Methods and apparatuses to perform secure registration of femto access points in operator controlled network
Abstract
Methods, devices, and systems for performing secure registration of femto access points for trusted access to operator-controlled network elements. Method Steps include establishing a security relationship for at least one femto access point and using this security relationship to request operator-controlled network elements. It requires a secure registration credential from the authorization component. The operator-controlled network element builds a secure registration credential and sends the secure registration credential to the requesting femto access point. This allows the requesting femto access point to have trusted access to operator-controlled network elements. The embodiment includes establishing a security relationship with an IPsec security relationship received from the security gateway. The security gateway is in the operator control area and uses a database of operator control IPsec internal addresses. In some embodiments, the femto access point performs a message exchange using one or more IMP protocols and components including call session control functional elements. The call session control functional element can allow femto access points in the IMS domain and ask for permission to access non-IMS network elements.
Term
3.2 yearsto projected expiry
Projected expiry 25 November 2029, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
50 claims: 6 independent, 44 dependent
- 1オペレータ制御型ネットワーク要素へのアクセスのために、フェムト・アクセス・ポイントの安全な登録を実行する方法であって、 少なくとも1つのフェムト・アクセス・ポイントのためのセキュリティ関係を確立することと、 前記セキュリティ関係を用いて、前記少なくとも1つのフェムト・アクセス・ポイントから、安全な登録信用証明を要求することと、 前記安全な登録信用証明を、少なくとも1つの許可構成要素によって構築することと、 前記フェムト・アクセス・ポイントにおいて、オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録信用証明を受信することとを備える方法。
- 2前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)から受信されたIPsecセキュリティ関係によって確立される請求項1に記載の方法。
- 3前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項1に記載の方法。
- 4前記セキュリティ関係を確立することは、IPsec内部アドレスの少なくとも1つのオペレータ制御データベースを用いて実行される請求項1に記載の方法。
- 5前記少なくとも1つのフェムト・アクセス・ポイントから、登録を要求することは、SIPメッセージを用いて登録を要求することを含む請求項1に記載の方法。
- 6前記要求された登録の許可が、コール・セッション制御機能(CSCF)要素と連携して実行される請求項1に記載の方法。
- 7前記少なくとも1つのオペレータ制御型ネットワーク要素が、フェムト・アクセス・ポイント・プロファイルを、少なくとも1つのホーム加入者サーバ(HSS)と交換する請求項6に記載の方法。
- 8前記少なくとも1つのオペレータ制御型ネットワーク要素は、フェムト・アクセス・ポイント・プロフィールを、少なくとも1つの許可構成要素と交換する請求項6に記載の方法。
- 9前記要求された登録の許可が、CSCF要素の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項1に記載の方法。
- 10前記オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録を受信することとは、SIP OKメッセージを受信することを含む請求項1に記載の方法。
- 11アクセス端末からのアクセス要求を中継することをさらに備える請求項1に記載の方法。
- 12前記中継されるアクセス要求は、SIPメッセージを用いて中継される請求項11に記載の方法。
- 13前記中継されるアクセス要求は、完全に保護されたインジケーションを含む請求項11に記載の方法。
- 14オペレータ制御型ネットワーク要素へのアクセスのために、フェムト・アクセス・ポイントの安全な登録を実行する通信システムであって、 前記オペレータ制御型ネットワーク内のIPsecアドレス・データセットを管理するように構成されたセキュリティ・ゲートウェイ要素と、 前記セキュリティ・ゲートウェイ要素からセキュリティ関係を要求するように構成され、安全な登録信用証明を要求するように構成された少なくとも1つのフェムト・アクセス・ポイントと、 前記要求された安全な登録信用証明を構築し、前記要求された安全な登録信用証明を格納するように構成され、前記要求された安全な登録信用証明を前記フェムト・アクセス・ポイントへ送信するように構成された少なくとも1つのオペレータ制御型ネットワーク要素とを備える通信システム。
- 15前記セキュリティ・ゲートウェイ要素は、セキュリティ・ゲートウェイの機能を実行する第2のオペレータ制御型ネットワーク要素である請求項14に記載の通信システム。
- 16前記IPsecアドレス・データセットは、IPsec内部アドレスのオペレータ制御データベースを含む請求項14に記載の通信システム。
- 17前記少なくとも1つのフェムト・アクセス・ポイントは、SIPメッセージを用いて、安全な登録信用証明を要求するように構成された請求項14に記載の通信システム。
- 18前記要求された安全な登録信用証明を前記フェムト・アクセス・ポイントへ送信することは、コール・セッション制御機能(CSCF)要素と連携して実行される請求項14に記載の通信システム。
- 19前記少なくとも1つのオペレータ制御型ネットワーク要素が、フェムト・アクセス・ポイント・プロファイルを、少なくとも1つのホーム加入者サーバ(HSS)と交換する請求項14に記載の通信システム。
- 20前記少なくとも1つのオペレータ制御型ネットワーク要素は、フェムト・アクセス・ポイント・プロフィールを、少なくとも1つの許可構成要素と交換する請求項14に記載の通信システム。
- 21前記安全な登録信用証書を要求することは、SIPメッセージを用いて実行される請求項14に記載の通信システム。
- 22前記中継されるアクセス要求は、完全に保護されたインジケーションを含む請求項14に記載の通信システム。
- 23前記オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録を受信することとは、SIP OKメッセージを受信することを含む請求項14に記載の通信システム。
- 24オペレータ制御型ネットワーク要素へのアクセスのために、フェムト・アクセス・ポイントの安全な登録を実行する方法を組み込んだ有形のコンピュータ読取可能媒体であって、 前記方法は、 少なくとも1つのフェムト・アクセス・ポイントのためのセキュリティ関係を確立することと、 前記セキュリティ関係を用いて、前記少なくとも1つのフェムト・アクセス・ポイントから、安全な登録信用証明を要求することと、 前記安全な登録信用証明を、少なくとも1つの許可構成要素によって構築することと、 前記フェムト・アクセス・ポイントにおいて、オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録信用証明を受信することとを備える有形のコンピュータ読取可能媒体。
- 25前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)から受信されたIPsecセキュリティ関係によって確立される請求項24に記載の有形のコンピュータ読取可能媒体。
- 26前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項24に記載の有形のコンピュータ読取可能媒体。
- 27前記セキュリティ関係を確立することは、IPsec内部アドレスの少なくとも1つのオペレータ制御データベースを用いて実行される請求項24に記載の有形のコンピュータ読取可能媒体。
- 28前記少なくとも1つのフェムト・アクセス・ポイントから、登録を要求することは、SIPメッセージを用いて登録を要求することを含む請求項24に記載の有形のコンピュータ読取可能媒体。
- 29前記要求された登録の許可が、コール・セッション制御機能(CSCF)要素と連携して実行される請求項24に記載の有形のコンピュータ読取可能媒体。
- 30前記少なくとも1つのオペレータ制御型ネットワーク要素が、フェムト・アクセス・ポイント・プロファイルを、少なくとも1つのホーム加入者サーバ(HSS)と交換する請求項24に記載の有形のコンピュータ読取可能媒体。
- 31前記要求された登録の許可が、CSCF要素の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項24に記載の有形のコンピュータ読取可能媒体。
- 32前記オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録を受信することとは、SIP OKメッセージを受信することを含む請求項24に記載の有形のコンピュータ読取可能媒体。
- 33アクセス端末からのアクセス要求を中継することをさらに備える請求項24に記載の有形のコンピュータ読取可能媒体。
- 34オペレータ制御型ネットワーク要素へのアクセスのために、フェムト・アクセス・ポイントの安全な登録を実行する装置であって、 少なくとも1つのフェムト・アクセス・ポイントのためのセキュリティ関係を確立する手段と、 前記セキュリティ関係を用いて、前記少なくとも1つのフェムト・アクセス・ポイントから、安全な登録信用証明を要求する手段と、 前記安全な登録信用証明を、少なくとも1つの許可構成要素によって構築する手段と、 前記フェムト・アクセス・ポイントにおいて、前記オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録信用証明を受信する手段とを備える装置。
- 35前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)から受信されたIPsecセキュリティ関係によって確立される請求項34に記載の装置。
- 36前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項34に記載の装置。
- 37前記セキュリティ関係を確立することは、IPsec内部アドレスの少なくとも1つのオペレータ制御データベースを用いて実行される請求項34に記載の装置。
- 38前記少なくとも1つのフェムト・アクセス・ポイントから、登録を要求することは、SIPメッセージを用いて登録を要求することを含む請求項34に記載の装置。
- 39前記要求された登録の許可が、コール・セッション制御機能(CSCF)要素と連携して実行される請求項34に記載の装置。
- 40前記少なくとも1つのオペレータ制御型ネットワーク要素が、フェムト・アクセス・ポイント・プロファイルを、少なくとも1つのホーム加入者サーバ(HSS)と交換する請求項34に記載の装置。
- 41前記少なくとも1つのオペレータ制御型ネットワーク要素は、フェムト・アクセス・ポイント・プロフィールを、少なくとも1つの許可構成要素と交換する請求項34に記載の装置。
- 42前記要求された登録の許可が、CSCF要素の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項34に記載の装置。
- 43前記オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録を受信することとは、SIP OKメッセージを受信することを含む請求項34に記載の装置。
- 44アクセス端末からのアクセス要求を中継することをさらに備える請求項34に記載の装置。
- 45オペレータ制御型ネットワーク要素への安全なアクセスのためのフェムト・アクセス・ポイントであって、 少なくとも1つのフェムト・アクセス・ポイントのためのセキュリティ関係を確立することと、 前記セキュリティ関係を用いて、安全な登録信用証明を要求することと、 前記フェムト・アクセス・ポイントにおいて、オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録信用証明を受信することと、のためのメモリおよび少なくとも1つのプロセッサを備えるフェムト・アクセス・ポイント。
- 46前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)から受信されたIPsecセキュリティ関係によって確立される請求項45に記載のフェムト・アクセス・ポイント。
- 47前記セキュリティ関係を確立することは、セキュリティ・ゲートウェイ(SeGW)の機能を実行する少なくとも1つのオペレータ制御型ネットワーク要素と連携して実行される請求項45に記載のフェムト・アクセス・ポイント。
- 48前記セキュリティ関係を確立することは、IPsec内部アドレスの少なくとも1つのオペレータ制御データベースを用いて実行される請求項45に記載のフェムト・アクセス・ポイント。
- 49前記少なくとも1つのフェムト・アクセス・ポイントから、登録を要求することは、SIPメッセージを用いて登録を要求することを含む請求項45に記載のフェムト・アクセス・ポイント。
- 50コンピュータ読取可能媒体を備えるコンピュータ・プログラム製品であって、 前記コンピュータ読取可能媒体は、 少なくとも1つのコンピュータに対して、少なくとも1つのフェムト・アクセス・ポイントのためのセキュリティ関係を確立させるためのコードと、 少なくとも1つのコンピュータに対して、前記セキュリティ関係を用いて、前記少なくとも1つのフェムト・アクセス・ポイントから、安全な登録信用証明を要求させるためのコードと、 少なくとも1つのコンピュータに対して、前記安全な登録信用証明を、少なくとも1つの許可構成要素によって構築させるためのコードと、 少なくとも1つのコンピュータに対して、前記フェムト・アクセス・ポイントにおいて、オペレータ制御型ネットワーク要素へのアクセスのため、前記安全な登録信用証明を受信させるためのコードとを備えるコンピュータ・プログラム製品。
Independent claims50
117 paragraphs, as filed
Priority claim
The patented invention claims priority over US Provisional Application No. 61 / 118,397 filed on November 26, 2008, which has been assigned to the assignee of the present application and is expressly incorporated herein by reference.
The following disclosures generally relate to wireless communications, and more particularly to the secure registration of femto access points.
Historically, telephone communications (ie, land lines) have been made possible using circuit-switched infrastructure operated by telephone companies. In contrast, mobile phone systems (ie, mobile phones) have been made possible using packet-switched infrastructure operated by mobile operator companies. With the development of mobile telephone communications, such mobile telephone communication systems use packet-switched infrastructure for edge communications and circuit-switched infrastructure to achieve long-distance calls. As mobile communication systems become more and more popular and mobile communication systems offer more services (eg multimedia capabilities, sophisticated voice capabilities, video conferencing, etc.), applications are in packet-switched infrastructure. There is a tendency towards more features suitable for. In addition, more and more devices have been developed that connect to packet-switched networks, such as femtocells, including femtocells deployed by users. At the same time, more and more services (eg multimedia services, low-cost long-distance calls, etc.) have relatively more packet-switched network infrastructures (eg, Internet networks and other IP-based networks). It is possible using.
This trend creates an environment in which more of these infrastructures are deployed under the control of entities other than telephone system operators. Therefore, new security issues (eg, secure registration of femtocells mentioned above) have become important.
The following is a simplified overview of such aspects to give a basic understanding of one or more aspects. This overview is not an extensive overview of all possible aspects, nor is it intended to identify the key or deterministic elements of all aspects, nor to delineate the scope of any or all aspects. Its sole purpose is to represent some notions of one or more aspects in a simplified form as a prelude to the more detailed description presented below.
Methods, devices, and systems for performing secure registration of femto access points for trusted access to operator-controlled network elements are disclosed. Method Steps include establishing a security relationship for at least one femto access point and making requests to operator-controlled network elements using the security relationship. The operator-controlled network element then builds a secure registration credential and sends this secure registration credential to the requesting femto access point. This allows trusted access by the requesting femto access point to access the operator-controlled network element. The embodiment includes establishing a security relationship with an IPsec security relationship received from the security gateway. The security gateway is in the operator control area and uses the operator control database of IPsec internal addresses. In some embodiments, the femto access point performs a message exchange using components including call session control functional elements and one or more IMS protocols and components. These components allow femto access points within the IMS domain. It may or may not access non-IMS network elements for permission.
In order to achieve the above-mentioned objects and related objects, the embodiments of the present invention are fully described below, and are particularly pointed out in the claims. The following description and accompanying drawings describe in detail an exemplary embodiment with one or more embodiments. However, these embodiments show only a few of the various schemes to which the principles of the various embodiments can be applied, and the embodiments described refer to such embodiments and their equivalents. Intended to include.
The features, properties, and advantages of the present disclosure, when combined with the accompanying drawings, will become more apparent from the detailed description below.<figref num="1">FIG. 1 illustrates a multiple access wireless communication system according to one embodiment of the present invention.</figref><figref num="2">FIG. 2 is a block diagram of a transmitter system and a receiver system according to one embodiment of the present invention.</figref><figref num="3">FIG. 3 shows a communication system for enabling the deployment of femto access points in a network environment according to one embodiment of the present invention.</figref><figref num="4">FIG. 4 is an IMS environment in which the establishment of secure registration of femto access points is realized according to one embodiment of the present invention.</figref><figref num="5">FIG. 5 is an IMS system that includes components for establishing secure registration of femto access points according to one embodiment of the invention.</figref><figref num="6">FIG. 6 shows a system for establishing secure registration of femto access points according to one embodiment of the invention.</figref><figref num="7">FIG. 7 is a flow diagram of the process used to perform secure registration of a femto access point according to one embodiment of the invention.</figref><figref num="8">FIG. 8 is a flow chart of the process used to guarantee the registered credential of a femto access point according to one embodiment of the invention.</figref><figref num="9">FIG. 9 is a flow diagram of performing a check for existing / current / valid authorization for secure registration of a femto access point according to one embodiment of the invention.</figref><figref num="10">FIG. 10 is a protocol diagram illustrating a messaging protocol for performing secure registration of femto access points using a centralized server in an IMS environment according to one embodiment of the present invention.</figref><figref num="11">FIG. 11 is a protocol diagram illustrating a messaging protocol for performing secure registration of femto access points within a complete IMS environment according to one embodiment of the invention.</figref><figref num="12">FIG. 12 illustrates a block diagram of a system for secure registration of femto access points for access to operator-controlled network elements according to one embodiment of the invention.</figref><figref num="13">13, according to one embodiment of the present invention, a femto access point for access to an operator-controlled network element to perform secure registration of bets, executes a communication system functions The block diagram of the system is illustrated.</figref><figref num="14">FIG. 14 is a block diagram of a device that performs secure registration of femto access points for accessing operator-controlled network elements using hardware and software means according to one embodiment of the invention. Shown.</figref><figref num="15">FIG. 15 shows a block diagram of a system that performs a function with a femto access point according to one embodiment of the invention.</figref>
Various aspects are described throughout with reference to drawings in which the same reference numerals are used to refer to the same elements. In the following description, for the purposes of explanation, many specific details are given to provide a complete understanding of one or more aspects. However, it is clear that such an embodiment can be realized without these specific details. In other cases, well-known configurations and devices are shown in block diagram format to facilitate the description of one or more embodiments.
In addition, various aspects of the disclosure are described below. It should be clear that the teachings described herein can be embodied in a wide range of forms, and that any specific configuration and / or function described herein is merely representative. Is. Based on the teachings herein, one of ordinary skill in the art can implement the embodiments disclosed herein independently of any other embodiment, and a plurality of these embodiments may be performed in various ways. It should be recognized that they can be combined. For example, the device can be implemented and / or the method can be implemented using any number of aspects described herein. Further, the device is implemented and / or the method is realized in addition to or with one or more of the aspects described herein, or with different configurations and / or functions. sell. As an example, many of the methods, devices, systems and devices described herein are systems for performing secure registration of femto access points in a wireless environment with another deployment of femto access points. Described in the context of implementing. Those skilled in the art should recognize that similar techniques are applicable to other communication environments.
Wireless communication systems have been widely developed to provide various types of communication content such as voice, data and the like. These systems can be multiple access systems that can support communication with multiple users by sharing available system resources (eg, bandwidth and transmit power). Examples of such multiple access systems are code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, 3GPP long term evolution (LTE) systems, and Includes orthogonal frequency division multiple access (OFDMA) systems and the like.
For example, traditional fixed-line communication systems such as Digital Subscriber Line (DSL), cable lines, dial-up networks, or similar connections provided by Internet Service Providers (ISPs) are two parties. It is an alternative and often competes with communication platforms for wireless communications. However, in recent years, users have begun to replace fixed-line communications with mobile communications. Some advantages of mobile communication systems, such as user movement, relatively small user equipment (UE), easy access to the Internet as well as public exchange telephone networks, make this system very convenient, thereby making this system very convenient. Made it very common. Users are increasingly relying on mobile systems for communication services traditionally obtained through fixed-line systems, increasing the demand for increased bandwidth, reliable services, high voice quality, and low prices.
In general, a wireless multiple access communication system can support communication for a plurality of wireless terminals at the same time. Each terminal can communicate with one or more base stations via forward and reverse link transmissions. A forward link (ie, downlink) refers to a communication link from a base station to a terminal, and a reverse link (ie, uplink) refers to a communication link from a terminal to a base station. This communication link can be established by a single input single output system, a multiple input single output system, or a multiple input multiple output (MIMO) system.
In addition to the mobile phone networks currently in use, a new class of small base stations has emerged. These small base stations are low power and generally utilize fixed line communication to connect to the network operator's core network. In addition, these base stations can be distributed for personal / private use in homes, offices, apartments, and private recreational facilities to provide mobile units with indoor / outdoor wireless effective coverage. These personal base stations are commonly known as femtocells, personal femto access points, access points, home node B units (HNB), or home evolved enode B units (HeNB). .. Generally, such small base stations are connected to the Internet and operator networks via DSL routers or cable modems. Femtocell base stations offer a new paradigm for mobile network connectivity. This allows direct subscriber control of access quality and mobile network access.
With the development of various types of wireless access points for communication networks (eg, public landline mobile networks (PLMN), network operators, mobile operator core networks, etc.), traditional wireless communication systems and traditional wireless communication systems One solution has been obtained to enable the effective communication range to and from the fixed line communication system. An effective communication range, also known as a fixed wireless effective communication range, includes the degree of interoperability between a fixed line network (eg, an intranet, the Internet, etc.) and a mobile communication network (eg, a cellular telephone network). A femto access point as described herein includes any suitable node, router, switch, hub, etc. configured to communicatively connect an access terminal (AT) to a communication network. Femto access points are wired (eg, such as Ethernet®, Universal Serial Bus (USB), or other wired connections for communication), radio signals (eg, for communication). Can be wireless, or both. Examples of femto access points are access point base stations (BS), wireless local area network (WLAN) access points, and worldwide interoperability for microwave access (WiMAX) BS. Includes wireless wide area network (WWAN) access points and the like. Femto access points are communications such as mobile communication operator networks, circuit-switched voice networks, circuit-switched and packet-switched voice and data networks (or full-packet voice and data networks), and the like. It has an access point to the operator network. Examples of femto access points are node B (NB), base transceiver stations of various transmit power / cell sizes, including macro cells, micro cells, pico cells, femto cells, etc. BTS) Includes Home Node B (Home Node B, Home Node B, HNB), Home Evolved eNodeB (HeNB), or simply BS. Consistent with the trends described above, the continuous deployment of femtocells is expected to have more and more IP Multimedia Subsystem (IMS) -based capabilities. Therefore, a femto access point may include sufficient IMS functionality as described as an IMS client femto access point.
Introducing various types of femto access points into traditional macro BS networks allows for consumer control and significant flexibility with personal access to such networks. User terminals can often be configured to select a nearby femto access point or macro network BS, depending on which provider provides the good signal and / or other factors. Moreover, in at least some environments, femto access points offer a better rate plan compared to macro networks, which allows users to reduce usage fees.
As wireless communication bandwidth and data rates have increased over time, and AT processing and user interface capabilities have become more sophisticated, users were previously only available for personal computer and fixed line communications. A mobile device can be utilized to perform the function.
However, because common macro networks are often deployed in large public use as a major market, indoor reception is often (eg, by absorption of radio frequency signals by buildings, insulators, groundscapes, etc.). ) Poorer than outdoor reception, making mobile devices less efficient than fixed-line computers in such environments. However, the femto access point BS can provide significant improvements in this environment. As an example, HNB and HeNB technologies (collectively referred to as HNB) provide users with outstanding control via personal wireless connections indoors and outdoors. This often eliminates almost or all connection problems. Therefore, HNB can further extend AT mobility even in suboptimal environments for macro networks.
Opportunities for new services have arisen, along with the significant benefits of HNB and other access point deployments, and some problems have arisen with the new services. For example, mobile cellular services depend on internet content (eg, news, images, videos, etc.) and / or are enabled by internet applications (real-time location services, online games, etc.). Continue to extend voice services (eg, phone calls, voicemail, etc.) and text services (eg, SMS) to include services. In some situations, mobile user terminals (ATs) may use only Internet Protocol (IP) networks to provide services without participating in the mobile operator core infrastructure. it can. Mobile operator communication service provision applies more IP technology, so the overall service provision is concentrated. Centralized communications services have become universally available on a variety of increasingly autonomous devices (eg, ATs, PDAs, smartphones, and laptops).
In some cases, a session to run an application is started and completely terminated without using the mobile operator's core network infrastructure. In other cases, the application may be downloaded and installed on an autonomous device. For example, an application that conforms to the IMS Centralized Services specification establishes a peer-to-peer session, performs some protocol embodiments of the application, exchanges multimedia content, and has a peer-to-peer session. Close.
IMS was originally considered part of the 3rd Generation Partnership Program (3GPP) specification for 3rd Generation (3G) Cell Telephone Networks. The 3rd Generation Partnership Planning Specification can define the characteristics of IMS to provide new services and applications to 3G cell phone users. Part of this specification ensures that IMS is independent of the access network so that network operators can offer new services through different types of radio interfaces and different types of cell phones.
For example, Concentration deals with many technical and deployment issues, including security, roaming, and quality of service (QoS). Of these, aspects of managing security are shown herein. Security protocols attempt to ensure proper user authentication, authorization, and privacy. In some embodiments, the user's access terminal is authenticated (ie, by a sign-in procedure), and this authentication is used to access the range of services the user has access to.
Of course, any network-oriented authentication and / or authorization procedure compromises credential (eg, credential cloning), malicious attacks (eg, configuration attacks, fake software updates), and Malicious protocol attacks (eg, intervener attacks), denial of service attacks, attacks on user and network operator identity (eg, spoofed SIP messages like INVITE or BYE), and any specific attack. Responsible protocols (eg SAE / TLE) Exposed to threats, including network use of TS33.401) or user privacy (eg, stealing) attacks associated with deployment concepts (eg, closed subscriber group concepts), or many other attacks. There is. Therefore, network operators can use countermeasures to remove such threats. Some typical countermeasures are mutual authentication technology, security tunnel establishment for backhaul links, use of trusted environmental technology inside network components, and operation, authentication, and maintenance (OAM). Includes security mechanisms for, host party authentication technology, etc.
In 3GPP network infrastructure deployments, femto access point deployments are generally unplanned or only partially planned. This means that the femto access point is installed outside the control of the network operator. Therefore, operators have limited capacity to achieve secure deployment of these femto access points. Femto access points are deployed in unsafe physical locations and are therefore physically exposed to malicious intent. Revisiting the security threats involved in the deployment of femto access points, femto access points provide network services (eg, GSM® services, UMTS, CDMA2000, circuit-switched services, etc.). IETF RFC 3261 specification, 3GPP and 3GPP2 to register itself in the operator's network to provide You can use the Session Initiation Protocol (SIP) procedure specified in the IMS specification. There is a secure way to register such femto access points to the network to ensure that these procedures are not being abused by femto access points deployed in insecure physical locations. Needed.
For illustrative purposes, the following paragraphs introduce terms used to describe embodiments of the present invention.
As is known in the art, according to various embodiments of the present invention, the AT can communicate mobile station identification information (MSID). If the AT has more than one identification, the user or AT selects the specific mobile station identification (user-controlled or autonomously by the AT) that should be valid during the session. The MSID can be either the Mobile Identity Number (MIN) or the International Mobile Bureau Identity (IMSI). The mobile identification number is a 34-bit number that is a digital display of the 10-digit number assigned to the mobile station. International mobile station identification information is a number of up to 15 digits in length that uniquely identifies a mobile station internationally.
The techniques described herein include, for example, code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), SC-FDMA (single carrier FDMA). ), And can be used for various wireless communication systems such as other systems. The terms "system" and "network" are often used interchangeably. CDMA systems can implement radio technologies such as Universal Terrestrial Radio Access (UTRA), CDMA2000, and the like. UTRA includes wideband CDMA (W-CDMA) and other variants of CDMA. CDMA2000 covers IS-2000, IS-95, and IS-856 standards. TDMA systems can implement wireless technologies such as the Global Mobile Communication System (GSM). OFDMA systems include, for example, Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE. Radio technologies such as 802.20, Flash-OFDM.RTM, etc. can be realized. UTRA, E-UTRA, and GSM are part of the Universal Mobile Telecommunications System (UMTS). Long Term Evolution (LTE) is the latest release of UMTS using E-UTRA, which applies OFDMA on the downlink and SC-FDMA on the uplink. UTRA, E-UTRA, UMTS, LTE, and GSM are described in documents from an organization named "3rd Generation Partnership Planning Project" (3GPP). CDMA2000 and UMB are documented by an organization named "3rd Generation Partnership Planning Project" (3GPP2).
Single Carrier Frequency Division Multiple Access (SC-FDMA), which utilizes single carrier modulation and frequency domain equalization, has performance comparable to that of an OFDMA system and has substantially the same overall complexity. It is a technology. SC-FDMA signals have a lower average peak-to-power ratio (PAPR) due to their unique single carrier structure. SC-FDMA has received a great deal of attention, especially in uplink communications, where low PAPR is of great benefit to mobile devices in terms of transmission power efficiency. This is currently the premise of operation for uplink multiple access schemes in 3GPP Long Term Evolution (LTE) or Evolved UTRA.
As used in the subject matter disclosure, terms such as "component", "system", "module" are hardware, software, running software, firmware, middleware, microcode, and / or, It is intended to refer to a computer-related entity that is any combination of these. For example, a module can be, but is not limited to, a process, an object, an executable, an execution thread, a program, a device, and / or a computer running on a processor. One or more modules reside within a process and / or execution thread, and modules can be localized on one electronic device and / or distributed among multiple electronic devices. In addition, these modules may be executable from a variety of computer-readable media with different stored data structures. These modules interact with other components, for example, one or more data packets (eg, local systems or distributed systems, and / or other systems by signal, such as the Internet. It can communicate by local and / or remote processing according to a signal (data from one component that interacts with another component) over a network that interacts with. In addition, the components or modules of the system described herein are further configured to facilitate achieving various aspects, goals, benefits, etc. as described in connection with this specification. Can be rebuilt and / or supplemented by elements / modules / systems. These are not limited to the exact configurations described in the given drawings, as will be appreciated by those skilled in the art.
In addition, various aspects are described herein in the context of access terminals. AT is a system, subscriber unit, subscriber station, mobile station, mobile communication device, mobile device, remote station, remote terminal, access terminal (AT), user agent (UA), user device, user device ( Also called UE) etc. Subscriber stations include cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless connectivity, or wireless modems. It can be another processing device connected to a similar mechanism that facilitates wireless communication with the processing device.
As used herein, the computer storage medium can be any physical medium that can be accessed by a computer. By way of example, but not limited to, such storage media include RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage, smart cards, and flash. Can be used to transmit or store program code in the form of memory devices (eg, cards, sticks, key drives, etc.), or instructions or data structures, and accessible by a computer. Any other suitable medium may be provided. Hardware communication media include data connections or any suitable device that facilitates the transfer of computer programs from one entity to another, at least electronic hardware, mechanical hardware, and / or. , Using electromechanical hardware. In general, data connections are also well referred to as computer readable media. For example, programs, software, or other data can be coaxial cables, fiber optic cables, twisted pairs, digital subscriber lines (DSL), communication bus structures, Ethernet®, or infrared, wireless, or microwave. When transmitted from websites, servers, or other remote sources using wireless technology such as coaxial cable, fiber optic cable, twist pair, DSL, or wireless technology such as infrared, wireless or microwave, Any suitable hardware component associated with such a medium is included in the definition of the medium and is included in the definition of the hardware communication medium. Disks (disk and disc) as used herein include compact discs (CDs), laser discs, optical discs, DVDs, floppy® discs and blue ray discs. Normally, disk magnetically reproduces data, and disc uses a laser to light the data. Regenerate scientifically. The above combinations should also be included within the range of computer readable media.
When implemented in hardware, the various exemplary logics, logic blocks, modules, and circuits of a processing unit described with respect to aspects disclosed herein are one or more application specific ICs (ASICs). Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Discrete Gate or Transistor Logic, Discrete Hardware Components, General Purpose Processor , Controllers, microcontrollers, microprocessors, other electronic units designed to perform the functions described herein, or combinations thereof. Although a microprocessor can be used as a general-purpose processor, a conventional processor, controller, microcontroller, or sequential circuit can be used instead. Processors can also be implemented as, for example, a combination of DSP and microprocessor, multiple microprocessors, one or more microprocessors associated with a DSP core, or a combination of computing devices such as any other suitable configuration. Can be done. In addition, at least one processor may include one or more modules that can operate to perform one or more of the steps or operations described herein.
In addition, the various aspects or features described herein can be realized as methods, devices, or manufactured articles using standard programming and / or engineering techniques. In addition, the steps and / or operations of the methods or algorithms described with respect to the aspects disclosed herein are specific in hardware, directly by a processor-executable software module, or in combination of the two. Can be transformed. Moreover, in some embodiments, the steps and / or actions of the method or algorithm can be incorporated into a computer program product with a device-readable medium, a machine-readable medium, and / or a set of instructions on the computer-readable medium and / Or can exist as at least one of the codes or any combination or set. As used herein, the term "manufactured article" is intended to include a computer program accessible from any computer-readable device or medium.
In addition, the term "typical" is used herein to mean serve as an example, an example, or an example. Any aspect or design described herein as "typical" need not necessarily be construed as favorable or advantageous over other aspects or designs. Rather, the use of the term typical is intended to embody the concept. As used herein and in the claims, the term "or" is intended to mean a comprehensive "or" rather than an exclusive "or". That is, "X applies A or B" is intended to mean one of the natural inclusive replacements, if not specified in the context or not apparent from the context. There is. That is, if X applies A, X applies B, or X applies both A and B, then "X applies A or B" is one of the above examples. Satisfied under. In addition, the articles "a" and "an" used herein and in the claims are generally "1" unless otherwise specified or when it is not clear from the context that they mean the singular. Or should be interpreted to mean "plurality".
With reference to FIG. 1, a multiple access wireless communication system 100 according to one embodiment is illustrated. Femto access point 102 (AP) contains multiple antenna groups. Here, one antenna group includes antennas 104, 106, another antenna group includes antennas 108, 110, and yet another antenna group includes antennas 112, 114. In Figure 1, only two antennas are shown for each antenna group. However, more or less antennas may be used for each antenna group. The access terminal 116 (AT) communicates with the antennas 112 and 114. Here, the antennas 112 and 114 transmit information to the access terminal 116 on the forward link 120 and receive information from the access terminal 116 on the reverse link 118. The access terminal 122 communicates with the antennas 106 and 108. Here, the antennas 106 and 108 transmit information to the access terminal 122 at the forward link 126 and receive information from the access terminal 122 at the reverse link 124. In frequency division duplex (FDD) systems, communication links 118, 120, 124, 126 may use different frequencies for communication. For example, the forward link 120 may use a different frequency than that used by the reverse link 118.
Each group of areas and / or antennas designed to communicate is often referred to as the femto access point sector. In the embodiment of FIG. 1, each antenna group is designed to communicate with access terminals within a sector of the area covered by the femto access point 102.
In communication over forward links 120, 126, the transmitting antenna at femto access point 102 uses beamforming to improve the signal-to-noise ratio of the forward links at another access terminal 116, 122. In addition, a femto access point that uses beamforming to transmit to access terminals that are randomly scattered over the effective communication range is a femto that transmits to all access terminals with a single antenna. It causes less interference with access terminals in neighboring cells than access points.
A femto access point may be a fixed station used to communicate with a terminal and is referred to by the access point, node B, evolved node B (eNB), or some other term. Access terminals can also be referred to as user equipment (UE), wireless communication devices, terminals. Alternatively, the access terminal may be referred to by a term that is consistent with some other terminology.
FIG. 2 is a block diagram of an embodiment of a transmitter system 210 (also known as a femto access point) and a receiver system 250 (also known as an access terminal) in MIMO system 200. In transmitter system 210, traffic data for many data streams is provided from the data source 212 to the transmit (TX) data processor 214.
In an embodiment, each data stream is transmitted through its respective transmitting antenna. The TX data processor 214 formats the traffic data stream for each data stream, encodes, interleaves, and encodes based on the specific coding scheme selected for this data stream. Provide data.
The encoded data in each data stream can be multiplexed with pilot data using OFDM technology. Pilot data is generally a known data pattern that is processed in a known way and can be used in the receiver system to estimate the channel response. The multiplexed pilot and encoded data for each data stream will then be selected for a particular modulation scheme (eg, BPSK, QSPK, M-PSK, etc.) for the data stream to provide modulation symbols. Or it is modulated (ie, symbol-mapped) based on M-QAM). The data rate, coding, and modulation for each data stream can be determined by a set of instructions executed by processor 230 using memory 232.
Modulation symbols for all data streams are then provided to the TX MIMO processor 220. The TX MIMO processor 220 also processes modulation symbols (eg for OFDM). The TX MIMO processor 220 then N<sub>T</sub>N modulation symbol streams<sub>T</sub>Provided to a number of transmitters (TMTR) 222a-222t. In one embodiment, the TX MIMO processor 220 applies beamforming weights to a symbol of the data stream and to the antenna on which the symbol is transmitted.
Each transceiver 222 receives its respective symbol stream and processes these symbol streams to provide one or more analog signals. In addition, these analog signals are tuned (eg, amplified, filtered, and up-converted) to provide the appropriate modulated signal for transmission over MIMO channels. N from transceivers 222a-222t<sub>T</sub>The modulated signals are then N<sub>T</sub>It is transmitted from each of the antennas 224a to 224t.
In receiver system 250, the modulated and transmitted signal is N<sub>R</sub>The signal received by the antennas 252a to 252r and received from each antenna 252 is provided to the respective receivers (RCVR) 254a to 254r. Each receiver 254 tunes (eg, filters, amplifies, and downconverts) each received signal and digitizes the tuned signal to provide a sample. In addition, these samples are processed to provide the corresponding "received" symbol stream.
RX data processor 260 is N<sub>R</sub>Receivers 254 to N<sub>R</sub>Receive N symbol streams and process these received symbol streams based on specific receiver processing techniques.<sub>T</sub>Provides a stream of "detected" symbols. The RX data processor 260 further demodulates, deinterleaves, and decodes each detected symbol stream to restore the traffic data in the data stream. The processing by the RX data processor 260 is complementary to that performed by the TX MIMO processor 220 and the TX data processor 214 in the transmitter system 210.
Processor 270 uses memory 272 to periodically determine which pre-coded matrix (discussed below) to use. Further, the processor 270 can specify a reverse link message having a matrix index part and a rank value part.
Reverse link messages can contain different types of information about communication links and / or received data streams. The reverse link message is then processed by the TX data processor 238, tuned by transmitters 254a to 254r, and sent back to transmitter system 210. The TX data processor 238 also receives traffic data from the data source 236 for many data streams modulated by the modulator 280.
In the transmitter system 210, the modulated signal from the receiver system 250 is received by the antenna 224, tuned by the transceiver 222, demodulated by the demodulator 240, and processed by the RX data processor 242 to process the receiver system. The reverse link message sent by 250 is extracted. Processor 230 then determines which pre-coded matrix to use to determine the beamforming weights and processes the extracted message.
In aspects, logical channels are classified into control channels and traffic channels. The logical control channel includes a broadcast control channel (BCCH), which is a DL channel for broadcasting system control information, and a paging control channel (PCCH), which is a DL channel for transferring paging information. The Multicast Control Channel (MCCH) is used to send multimedia broadcasts and Multicast Services (MBMS), and to schedule and control information for one or several MTCHs. It is a multipoint DL channel. Generally, this channel is only used by ATs that receive MBMS (Note: Old MCCH + MSCH) after establishing an RRC connection. A dedicated control channel (DCCH) is a point-to-point bidirectional channel that transmits dedicated control information and is used by ATs with RRC connections. In an aspect, the logical traffic channel is to send traffic data with a dedicated traffic channel (DTCH), which is one AT-specific point-to-point bidirectional channel for the transfer of user information. It has a multipoint traffic channel (MTCH) for point-to-multipoint DL channels.
In aspects, transmission channels are classified into DL and UL. DL transmission channels include broadcast channels (BCH), downlink shared data channels (DL-SDCH), and paging channels (PCH). Here, PCHs that support AT power saving (DRX cycles are shown to AT by the network) are broadcast across the cell and mapped to PHY resources used for other control / traffic channels. UL transmission channels include random access channels (RACH), request channels (REQCH), uplink shared data channels (UL-SDCH), and multiple PHY channels. The PHY channel comprises a set of DL and UL channels.
The DL PHY channel includes: Acknowledgment Channel (ACKCH), Common Control Channel (CCCH), Common Pilot Channel (CPICH), DL Physical Shared Data Channel (DL-PSDCH), Load Indicator Channel (LICH), Multicast Control Channel (MCCH), Paging Indicator Channel (PICH), Shared DL Control Channel (SDCCH), Shared UL Allocation Channel (SUACH), Synchronous channel (SCH), UL Power Control Channel (UPCCH).
UL PHY channels include: Acknowledgment Channel (ACKCH), Antenna Subset Indicator Channel (ASICH), Broadcast Pilot Channel (BPICH), Channel Quality Indicator Channel (CQICH), Physical Random Access Channel (PRACH), Shared request channel (SREQCH), UL Physical Shared Data Channel (UL-PSDCH).
The following abbreviations apply for the purposes of this document.
AMD: Acknowledge Mode Data, ARQ: Automatic repeat request, AT: Access terminal, ATM: Acknowledge Mode, BCCH: Broadcast control channel, BCH: Broadcast channel, C-: Control-, CCCH: Common control channel, CCH: Control channel, CCTrCH: Encoded synthetic transmission channel, CP: Cyclic Prefix, CRC: Cyclic Redundancy Check, CSG: Closed subscriber group, CTCH: Common traffic channel, DCCH: Dedicated control channel, DCH: Dedicated channel, DL: Downlink, DL-SCH: Downlink shared channel, DSCH: Downlink shared channel, DTCH: Dedicated traffic channel, FACH: Forward Link Access Channel, FDD: Frequency Division Duplex, HLR: Home Location Register, HNBID: Femtocell ID, HSS: Home Subscriber Server, I-CSCF: Inquiry call session control function, IMS: IP Multimedia Subsystem, IMSI: International Mobile Station Identification Information, L1: Layer 1 (physical layer), L2: Layer 2 (Data Link Layer), L3: Layer 3 (network layer), LI: Length indicator, LSB: least significant bit, MAC: Medium Access Control, MBMS: Multimedia Broadcast Multicast Service, MBSFN: Multicast Broadcast Single Frequency Network, MCCH: MBMS point-to-multipoint control channel, MCE: MBMS Coordinating Entity, MCH: Multicast channel, MRW: Motion reception window, MSB: Most significant bit, MSC: Mobile Exchange Center, MSCH: MBMS Point-to-Multipoint Scheduling Channel, MSCH: MBMS control channel, MTCH: MBMS point-to-multipoint traffic channel, NASS: Network Connection Point Subsystem, P2P: Peer-to-peer, PCCH: Paging control channel, PCH: Paging channel, P-CSCF: Proxy call session control function, PDCCH: Physical downlink control channel, PDSCH: Physical Downlink Shared Channel, PDU: Protocol data unit, PHY: Physical layer, PhyCH: Physical channel, RACH: Random Access Channel, RACS: Resources and Authorization Control Subsystem, RLC: Wireless link control, RRC: Radio Resource Control, SAP: Service Access Point, S-CSCF: Service provision call session control function, SDU: Service Data Unit, SeGW: Secure gateway, SHCCH: Shared channel control channel, SIP: Session Initiation Protocol, SLF: Subscriber location feature, SN: Sequence number, SUFI: Super Field, TCH: Traffic channel, TDD: Time Division Duplex, TFI: Transmission format indicator, TISPAN: Telecom & Internet Integrated Services and Protocols for Evolved Networks, TM: Transparent mode, TMD: Transparent mode data, TMSI: Temporary Mobile Subscriber Identification, TTI: Transmission time interval, U-: User-, UE: User equipment, UL: Uplink, UM: Non-acknowledgement mode, UMD: Non-acknowledged mode data, UMTS: Universal Mobile Communication System, UTRA: UMTS Ground Radio Access, UTRAN: UMTS Terrestrial Radio Access Network.
FIG. 3 illustrates a typical communication system 300 that allows the deployment of femto access point BS (eg, HNB) in a network environment. The communication system 300 is a plurality of femto embodied as femto access points (s) 310 and / or IMS femto access points (s) 311 mounted in a small network environment. -Includes access points. Examples of small network environments can include virtually any indoor facility and / or indoor / outdoor facility 330. The femto access point (s) 310 serves the associated access terminal 320 (AT), for example, the AT contained in the access group (eg, CSG) associated with the femto access point. It is configured to provide or optionally service to an external, i.e., visitor access terminal 320. The access terminal 320 communicates with the macro cell by wireless link 360 and by wireless link 361 and / or wireless link 362 by one or more femto access points 310 and / or one or more IMS femto access points. Communicate with 311. Each femto access point (eg, femto access point 310 and / or IMS femto access point 311) is further by a DSL router (not shown), by a cable modem, or by wire connection. It is connected to the IP network 340 by broadband, by satellite IP network connection, or by a similar broadband IP network connection 370. Additional networks, including mobile operator core network 350, IMS network 390, and / or third-party operator network 380, are accessible via IP network 340. Mobai
In some embodiments, the femto access point 310 communicates with the femto access point gateway. Femto access point gateways are HNB gateways (HNB-GW), home-evolved e-node B gateways (HeNB-GW), or other gateways that can perform message exchanges under computer control. It can be embodied as a device.
The femto access point 310 can be embodied as a Home Node B Unit (HNB) or a Home Evolved Node B Unit (HeNB). As illustrated, the access terminal 320 can operate in a macro cell environment and / or in a small residential network environment using the various techniques described herein. Thus, in at least some disclosed aspects, the femto access point 310 may be backward compatible with any suitable existing access terminal 320. Although the embodiments described herein apply the 3GPP specification, these embodiments also apply to the 3GPP2 technology (Rel99 [Rel99], Rel5, Rel6, Rel7) and other well-known and related technologies. It must be recognized that it should be understood that it can also be applied to 3GPP variants. In such embodiments described herein, the owner of the HNB 310 subscribes to a mobile service, such as the 3G mobile service provided by the Mobile Operator Core Network 350. The access terminal 320 can operate in both a macro cellular environment and a small network environment of a residential or private enterprise. The femto access point 310 is backward compatible with any existing access terminal 320.
In some embodiments of the invention, the femto access point (FAP) is an IP to provide network services such as GSM, UMTS, LTE / dual mode, CDMA2000, circuit switching services, etc. It can be deployed to interface within the Multimedia Subsystem (IMS). Such deployments register the FAP with the network to ensure that it is not open to be abused by the FAP (which may be hosted by a network operator in a location not known to be trusted). It would be advantageous to provide safe methods and equipment for this.
In some embodiments of the invention, a femto access point (FAP) or HNB provides network services such as GSM, UMTS, LTE / dual mode, CDMA2000, and circuit switching services. Register yourself with the operator's network using the SIP procedure as specified in the IETF RFC 3261 and 3GPP and 3GPP2 IP Multimedia Subsystem (IMS) specifications. A secure way to register a FAP with the network to ensure that such a procedure is not abused by the FAP (which can be hosted by a network operator in a location not known to be trusted). And it is advantageous to provide the device.
FIG. 4 is an IMS environment, which is an environment for establishing secure registration of femto access points according to one embodiment of the present invention. As an option, the Environment 400 exists within the context of the architecture and functionality shown in FIGS. 1 to 3.
The IMS architecture, as shown, systematizes the network infrastructure into another plane with standardized interfaces. Each interface is designated as a reference point that defines the protocol and functionality. Features can be mapped to any one or more planes. A single device can include several features.
Environment 400 is organized into three planes: application plane 402, control plane 404, and user plane 406.
The application plane 402 provides the infrastructure for the provision and management of services and is common, including configuration storage, identity management, user status (eg, presence and location), and other features. Define a standard interface to the function. In some cases, data corresponding to any of the above may be stored and managed by the Home Subscriber Server (HSS).
The application plane 402 is a plurality of application servers 408 (for example, telephony application servers, IP multimedia service exchange functions, open service access gateways, etc.) for executing various services. AS) can be included. These application servers are responsible for performing functions for managing subscriber sessions, including managing the state of telephone calls. A service provider may deploy one or more application servers to allow the generation of new applications. In addition, the application plane provides the infrastructure for providing billing capabilities 410 and other billing-related services. The application plane provides the infrastructure for controlling voice and video calls, as well as the infrastructure for messaging, which is further serviced by features within the control plane.
As shown, the control plane 404 is logically placed between the application plane 402 and the user plane 406. Typically, the control plane routes call signaling, performs authorization and authentication aspects, and performs some privacy functions. Functions within the control plane can interface with billing function 410 to generate certain types of billing-related services.
In some embodiments, the control plane combines logical connections between various other network functions to facilitate endpoint registration, SIP message routing, and overall coordination of media and signaling resources. .. As shown, the control plane includes a call session control function. This is achieved cooperatively by proxy CSCF (indicated as P-CSCF412), service providing CSCF (indicated as S-CSCF414), and query CSCF (indicated as I-CSCF416). The control plane also includes a Home Subscriber Server (HSS) database. HSS maintains a service profile for each end user, including registration information, priorities, roaming information, voicemail options, friend list, etc. In addition, the HSS retains service profile information associated with femto access points (eg, femto access point 310 and / or IMS femto access point 311). Centralizing subscriber information can facilitate service delivery, consistent application access, and profile sharing across multiple access networks. In some cases, the Home Location Register (HLR) is reachable over the network and can operate on behalf of (or in coordination with) HSS. Multiple core networks 420 (eg, mobile operator core network 350) may be reachable by the interconnect boundary control functional component 418. Access to the core network 420 is made via a perimeter gateway (eg, I-BCF418). Boundary gateways can be deployed to enhance access policies and control traffic flow to and from core network 420. In some embodiments, the Interconnect Boundary Control Function (I-BCF) controls transmission level security.
The control plane 404 implements a call session control function (CSCF) that includes: Proxy CSCF (P-CSCF412) is the first contact point for users using IMS. P-CSCF is responsible not only for allocating resources for media flow, but also for security of messages between the network and users. Inquiry CSCF (I-CSCF416) is the first contact point from the peer network. The I-CSCF is responsible for querying the HSS to determine the S-CSCF for the user and also (for example, using the Topology Hidden Inter-Network Gateway THIG) to query the operator's topology from the peer network. hide. Service provider The CSCF (eg, S-CSCF414) is responsible for handling registrations to record each user's location, user authentication, and call processing (including routing the call to the application). The operation of S-CSCF can be partially controlled by the policies stored in HSS.
User plane 406 is for access from user equipment 422 (such as access terminal 320) via various networks (eg, mobile networks, WiFi networks, broadband networks, etc.). Provides a core QoS-enabled IPv6 network 422. This infrastructure was designed to provide a wide range of services, such as IP multimedia services based and peer-to-peer (P2P).
FIG. 5 is an IMS system that includes components for establishing secure registration of femto access points according to one embodiment of the invention. Optionally, the System 500 can be implemented in the context of the architecture and functionality shown in FIGS. 1 to 4. However, of course, System 500 or any operation can be achieved in any desired environment.
The differences shown in FIG. 5 compared to FIG. 4 are the presence of the femto access point 310 associated with the user equipment 424 and the presence of the femto access point gateway 506 (FAP-GW). And that there is a display of operator control network 521. The operator control network 521 includes a secure gateway (eg, SeGW502) (as shown) and an operator control IPsec address dataset 504.
In some embodiments, one or more femto access points 310 may use SIP to register themselves with the S-CSCF within the IMS domain. Certain procedures and / or rules may be invoked to provide network environments and protocols to ensure secure and resistant registration to threats. For example The FAP authenticates itself to a secure gateway (eg SeGW) located within the operator's network and establishes a secure tunnel (eg IPSec ESP). A FAP can forward any IP packet from another with a source IP address that has the same address as the FAP-protected address (eg, IPSec tunnel internal header source IP address, FAP source IP address). It shall not be processed. Any SIP message originating on FAP310 shall use the IPSec tunnel internal address assigned by SeGW (using the operator control database of IPsec internal addresses). Assume that the tunnel internal address space is under the control of the operator. The FAP subnet address is not used for any other purpose by the telecommunications network operator. In addition to the above rules, other rules may apply.
Various authentication techniques for IMS registration (eg IMS AKA, SIP digest (with or without TLS), GPRS IMS bundle authentication, NASS IMS bundle authentication, trusted node authentication (for ICS) or TNA, etc. ) Was proposed. These authentication techniques and how they coexist in IMS are defined by 3GPP in TS 33.203 (Rel-8). This specification is incorporated herein by reference in its entirety.
The techniques described above introduce additional requirements or problems with these deployments. The embodiments of the invention described herein may use some of the techniques known as trusted node authentication (TNA) for the secure registration of femto access points. Assumptions related to the various embodiments include: A trusted node is either a node that is completely under operator control, or a node that has been verified to be trusted (eg, by some independent authentication, software code signing, etc.). It is either. A trusted node (for example, FAP) inserts a fully protected flag (for example, with a value of "authenticated"). The P-CSCF must not exist between the trusted node and the I / S-CSCF (ie, otherwise the P-CSCF removes the fully protected flag).
According to these rules, when the FAP is authenticated by the home network (eg, using FAP device authentication), the components in the IMS domain treat the FAP as a trusted node. In particular, the execution of IMS FAP registration uses trusted node authentication technology. Therefore, the FAP can be considered as a trusted node once it is authenticated to the operator's network. In some embodiments, the network operator can further verify that the FAP is in a trusted state (eg, by using methods such as secure booting, code signing, etc.).
For FAP IMS registration The techniques described above do not require any additional configuration or configuration in the FAP. However, in some embodiments, the FAP may use a SIP digest for the IMS registration procedure.
If the FAP correctly registers using one of these authentication methods, it can provide network services (eg, circuit-switched services) to the AT using the IMS infrastructure and SIP messaging.
System 500 embodies a communication system that performs secure registration of femto access points for access to operator-controlled network elements. Various functions are shown, including a security gateway element (eg, SeGW502) that is configured to manage the IPsec address dataset 504 in the operator-controlled network 521. A femto access point (eg, FAP310) is configured to request a security relationship from a security gateway element and a secure registration credential from a network element within an operator-controlled network 521. Such an operator-controlled network element may be configured to build the requested secure registration credential and send the requested secure registration credential to the femto access point. The requested secure registration certificate can be stored in non-volatile memory or cached for subsequent requests for the same secure registration certificate. The communication system includes at least one security gateway element for managing IPsec internal addresses (eg, IPsec address dataset 504). As shown, the femto access point is configured to use a SIP message (see message 1140) to request a secure registration credential. In some cases, the femto access point sends a request for secure registration credential to a session control function (CSCF) element (eg, P-CSCF412, S-CSCF414, I-CSCF416, etc.). The communication system can exchange messages with a femto access point profile (such as the femto access point's IMS identity) for authorization components. The authorization components are the home subscriber server, one or more components in the mobile operator core network 350, and the third party operator network 380.
FIG. 6 is representative of a system for establishing secure registration of femto access points according to one embodiment of the invention. Optionally, the System 600 can be implemented in the context of the architecture and functionality shown in FIGS. 1-5. However, of course, herein, the system 600 or any operation can be performed in any desired environment.
As shown, the system 600 includes an access terminal 320 that communicates with one or more network elements 625 by a wireless link (eg, wireless link 361, wireless link 362). In particular, the access terminal 320 is shown to be communicating with a femto access point (eg, femto access point 310, IMS femto access point 311). Femto access points, on the other hand, communicate with IP network 340 (eg, the Internet). On the other hand, the IP network 340 communicates with a plurality of operator-controlled network elements 626. In some embodiments, the operator-controlled network element 626 comprises one or more authorization components 635. The operator-controlled network element 626 is one or more operator-controlled network elements 626 (eg, FAP-GW506, one or more CSCF components, one or more security gateways 502, and one or more femtocells. It may include a cell centralized server 610). The Femtocell Centralized Server (FCS) is included in the IMS environment and not only operates or emulates as an IMP application server, but also emulates the protocols and features of the Mobile Exchange Center (MSC) and is deployed in the IMS environment. Serves as a networking gateway to interpret both to deliver existing MSC-related services to femto access points.
Permission component 635 is also shown. The authorization component can consist of one or more network components capable of performing one or more authorization actions for the secure registration of the femto access point. Examples of authorization component 635 include HSS620, one or more components in the mobile operator core network 350 (eg, HLR630), and one or more components in the third party operator network 380. ..
The femto access point gateway 506 (FAP-GW) is a messaging by any of the network elements within the operator-controlled network element 626, and any one including messaging between these network elements and possibly security gateway 502. Or useful for messaging with multiple femto access points (eg, femto access point 310, IMS femto access point 311), and for messaging between these femto access points. The security gateway 502 is embodied in a component separate from the femto access point gateway, as shown, or the security gateway 502 is a femto access point point, as described below. It can be embodied as a module within the gateway.
Any one or more of the authorization components 635 may include a list (eg, IPsec address dataset 504), which list may contain various types of singular or plural identifiers. In addition, this list can be systematized so that one type of identifier can be associated with another type of identifier (eg, a list of pairs, a list of tables, and so on). Such a list is stored in memory and is a valid identifier and / or a valid identifier pair or a valid access to identify a valid access (eg, one or more arbitrary permissions). Can include any relationship in any system to an identifier that identifies.
Any one or more of the network elements 625 may include a processor and memory. For example, the femto access point 310 may include a femto access point processor and a femto access point memory. Similarly, the femto access point gateway 506 may include a femto access point gateway processor and a femto access point gateway memory.
In embodiments of the invention, the system 600 can be used to perform secure registration of femto access points for access to operator-controlled network elements. More specifically, femto access points (eg FAP310, IMS) FAP311) can be configured to establish a security relationship. This security relationship (including IPsec internal addresses, etc.) can be used to request secure registration credit from operator-controlled network elements 626 (eg, P-CSCF412, S-CSCF414, etc.). Such an operator-controlled network element 626 builds the requested secure registration credential and uses this secure registration credential for the requesting femto access for access to the operator-controlled network element. -Can be configured to send to points. In some cases, establishing a security relationship is established by the function of a security gateway (such as SeGW502). This function can be performed in conjunction with at least one operator-controlled network element using an operator-controlled database of IPsec internal addresses.
In a typical embodiment, the femto access point requests registration using a SIP message sent to a call session control functional element (eg, P-CSCF412, S-CSCF414, I-CSCF416, etc.). Can be configured in. Of course, the session control functional element can be configured to hold a proof of credit, or the authorization component 635 (eg, HSS620, HLR630, mobile operator core network 350, third party operator network 380, etc.) ) Can be configured to obtain a secure registration credential by exchanging network messages with.
Any one or more of the operator-controlled network elements 626 described above are configured to relay access requests from access terminals (eg, access terminals 320, UE424, etc.), and the relayed access requests are Can be relayed using SIP messages. One or more operator-controlled network elements may be configured such that the relayed access request contains a fully protected indication.
FIG. 7 is a flow diagram of the process used to perform secure registration of a femto access point according to one embodiment of the invention. Optionally, the System 700 can be implemented in the context of the architecture and functionality shown in FIGS. 1-6. However, of course, system 700 or any operation within it can be achieved in any desired environment.
As shown, the steps performed by the femto access point to become a trusted node in the IMS region are to power up the femto access point component (see operation 710) and IP. Includes physical connection to the network (see operation 720). Once the physical layer connection is established, the femto access point begins establishing the connection at the MAC and link layers, and at some point requests a security relationship from the components within the IMS domain. This request for a security relationship is either granted by the security gateway (see Action 730) or by a proxy for the security gateway that is a member of operator-controlled network element 626. In embodiments of the invention, the femto access point can process SIP messages, which causes the femto access point to send SIP registration messages (see operation 740). This message can be processed by CSCF components within the IMS domain. On the other hand, the CSCF component requests permission by the permission component 635, which is a member of the operator-controlled network element 626.
The CSCF may request a permit (in operation 750) and then receive the requested permit from the permit component. Upon receipt (see decision 755), CSCF sends a SIP OK message to the requesting femto access point (see action 760). Of course, the permit request may be denied. In this case, the determination 755 rejects the permission request.
As shown, the CSCF asking for permission (in action 750) sends a SIP OK message to the requesting femto access point (see action 760), and the requesting femto access point is the permission component. Become a trusted node in the network area corresponding to the area allowed by 635 (see operation 770).
As mentioned above, authorization components are authorization components within the set of operator-controlled network elements 626, and such authorization components are authorization components within the HSS, HLR, and mobile operator core networks. It can be an element or an authorization component within the third-party operator network 380.
The femto access point that subsequently sent the SIP registration message (for operation 740) then receives the requested permission, and upon receipt (see operation 770), the femto access point that sent the SIP registration message is granted. Become a trusted node in the area. In a typical embodiment, the femto access point uses a SIP message containing a fully protected indication field set as "authenticated" (see operation 780). The femto access point begins receiving messages from ATs (eg, legacy ATs, UEs, SIP phones, etc.) and converts them to SIP if necessary (see operation 790).
FIG. 8 is a flow diagram of a process used to secure a registered credential for a femto access point according to one embodiment of the invention. Optionally, the System 800 can be implemented in the context of the architecture and functionality shown in FIGS. 1-7. However, of course, the system or any operation described herein can be achieved in any desired environment.
As shown, the CSCF (eg, service provider CSCF414) receives a SIP registration request (see operation 810) and performs a check for existing / current / valid permissions (see decision 825) (operation 820). reference). If the device corresponding to the SIP registration request received in operation 810 is allowed, this request is satisfied by "OK" (see operation 830). If not, this registration request is interpreted as a request for new permission and is a permission component (eg, HSS, HLR, mobile operator core network, third party operator network, etc.). Is requested (see operation 840). The authorization component responds to the requester, so that the CSCF receives the requested credential (see operation 850). In some cases, additional checks on authorization are performed (see behavior 860), and if the authorization test passes (see decision 865), the credential is the requester (eg, femto access point, or femto access point). It is sent to the point gateway, etc.). Of course, permission checks are performed (see action 860), and if the permission test is not passed, the registration request is rejected (see action 870). In some cases, the registration request is rejected by returning a message stating the reason for rejecting this request. In other cases, no response is returned to the requester and the requester does not receive the requested proof of credit. In other cases, the registration request is accepted and the authorization credit certificate is sent to the requester (see Action 880).
FIG. 9 is a flow diagram for performing a check for existing / current / valid permissions for secure registration of a femto access point. Optionally, the System 900 may be implemented in the context of the architecture and functionality shown in FIGS. 1-8. However, of course, System 900 or any operation thereof can be achieved in any desired environment.
System 900 can be started whenever an operator-controlled network element attempts to satisfy a request for permission (see operation 820). In some cases, CSCF or other operator-controlled network elements may store the authenticated authorization of the femto access point in cache memory (see Action 910). In some cases, the femto access point's authenticated authorization does not exist in cache memory and the CSCF or other operator-controlled network element obtains the true authorization from authorization component 635. Try. In such cases, the operator-controlled network element selects one or more authorization components (see Action 920) and performs network messaging to establish the authenticity of the selected authorization component (behavior). See 930). If the authentication step described above is done correctly, the operator-controlled network element issues a request for authorization credential (see action 940), and upon receiving the authorization credential, caches this credential (see action 950). , Start sending this proof of credit to the requester (see Action 960).
FIG. 10 is a protocol diagram illustrating a messaging protocol for performing secure registration of femto access points using a centralized server in an IMS environment according to one embodiment of the present invention. Optionally, the Protocol 1000 can be implemented in the context of the architecture and functionality of FIGS. 1-9. However, of course, this Protocol 1000 or any operation thereof can be performed in any desired environment.
As shown, protocol 1000 is executed by components including access terminal AT / UE1010, femto access point FAP1012, security gateway SeGW1014, CSCF (IMS) 1016, and authorization components in the form of HSS1018. To. The protocol will also be joined by the femtocell centralized server FCS1020.
The protocol is initiated at any time, and the specific order and / or interleaving of actions and messages contained in this protocol is shown for illustrative purposes.
As shown, FAP1012 initiates a protocol exchange, perhaps via a femto access point gateway (not shown), to establish an IPsec security relationship from SeGW1014 (see message 1022). SeGW responds by returning the requested IPsec relationship (see message 1024). FAP1012 sends a SIP registration message to CSCF using the acquired IPsec relationship (see message 1026). The CSCF confirms the permission in some cases (see operation 1028), however, in other cases the CSCF may require a permission from a permission component (eg, HSS1018). In such cases, CSCF sends the request (including the femto access point profile) to the authorization component (see message 1030). If the authorization component considers that it satisfies this authorization request, the authorization component returns the authorization credential (see message 1032). A CSCF with sufficient credentials to allow at least some access to the network elements covered by this credentials then performs an additional authorization step (see operation 1034) and sends a SIP OK message to the requester. Send (see message 1036). In some cases, CSCF may perform additional registration steps. For example, CSCF initiates a third-party core network registration (see message 1037), and the third-party core network registration returns proof of credit to CSCF (not shown).
Assuming message 1036 is present, the femto access point is a trusted node in the region corresponding to the credential and is considered by this region to be a trusted node. Therefore, the access terminal (eg, AT / UE1010) initiates an attach or registration request (see message 1038). This request is translated into a SIP message (see operation 1039) and is probably forwarded to CSCF as a SIP INVITE message (see message 1040) sent and / or relayed to FCS1020 (see message 1042). As mentioned above, FCS helps bridge IMS domain services to non-IMS domain services (eg, in circuit-switched domains). This involves translating SIP messages into legacy messages (see operation 1043). Therefore, the SIP received by FCS The INVITE message is translated into a request (see message 1044), the authorization response from the non-IMS region (see message 1046) is translated back into the SIP message format (see action 1047), and probably by relay (see message 1048). , See message 1049) Returned to the requester. As shown, this relay is a legacy attach message sent to the legacy AT1010, i.e. a registration OK message (see message 1052).
FIG. 11 is a protocol diagram illustrating a messaging protocol for performing secure registration of femto access points in a full IMS environment according to one embodiment of the invention. Optionally, the Protocol 1100 can be implemented in the context of the architecture and functionality of FIGS. 1-10. However, of course, this protocol 1100 or any operation thereof can be performed in any desired environment.
As shown, protocol 1100 is executed by components including access terminal AT / UE1010, femto access point FAP1012, security gateway SeGW1014, CSCF (IMS) 1016, and authorization components in the form of HSS1018. To. The protocol is initiated at any time, and the specific order and / or interleaving of actions and messages contained in this protocol is shown for illustrative purposes. As shown, FAP1012 initiates a protocol exchange to establish an IPsec security relationship from SeGW1014 (see message 1122). SeGW can respond by returning the requested IPsec relationship (see message 1124). Using the acquired IPsec relationship, FAP1012 sends a SIP registration message to CSCF (see message 1126). The CSCF in some cases confirms the permission (see behavior 1128), but in other cases the CSCF requests the permission from the permission component 1018. In such cases, CSCF1016 sends a request (including the femto access point profile) to authorization component HSS1018 (see message 1030). The authorization component returns the authorization credential to CSCF1016 if it considers it satisfying the authorization request (see message 1132). The messaging protocol for performing secure registration of femto access points in a complete IMS environment does not require interaction with the FCS1020 (for example, for third-party registration). These services are delivered exclusively within the IMS domain. In addition, CSCF1016 has the database needed to check if the FAP is a trusted node, perhaps in conjunction with HSS. That is, CSCF1016 and HSS1018 are a group of operator-controlled network elements 626 operating within operator-controlled network 521. It is a member. Therefore, the CSCF1016 can probably work with the HSS1018 to have access to the authorization database, which contains at least the IPsec address dataset 504, and to respond with a SIP OK message (see message 1135). This is relayed to the requesting FAP1012 (see message 1137). In other situations, the HSS1018 does not have direct access to the required authorization database and probably has some behavior (behavior) that includes additional messaging (not shown) to check for the existence of authorization credentials. 1134) can be executed. If message 1137 is present, the femto access point is a trusted node in the region corresponding to the credential and is considered to be a trusted node by this region. Therefore, the access terminal (eg, AT / UE1010) initiates an attach or registration request (see message 1138). This request is probably forwarded to CSCF1016 as a SIP INVITE message (see message 1140) and / or relayed to CSCF1016 (see message 1142).
The CSCF1016 uses the IMS domain networking components to provide or manage IMS domain services (ie, without the assistance of the FCS1020 or without the assistance of non-IMS domain components). Therefore, the SIP INVITE message received on the CSCF1016 initiates a SIP protocol exchange for the provision of IMS services. By providing this service, SIP messages are sent to FAP1012 (see message 1144) and then to AT / UE1010 (see message 1150).
Figure 12 shows a block diagram of the system for performing secure registration of femto access points for access to operator-controlled network elements. Optionally, the System 1200 may be implemented in the context of the architecture and functionality of the embodiments described herein. However, of course, the system 1200 or any operation thereof can be performed in any desired environment. As shown, system 1200 includes multiple modules, each connected to communication link 1205. Any module can communicate with other modules via communication link 1205. Modules of this system may perform method steps within System 1200, either individually or in combination. Any method step performed within the system 1200 may be performed in any order unless specified in the claims. As shown, the system 1200 implements a method for accessing operator-controlled network elements. The system 1200 establishes a security relationship for at least one femto access point (see module 1210) and secure registration credential from at least one femto access point using the security relationship. (See module 1220), build a secure registration credential with at least one authorization component (see module 1230), and access to operator-controlled network elements at the femto access point. Provide each module for receiving a secure registration credit certificate for (see Module 1240).
FIG. 13 shows a block diagram of a system that performs certain functions of a communication system to perform secure registration of femto access points. Optionally, the System 1300 may be implemented in the context of the architecture and functionality of the embodiments described herein. However, of course, this system 1300 or any operation thereof can be performed in any desired environment. As shown, system 1300 includes multiple modules, including a processor and memory. Each module is connected to communication link 1305, and any module can communicate with other modules through communication link 1305. Modules of this system may perform method steps within system 1300, either individually or in combination. Any method step performed within the system 1300 may be performed in any order unless specified in the claims. As shown, Figure 13 requests a security relationship from a security gateway element (see module 1310) that is configured to manage IPsec address datasets in an operator-controlled network. At least one femto access point (see module 1320) configured to require a secure registration credential and a required secure registration credential to build and a required secure registration. Each including at least one operator-controlled network element (see module 1330) configured to store the credential and to send the requested secure registered credential to the femto access point. A communication system is realized as a system 1300 equipped with a module.
FIG. 14 shows a block diagram of a device that uses hardware and software means to perform secure registration of femto access points for access to operator-controlled network elements. Optionally, the System 1400 can be implemented in the context of the architecture and functionality of the embodiments described herein. However, of course, this system 1400 or any operation thereof can be performed in any desired environment. As shown, system 1400 includes multiple hardware and software components. Each of these is connected to communication link 1405, and any one component may communicate with the other component through communication link 1405. This system 1400 may perform method steps within system 1400 individually or in combination. Any method step performed within the system 1400 may be performed in any order unless specified in the claims. As shown, FIG. 14 implements a device for accessing operator-controlled network elements. This device uses security relationships as a means of establishing a security relationship for at least one fem access point (see component 1410), and secure registration credential from at least one fem access point. Means to request (see component 1420), to build a secure registration credential with at least one authorization component (see component 1430), and to an operator-controlled network element at the femto access point. It is provided with a means of receiving a secure registration credit certificate for access (see component 1440).
Figure 15 shows a block diagram of a system performing a function with a femto access point. Optionally, the System 1500 may be implemented in the context of the architecture and functionality of the embodiments described herein. However, of course, this system 1500 or any operation thereof can be performed in any desired environment. As shown, the system 1500 includes multiple modules including a processor and memory. Each module is connected to communication link 1505, and any module can communicate with other modules via communication link 1505. Modules of this system may perform method steps within the system 1500, either individually or in combination. Any method step performed within the system 1500 may be performed in any order unless specified in the claims. As shown, FIG. 15 implements a femto access point as a system 1500. This system uses a module containing at least one processor and memory (see module 1510) and establishing a security relationship for at least one fem access point (see module 1520) and using the security relationship. Requesting a secure registration credential (see module 1530) and receiving a secure registration credential for access to operator-controlled network elements at the femto access point (see module 1540). Each module is provided.
The ones mentioned above include examples of aspects of the subject matter claimed. Of course, it is not possible to describe all possible combinations of components and methods to describe the alleged subject matter, but those skilled in the art will appreciate more combinations and substitutions of the disclosed subject matter. Can be recognized as possible. Therefore, the disclosed subject matter is intended to include all such changes, modifications, and modifications within the spirit and scope of the claims. Further, as long as the terms "include", "have", or "have" are used in either the detailed description or the claims, such terms are such that the term "provides" transitions within the claims. It is intended to be inclusive, as is the term "provide" as interpreted when applied as a word.
It is understood that the specific order or hierarchy of steps in the disclosed process is an example of a typical approach. Based on the design choices, it is understood that the specific order or hierarchy of steps in these processes can be reconstructed while remaining within the scope of the present disclosure. The method claims are meant to show the elements of the various steps in sample order and are not limited to the specific order or hierarchy shown.
Those skilled in the art will appreciate that information and signals can be represented using any of a variety of different techniques and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced through the above description are voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or particles, or any combination thereof. Can be represented by.
Those skilled in the art will further appreciate the various exemplary logical blocks, modules, circuits, and algorithmic steps described in connection with the embodiments disclosed herein, including electronic hardware, computer software. You will recognize that it is realized as a combination of, or both. To articulate the interstitial nature of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been generally described in terms of their functionality. Whether these functions are realized as hardware or software depends on the design constraints imposed on specific applications and the entire system. Those skilled in the art can realize the above-mentioned functions in a manner that changes according to each specific application. However, this application decision should not be construed as causing a deviation from the scope of the invention.
The various exemplary logic blocks, modules, and circuits described in connection with the embodiments disclosed herein include general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), and fields. A programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination of the above designed to achieve the functions described above. Can be realized or implemented using. Although a microprocessor can be used as a general-purpose processor, a conventional processor, controller, microcontroller, or sequential circuit can be used instead. Processors are also implemented as, for example, a combination of DPS and processors, multiple microprocessors, one or more microprocessors working with DSP cores, or a combination of computing devices such as any other configuration. sell.
The steps of the method or algorithm described with respect to the embodiments disclosed herein can be embodied directly in hardware by a software module executed by a processor or by a combination of the two. Software modules are RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disks, removable disks, CD-ROMs, or other types of storage media known in the art. Can be stored in. A typical storage medium is connected to a processor such as a processor capable of reading information from the storage medium and writing information to the storage medium. Alternatively, the storage medium can be integrated into the processor. The processor and storage medium can reside within the ASIC. The ASIC can also exist in the user terminal. Alternatively, the processor and the storage medium can exist as discrete components in the user terminal.
In one or more typical embodiments, the described functionality may be achieved by hardware, software, firmware, or any combination thereof. When implemented in software, these functions may be stored on a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include both computer storage media and communication media. These include any medium that facilitates the transfer of computer programs from one location to another. The storage medium is any available medium that can be accessed by a computer. By way of example, without limitation, such computer readable media can be RAM, ROM, EEPROM, CD-ROM or other optical disc storage device, magnetic disk storage device or other magnetic storage device, or a desired program. Code means may be used to carry or store in the form of instructions or data structures, and may include any other medium accessible by a computer. Moreover, any connection is appropriately referred to as a computer readable medium. From coaxial cables, fiber optic cables, twist pairs, digital subscriber lines (DSL), or wireless technologies such as infrared, wireless and microwave, from websites, servers, or other remote sources. When the software is transmitted, the definition of medium includes coaxial cables, fiber optic cables, twisted pairs, DSLs, or wireless technologies such as infrared, wireless and microwave. The discs (disk and disc) used herein are compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy® discs, and blue ray discs. including. These discs use a laser to optically reproduce the data. Disk, on the other hand, usually magnetizes the data. Regenerate in a spirited manner. The above combinations should also be included within the range of computer readable media.
The above description of the disclosed embodiments will be provided to those skilled in the art to enable the manufacture or use of the present disclosure. Various variations on these embodiments are also apparent to those of skill in the art, and the general principles defined herein apply to other examples without departing from the gist or scope of the present disclosure. Can be done. As such, the invention is not limited to the embodiments presented herein, but is intended to correspond to the broadest scope consistent with the principles and novel features disclosed herein. ing.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2015523813A | Cited by | Japan | Search report |
| WO2015182292A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2021108460A | Cited by | Japan | Search report |
| JPWO2015182292A1 | Cited by | Japan | Search report |
| JP2015523813A | Cited by | Japan | Search report |
| JP2013510504A | Cited by | Japan | Search report |
| US11251852B2 | Cited by | United States of America | Applicant |
| US10587326B2 | Cited by | United States of America | Applicant |
| JP2006174152A | Cites | Japan | Examiner |
| JP2006518121A | Cites | Japan | Examiner |
| WO2007015075A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO2007024455A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2007151090A | Cites | Japan | Search report |
| US2008076425A1 | Cites | United States of America | Examiner |
| WO2008125657A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2008219150A | Cites | Japan | Examiner |
| JP2009504051A | Cites | Japan | Examiner |
| JP2009505576A | Cites | Japan | Examiner |
| JP2010525643A | Cites | Japan | Search report |
16 members in 7 offices
Priority claims11
| Document | Office | Kind | Date |
|---|---|---|---|
| 11839708 | United States of America | P | |
| 61118397 | United States of America | – | |
| 12625047 | United States of America | – | |
| 62504709 | United States of America | A | |
| 2009065972 | United States of America | W | |
| 2008118397 | – | – | – |
| 2009625047 | – | – | – |
| 2009065972 | – | – | – |
| US20080118397P | – | – | – |
| US20090625047 | – | – | – |
| WO2009US65972 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| US2010130171A1 | United States of America | A1 | |
| WO2010062983A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010062983A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW201043053A | Taiwan Province of China | A | |
| KR20110091022A | Republic of Korea | A | |
| EP2368384A2 | European Patent Office (EPO) | A2 | |
| CN102224748A | China | A | |
| JP2012510241AThis record | Japan | A | |
| KR101315205B1 | Republic of Korea | B1 | |
| JP5524232B2 | Japan | B2 | |
| JP2014132767A | Japan | A | |
| US8886164B2 | United States of America | B2 | |
| CN102224748B | China | B | |
| CN105101204A | China | A | |
| JP5826870B2 | Japan | B2 | |
| CN105101204B | China | B |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2012510241
- Publication, DOCDB
- 2012510241
- Publication, EPODOC
- JP2012510241
- Application
- 2011538698
- Application, DOCDB
- 2011538698
- Application, EPODOC
- JP20110538698
Titles2
- Japanese
- フェムト・アクセス・ポイントの安全な登録を実行するための方法および装置
- English
- Methods and equipment for performing secure registration of femto access points
Classification
- CPC, 6
- H04W12/06
- H04L63/0823
- H04L9/32
- H04L65/1073
- H04W84/045
- H04W12/069
- IPC, 3
- H04W12 06
- H04W84 10
- H04W16 16
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo