the actual (full) access is granted. Therefore, this known access network needs to be able to distinguish between limited and full access.
WO 2006/101183 (Matsushita), published international patent application published on September 28, 2006, describes a system for automatic security authentication in wireless networks. The terminal has two communication units, a first unit for communication with the access point and a second unit for communication with the GSM network or similar network. This access point can issue an identification code that should be used by the terminal. In other words, the access point is involved in the exchange of information before the actual access is granted, as in the other prior art documents mentioned above.
<p> An object of the present invention is to provide a method and system for accessing a first network and a second network that do not require much extensive modification to existing networks and network components.</p>
<p> Therefore, according to the present invention, the method of accessing the first network and the second network by using a terminal is A step in which the terminal provides a first identifier while requesting access to the first network via the first network. A step in which the first network verifies the first identifier and issues a second identifier if the verification is successful. A step in which the terminal provides the second identifier while requesting access to the second network via the first network. A step in which the authentication server verifies the second identifier and issues a third identifier if the verification is successful. A step in which the first network transmits the third identifier to the terminal, With the step of the terminal accessing the second network using the third identifier Have.</p><p> By accessing only the first network until access to the second network is granted, it is no longer necessary to allow partial and / or temporary access to the second network.</p><p> Such a method does not require much extensive modification. The reason is that most terminals receive and transmit appropriate software and / or hardware that should be connected to a packet-switched network, such as a network that operates according to the IP protocol, as well as data and instructions received from that packet-switched network. And because it already includes software and / or hardware to process, typically a web browser. In addition, most authentication servers, such as RADIUS servers that allow access to WLANs, should already be connected to a packet exchange network, such as a network that operates according to Internet Protocol (IP) standards, with the appropriate software and / or hardware. Includes software and / or hardware that receives, transmits, and processes data and instructions received from the packet exchange network, such as web server applications. So, with only a few adaptations, for example, having the terminal's web browser application send a request and responding to this request to have the web server application on the authentication server generate and send an authentication code. I'm done.</p><p> The first identifier is preferably a SIM card identifier, and thus uses an identifier facility that exists within GSM terminals and similar terminals. The second identifier is preferably a network address, more preferably an IP (Internet Protocol) address. This allows for easy identification using existing resources. The third identifier is preferably a one-time password to achieve a high level of security.</p><p> Various (types) of networks can be used. However, in a preferred embodiment, the first network is a wireless network, preferably a packet exchange wireless network such as a GPRS network or GSM network, while the second network is a local area network (LAN). , Preferably a wireless local area network (WLAN).</p><p> The second identifier may be stored in a storage device, which also stores user information associated with the second identifier. If the second identifier is a network address, user (and / or terminal) information may be stored with the network address in a suitable storage device, eg, in an IP session database. This user information may have subscriber information.</p><p> According to the present invention, when the first network and the second network have different operators, the operator of the first network can obtain access to which second network by the customer of the first network. It is especially advantageous because it can be determined.</p><p> The present invention also provides at least one computer program for carrying out the methods defined above. A computer program may include a set of computer-executable instructions stored on a data carrier such as a CD or DVD. These computer-executable instructions allow a programmable computer to perform the methods specified above, but are available by downloading from a remote server, for example via the Internet. You may be.</p><p> Furthermore, the present invention provides an access control configuration for accessing a first network and a second network, and a network having such an access control configuration. In addition, the present invention provides a system comprising a first network and a second network, wherein the first network is: Upon receiving the first access request and the first identifier from the terminal, the first identifier is verified, and if the verification is successful, the second identifier is issued. Upon receiving the second access request and the second identifier from the terminal, the authentication server is used to verify the second identifier received from the terminal, and if the verification is successful, the terminal. Send a third identifier to It is configured as follows.</p><p> These and other aspects of the invention will become apparent from the embodiments described below and will be described with respect to these embodiments. Specific embodiments of the present invention are set forth in the dependent claims.</p><p> Further details, embodiments and embodiments of the present invention will be described with reference to the drawings, by way of example only.</p>
<figref num="1">It is a block diagram which shows typically one Embodiment of the remote communication system by this invention.</figref><figref num="2">It is a block diagram which shows roughly one Embodiment of the terminal by this invention.</figref><figref num="3">It is a block diagram which shows typically one Embodiment of the access control configuration by this invention.</figref>
In this document, the following abbreviations and / or terms are understood to have at least the following meanings: A "wireless LAN" or "WLAN" is a network that allows mobile users to connect to a local area network (LAN) through a wireless connection, such as an IEEE 802.11 compliant network. A "RADIUS client" (which can be a network access server, such as a dial-up server, or a wireless access point) sends the RADIUS server user credentials and connection parameters in the form of a RADIUS message. Send information about. The "RADIUS Protocol" is an Internet Engineering Steering Group (IESG) Request for Comments (RFC) 2865 (Internet Engineering Steering Group (IESG) Request for Comments (RFC). It is defined in 2865). The "RADIUS server" authenticates and authorizes RADIUS client requests and sends back a RADIUS message response. A "RADIUS proxy" is a computer that forwards RADIUS messages between a RADIUS client, a RADIUS server, and another RADIUS proxy.
"SIM" stands for Subscriber Identity Module. A "SIM card" is a type of smart card that is inserted into a GSM phone. The SIM card identifies the user account for the network, processes authentication, and stores data about basic user data and network information.
The "Mobile Subscriber ISDN Number" (MSISDN) is the number on which the caller dials to contact the mobile subscriber. The "International Mobile Station Identity (IMSI)" is a unique, non-dialable number assigned to each mobile subscriber within the GSM system, which is the subscriber's number within the GSM network. And identify whether or not this subscriber is subscribed. The IMSI is usually stored in the SIM card.
The "serving GPRS support node" or SGSN is responsible for delivering data packets from and to mobile stations within the SGSN service area. Gateway GPRS support The "node)" or "GGSN" acts as an interface between the backbone node and the "SGSN". The "GGSN" translates packet data coming from the SGSN into the appropriate packet data protocol for the backbone network and sends this transformed packet data over the backbone network. In the opposite direction, received data packets from the backbone network are translated into packets suitable for being forwarded by the SGSN to mobile stations within the SGSN service area. The GGSN also performs authentication and billing functions. In general, there is a many-to-many relationship between SGSN and GGSN. That is, the GGSN can operate on one or more SGSNs, and the SGSN routes packets on this SGSN through one or more GGSNs to contact different backbone networks. Can be done.
The "Home Location Register" or HLR is the relevant information about a legitimate subscriber, such as the subscriber's mobile device's MSISDN (that is, mobile phone number), IMSI, access rights and / or current location. Contains the (central) database on the wireless network that stores. The HLR may reside on, for example, the GGSN.
Referring to FIG. 1, the communication system 3, which is merely an example shown in FIG. 1, includes a packet-switched first network 1 and a second network 2. In the example of FIG. 1, the packet-switched first network 1 is a telecommunications network, and more particularly, a packet-switched mobile network such as a GPRS (General Packet Radio Services) or UMTS (Universal Mobile Telecommunications System) network. However, the packet-switched primary network can be any suitable type of packet-switched network. The packet-switched first network may be, for example, a network operated by the same operator as the second network, or may be operated by a different operator.
The second network 2 can be any suitable type of network. As an example, the second network may be a wireless network, such as a wireless local area network (WLAN), which can be accessed by a terminal over a wireless connection, for example.
System 3 shown in FIG. 1 further includes terminal 4 and access control. In this example, the access controls are the first access control configuration (first access control device) including SGSN100, GGSN110, GPRS IP core 113 and authentication server 112, and gateway 200, proxy 210, server 220 and authentication server. It includes a second access control configuration (second access control device) including 112.
Terminal 4 may be implemented as shown in FIG. The example shown in FIG. 2 includes a first terminal output 40 that can connect to a packet-switched network, eg, the first network 1 shown in FIG. Terminal 4 further has a terminal input 41 that can connect to a packet-switched network. The terminal 4 has a second terminal output 42 that can be connected to another network, for example the second network 2 in the example of FIG. Terminal 4 further has a processing unit 43 connected to terminal inputs 41, terminal outputs 40, 42. The terminal 4 further has a storage device 44 connected to the processing unit 43.
The storage device 44 may be implemented, for example, as a SIM card reader with a suitable SIM card inserted. However, the storage device 44 may be implemented in any suitable manner, which storage device 44 may include, for example, a non-volatile memory such as a SIM card or other type of smart card. The storage device 44 may contain an identification code for the first network 1, such as MSISDN, IMSI, or any other suitable type of code.
The processing unit 43 can retrieve the identification code and any other suitable type of information needed to access the first network 1 from the storage device 44. The processing unit 43 is further provided with suitable hardware and / or software to allow the connection to be established on the packet-switched network. As an example, the processing unit 43 may include a network connection module suitable for connecting to, for example, an IP network, and the processing unit 43 may transmit and receive data on the connection and process the data, for example. It may be able to run a web browser application that can. For example, this browser application sends a request for a web page to a web server, receives the web page, and makes this web page visually output to the user of terminal 4. -Can process pages. The processing unit 43 can transmit the identification code for the first network to the access control via the first terminal output 40 and thus through the first network 1. The processing unit 43 can receive the authentication code assigned for the second network 2, for example for the WLAN in the example of FIG. 1, from the access control via the terminal input 41. The received code may then be output to the user interface. After that, in order to access the second network 4, the terminal authentication code can be input by the user at the terminal with appropriate input. This terminal authentication code may be transmitted from the terminal 4 to the second network by the processing unit 43 via the second terminal output 42. Alternatively, the processing unit 43 may be configured to automatically transfer the received code as an authentication code to the second network.
FIG. 3 schematically shows an example of an access control configuration (access control device) 5. Although access control configuration 5 is shown as a single entity in FIG. 3, access control configuration 5 is configured as a plurality of separate entities, such as SGSN100, GGSN100, etc., which are appropriately connected to each other, as shown in FIG. 1, for example. It should be noted that the entity may be included.
In FIG. 3, the access control configuration 5 includes a control input 50 that receives a request for an authentication code via the packet-switched first network. An authentication code generator 51 is connected to this control input 50. The authentication code generator 51 can generate the authentication code assigned for the second network 2 in response to the request. The authentication code generator 51 is connected to the control output 52 connected to the first network. Through this control output 52, the authentication code can be transmitted to the terminal 4 via the first network 1.
Access control configuration 5 further includes an authentication code generator 51 and an authentication controller 53 connected to a second network 2. Authentication control 53 can enable the assigned authentication code. That is, when the authentication code is enabled, when the authentication code corresponding to this assigned authentication code is received by the second network 2, the terminal 4 is allowed to access the second network 2. Will be done. In this example, the authentication control 53 is connected to the authentication code processor 54, and the authentication control 53 transmits the generated or assigned authentication code to the authentication code processor 54.
The authentication controller system 5 further has an authentication controller input 55. This authentication control input 55 is connected to the second network 2. At the authentication controller input 55, it is possible to receive the terminal authentication code transmitted by the terminal 4 via the second network 2. The authentication code processor 54 is connected to the authentication control input 55. The authentication code processor 54 can compare the received terminal authentication code with the assigned authentication code. The authentication code outputs the result of this comparison to the second access control 56 connected to the authentication code processor 53. When the terminal authentication code corresponds to the assigned authentication code, the second access control 56 allows access to the second network 4. It should be noted that the term "corresponding" as used herein does not necessarily imply that the authorization codes are exactly the same. Mismatches between authorization codes can be acceptable under some circumstances. However, preferably, the authorization code must be identical enough to eliminate almost or all unauthorized or malicious access attempts.
The access control configuration 5 may further include a configuration that controls access to the first network. In the example of FIG. 1, this is implemented by SGSN100 and GGSN110 and is isolated from the entities that control access to the second network: gateway 200, proxy 210, server 220 and authentication server 112. However, in Figure 3, the block diagram is shown as a single entity to make it clearer what units can exist in System 3 to control access to the first network.
In FIG. 3, the access control configuration 5 can receive the authentication code from the terminal 4 via the control input 50. As shown in FIG. 3, the verification processor 57 is connected to the control input 50. The verification processor 57 can check the received identification code against the verification criteria. In the example of FIG. 1, the SGSN100 retrieves subscriber information from storage 101, such as the HLR (Home Location Register), and this received identification of whether access to the first network 1 may be granted. Can be determined from the code. The access control unit 58 is connected to the verification processor 57. The access control unit 58 enables access from the terminal 4 to the first network 1 when the identification code meets the verification criteria, and the first network when the identification code does not meet the verification criteria. Terminate terminal 4 access to 1. The access control unit 58 is connected to the control output 52 to transmit a signal suitable for enabling or terminating access.
In the example of FIG. 1, the method according to the invention can be implemented. Such a method includes a step of accessing the first network 1 and a step of accessing the second network 2 when the first network 1 is accessed. The step of accessing the first network 1 may form part of the method of accessing the second network 2. However, the terminal is first placed (longer) before the second network 2 is accessed, for example, before the terminal 4 is within the coverage area of the second network 2. It is also possible that you have already accessed network 1. Therefore, access to the second network may be enabled (enough) before the terminal actually gains access to the second network.
Access to the first network 1 may be made, for example, by transmitting the identification code ID 1 for accessing the first network from the terminal 4. The access request RQ1 may be attached to the identification code ID1, and the identification code ID1 may be incorporated in the request RQ1.
The identification code ID1 is transmitted to the first network and checked in this first network, for example, in the SGSN100 and GGSN110 in the example of FIG. 1, against the verification criteria. For example, in the example of Figure 1, the terminal 4 can transmit MSISDN and / or IMSI, and the SGSN100 can, among other things, compare this MSISDN and / or IMSI with the information stored within the HLR101. If the identification code is correct, for example, if the MSISDN and / or IMSI belong to a subscriber to the network connected to the SGSN100 and the terminal is not listed in the database as stolen, the SGSN100 will provide access. To do. (Of course, if, for example, the device is listed as stolen, or the identification code is otherwise incorrect, that is, the identification code does not meet the validation criteria, then the device's access to the first network Is terminated by the SGSN.) After the SGSN100 has made it accessible, the GGSN can verify the identification code to allow access to the packet-switched network that connects the authentication server to this GGSN. The GGSN can, for example, implement the accounting, authentication, administration (AAA) network security services required to access the GPRS IP network. In the example of FIG. 1, for example, the GPRS IP core network 113 connects the authentication server 112 to terminal 4 via SGSN100 and GGSN110. The GSM / GPRS network is a mixed voice and data communication network in which the SGSN controls access to the entire network, while the GGSN goes to the data communication network, for example the GPRS IP core 113 in Figure 1. It should be noted that it can be considered a control node for access.
Before, during, or after the acquisition of the first network 1, the network address of the first network 1 can be assigned to the terminal 4, which terminal 4 is It is possible to be supplied with data indicating the network address of the authentication server in the first network 1. For example, in the example in Figure 1, the GGSN and / or SGSN can assign an IP address to Terminal 4 via Dynamic Host Configuration Protocol (DHCP) or is suitable for a particular type of network. Any other type of network address can be assigned to terminal 4.
After accessing the first network, the procedure for accessing the second network can be started. As mentioned above, there may be a time interval between the step of accessing the second network and the step of accessing the first network. Also, multiple accesses to the second network may be pre-requested and granted.
Access to the first network 1 is verified and controlled by SGSN100 and GGSN110, for example in the example of FIG. 1, so that the authentication server 112 does not need to verify the identification code and the authentication code for the second network 2. Only needs information about the identity of the terminal 4 to assign to the terminal 4. Therefore, the authentication server only needs a small modification to get this information, while the first network 1, for example SGSN100 and GGSN110, does not need any modification at all. In the example of FIG. 1, the authentication server 112 is connected to the storage device, and in FIG. 1, the IP session database 111 is connected, and the GGSN is in this storage device, the identity of the terminal and / or the terminal user, and the terminal. Stores information about network addresses, such as IP addresses.
Access to the second network 2, for example the WLAN in the example of FIG. 1, is made by sending an authentication code access request RQ2 from the terminal 4 to the authentication server 112 via the packet-switched first network 1. It is possible. In response to this request RQ2, the authentication server 112 can generate the authentication code ID3 assigned to the WLAN for the second network 2, for example in the example of Figure 1, and enable this assigned authentication code. it can. That is, when authentication code ID3 is enabled, the second authentication code corresponding to this assigned authentication code ID3 is received by the second network 2, for example by the WLAN in the example of FIG. Access to network 2 is enabled for terminal 4. In the example of FIG. 1, as an example, the authentication server can determine the request source from the request RQ2 by, for example, determining the IP address that is the source of the request RQ2. As an example, the authentication server 112 retrieves the user's identity information ID2 associated with this determined IP address, such as the MSISDN or IMSI associated with this determined IP address, from the IP session database 111. It is possible.
Based on the user's identity information ID2, or the IP address itself, the authentication server 112 can determine whether the terminal is allowed to obtain an authentication code for the second network 2. For example, if neither the MSISDN nor the IMSI associated with the determined IP address is present in the IP session database 111, the authentication server 112 can determine that the request is invalid and can terminate the procedure. Also, if the MSISDN or IMSI associated with the determined IP address reveals that the subscriber is not subscribed to the service through the second network 2, the authentication server 4 terminates the procedure. Can be made to.
If the authentication server 112 continues the procedure, for example, if the IP address corresponds to the subscriber's MSISDN or IMSI subscribing to the service over the second network 2, the authentication server 112 will The authentication code ID 3 is optionally transmitted to the terminal 4 via the packet-switched first network 1 in an encrypted format. For example, in the example of Figure 1, the authentication server 112 can send the authentication code to the request IP address as a secure hypertext document compliant with https (hypertext over secure socket layer protocol). Terminal 4 may output the received authentication code ID 3 to the user interface. The user enters the terminal authentication code into the authentication application running on the terminal 4 to access the second network 2 after recognizing the received authentication code (for example, visually or as voice). It is possible to do.
However, it is also possible for the terminal 4 to automatically input the received authentication code as the terminal authentication code into the authentication application. For example, a web browser application may be running on the terminal, which first requests a web page from the authentication server, and the authentication server responds to this request with an authentication code. A web page containing the written login script for the second network can be sent to this terminal. When the terminal's web browser application receives it, it executes a login script and sends this pre-written authorization code to the second network 2.
Such automatic access to the second network 2 enables so-called "seamless roaming". In "seamless roaming", the terminal 4 is automatically switched between networks, for example, the optimum network, without bothering the user of the terminal. To facilitate seamless roaming, for example, the terminal may be further equipped with a detector capable of automatically detecting the presence of a second network. After this, access to the second network can be automatically gained and this second network will be used in place of the first network to send and receive data from the terminal. It becomes possible. Further, the network address assigned to the terminal for the first network may be the same as the network address assigned to the terminal for the second network. In addition, when the terminal comes out of the coverage area of the second network, the terminal will use the first network or other network in place of the second network to send or receive data. It may be controlled.
In the second network, the terminal verification code can then be compared with the assigned verification code, and if this terminal verification code corresponds to the assigned verification code, the second from the terminal. Access to the network may be enabled. For example, in the example of FIG. 1, terminal 4 optionally sends a terminal authentication code to gateway 200 of the second network 2, along with other data such as username, terminal network address, and so on. The terminal 4 can send an access request containing, for example, a terminal authentication code and other optional data.
This access request is received within the second network 2. For example, this access request can be received by the first node in the second network, and the second node can be selected based on the authentication code received. After this, the received authentication code is transferred from the first node to the selected second node. For example, in the example of Figure 1, the gateway responds to the access request and forwards the required data to the authentication server. As an example, the gateway can determine the appropriate authentication server from this access request, for example the username is user @ provider. If of type com, gateway 200 can forward access requests to the provider's network. For example, in the example of FIG. 1, the gateway 200 can forward the access request to the RADIUS server 220 via the RADIUS proxy 210. The RADIUS proxy 210 may be operated by, for example, the same operator as the gateway 200, and the address and name of the provider's RADIUS server that has an agreement with the gateway operator, as well as the identifier for this provider, such as the username. It may have a string after the symbol "@". The RADIUS proxy 210 can, for example, receive an access request from the gateway 200, determine the associated RADIUS server from the username, and send the access request for the second network 2 to this RADIUS server. The RADIUS server 220 receives this access request and searches the authentication server for which authentication code is assigned to the terminal, for example, based on the IP address of the terminal or the identity of the user of the terminal. The RADIUS server compares the assigned authentication code with the terminal authentication code and sends either an "permit" or "deny" message to the gateway 200. The gateway 200 responds to this message by either permitting or denying access. Communication between gateway 200 and authentication server 112 may not be routed through server 220 (and / or proxy 210), as indicated by the dashed arrow.
If the first network has a different operator than the second network, the second node, in this example the RADIUS server 220, will charge the user of terminal 4 for the use of the second network. , May include a storage device that stores information about the use of the second network by this user. Billing for the second network can be combined with billing for the first network. This reduces the administrative burden by preventing users from being billed by multiple entities.
The assigned authorization code may be, for example, a one-time password (OTP). WLANs are usually installed in public places such as bars, restaurants, train stations, and airports. Therefore, WLAN users are connected to the WLAN for a relatively short time, many different users connect to the WLAN, for example one user on a trip connects to a different WLAN. WLANs are typically operated by a different entity than the party to which the user is subscribed, such as a mobile operator. Therefore, if the authentication code may be used more than once may be provided to the subscriber, the same authentication code this that is input to a number of WLAN or significant security risks by the results, or the user, a very limited number Only WLAN can be used. Therefore, providing OTP reduces security risks and / or increases the number of WLANs that can be used.
The terminal 4 may be provided with means for detecting the presence of a second network. For example, the terminal may include a transmitter / receiver suitable for the second network, the processing unit 43 in the example of FIG. 2 detects a signal received from the second network, and the second network, For example, it may be able to start communication with the gateway 200. If the presence of a second network is detected in this way, the terminal optionally gives user permission to send a request some time after allowing access to the first network. After making a request in the user interface of, terminal 4 can automatically send an access request to the gateway.
The present invention also includes at least a code portion for performing the steps of the method according to the invention when executed on a programmable device such as a computer system, or a programmable device is a device or system according to the invention. It can also be implemented as a computer program for execution on a computer system, which makes it possible to carry out the various functions of. Such computer programs may be provided on a data carrier such as a CD-ROM or diskette that represents the computer program and contains loadable data in the memory of the computer system. The data carrier may also be a data connection such as a telephone cable or wireless connection.
In the present specification described above, the present invention has been described with reference to specific examples of embodiments of the present invention. However, it is clear that various modifications and modifications may be made to the invention without departing from the broader intent and scope of the invention as defined in the appended claims. For example, in the embodiment shown in FIG. 1, the first network 1 may include a UMTS network or the like instead of the GPRS network. Further, the terminal may include, for example, a notebook computer, a personal digital assistant or other suitable device.
Also, the invention is not limited to physical devices or units implemented as non-programmable hardware, but in programmable devices or units that can perform the desired device function by operating according to appropriate program code. It can also be applied. In addition, the device can functionally operate as a single device while being physically distributed over several devices. For example, the access control configuration 5 shown in FIG. 3 may be implemented on separate nodes in the first network 1, for example SGSN100, GGSN110 and authentication server 112 shown in FIG. In addition, each device forming functionally separate devices may be integrated into a single physical device. For example, the RADIUS server 220 and the authentication server 112 may be implemented as a single node in the second network.
The first network may also include any suitable type of mobile telecommunications network, such as a GPRS or UMTS network. Also, one or both of the first network and the second network may be, at least in part, a wireless data network such as a wireless local area network. In addition, the first network may have a separate operator than (a part of) the second network. For example, in the example of FIG. 1, the first part 21 of the second network 2, which includes the gateway 200 and the proxy 210, includes the first network 1 and the RADIUS server 220, as shown by the dashed line in FIG. It may be operated by a different entity than the second part 22 of the second network 2. Similarly, the first network 1 may consist of a first part 11 and a second part 12, but these first part 11 and second part 12 may be operated by different entities. It is possible.
However, other modifications, changes and modifications are possible. Therefore, the specification and drawings should be considered as exemplary rather than limiting.
In the claims, any reference code placed in parentheses should not be construed as limiting the claim. The term "comprising" does not preclude the presence of other elements or steps other than those listed in the claims. Furthermore, the terms "a" and "an" should not be construed as being limited to "only one", but instead should be used to mean "at least one" and be plural. Do not exclude. The fact that some means are described in different claims does not mean that the combination of these means cannot be used advantageously.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10531284B2 | Cited by | United States of America | Applicant |
| US10299112B2 | Cited by | United States of America | Applicant |
| US10104540B2 | Cited by | United States of America | Applicant |
| JP2013521728A | Cited by | Japan | Examiner |
| JP2016509422A | Cited by | Japan | Search report |
| JP5819017B1 | Cited by | Japan | Examiner |
| JP2018125812A | Cited by | Japan | Search report |
| JP2010257079A | Cited by | Japan | Search report |
| JP2014532348A | Cited by | Japan | Examiner |
| JP5819017B1 | Cited by | Japan | Search report |
| JP2016509422A | Cited by | Japan | Search report |
| US11153301B2 | Cited by | United States of America | Applicant |
| JP2016212566A | Cited by | Japan | Search report |
| JP2004070814A | Cites | Japan | Search report |
| JP2004070814A | Cites | Japan | Examiner |
| JP2004153300A | Cites | Japan | Examiner |
| JP2004374359A | Cites | Japan | Search report |
| JP2004374359A | Cites | Japan | Examiner |
| JP2006086772A | Cites | Japan | Search report |
| JP2006086772A | Cites | Japan | Examiner |
14 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 06076259 | European Patent Office (EPO) | A | |
| 06076259 | European Patent Office (EPO) | A | |
| 060762598 | European Patent Office (EPO) | – | |
| 2007050296 | Netherlands (Kingdom of the) | W | |
| 2007050296 | Netherlands (Kingdom of the) | W | |
| 200606076259 | – | – | – |
| 2007050296 | – | – | – |
| EP20060076259 | – | – | – |
| WO2007NL50296 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| EP1871065A1 | European Patent Office (EPO) | A1 | |
| CA2656919A1 | Canada | A1 | |
| WO2007148969A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2039110A1 | European Patent Office (EPO) | A1 | |
| KR20090036562A | Republic of Korea | A | |
| CN101473670A | China | A | |
| US2009282467A1 | United States of America | A1 | |
| JP2009541843AThis record | Japan | A | |
| CN101473670B | China | B | |
| JP5242561B2 | Japan | B2 | |
| US8533798B2 | United States of America | B2 | |
| EP2039110B1 | European Patent Office (EPO) | B1 | |
| KR101401190B1 | Republic of Korea | B1 | |
| CA2656919C | Canada | C |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2009541843
- Publication, DOCDB
- 2009541843
- Publication, EPODOC
- JP2009541843
- Application
- 2009516418
- Application, DOCDB
- 2009516418
- Application, EPODOC
- JP20090516418
Titles2
- Japanese
- ネットワークへのアクセスを制御するための方法およびシステム
- English
- Methods and systems for controlling access to the network
Classification
- CPC, 7
- H04L63/10
- H04W12/08
- H04L63/08
- H04L63/18
- H04W88/04
- H04L63/0838
- H04W12/06
- IPC, 9
- G06F21 20
- H04W88 06
- H04W48 18
- H04W12 06
- G06F21 33
- G06F21 34
- G06F21 42
- G06F21 44
- H04W88 04
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo