Methods and apparatuses to perform secure registration of femto access points in operator controlled network
Abstract
A method, apparatus and system for performing secure registration of a femto access point for trusted access to an operator-controlled network element. Method steps include establishing a security association for at least one said femto access point, requesting an operator-controlled network element using the security association, wherein the operator-controlled network element obtains a security registration certificate from an authorization component. request. The operator-controlled network element configures a security registration certificate, and sends the security registration certificate to the requesting femto access point to authorize trusted access by the requesting femto access point to access the operator-controlled network element. Embodiments include establishing the security association via an IPsec security association received from a security gateway within an operator-controlled domain and using an operator-controlled database of IPsec internal addresses. In some embodiments, the femto access point performs message exchange using one or more IMS protocols and components that include a call session control function element, which elements may authorize the femto access point in the IMS domain, for authorization Can access non-IMS network elements.

Term
3.2 yearsleft in the term
Expires 25 November 2029.
- Priority
- Filed
- Granted
- Today
- Expires
50 claims: 6 independent, 44 dependent
- 1운영자-제어(operator-controlled) 네트워크 엘리먼트로의 액세스를 위해 펨토 액세스 포인트의 보안 등록을 수행하는 방법으로서, 적어도 하나의 상기 펨토 액세스 포인트에 대한 보안 연관을 설정하는 단계;상기 보안 연관을 이용하여 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서(credential)를 요청하는 단계;적어도 하나의 인가 컴포넌트에 의해 상기 보안 등록 인증서를 구성하는 단계;및 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 상기 펨토 액세스 포인트에서 수신하는 단계를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 2제 1 항에 있어서, 상기 보안 연관을 설정하는 단계는 보안 게이트웨이(SeGW)로부터 수신된 IPsec 보안 연관에 의해 설정되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 3제 1 항에 있어서, 상기 보안 연관을 설정하는 단계는 보안 게이트웨이(SeGW)의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 4제 1 항에 있어서, 상기 보안 연관을 설정하는 단계는 IPsec 내부 어드레스의 적어도 하나의 운영자-제어 데이터베이스를 이용하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 5제 1 항에 있어서, 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하는 단계는 SIP 메시지를 이용하여 등록을 요청하는 단계를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 6제 1 항에 있어서, 상기 보안 등록 인증서를 구성하는 단계는 호출 세션 제어 기능(CSCF) 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 7제 6 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 홈 가입자 서버(HSS)와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 8제 6 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 인가 컴포넌트와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 9제 1 항에 있어서, 상기 보안 등록 인증서를 구성하는 단계는 CSCF 엘리먼트의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 10제 1 항에 있어서, 상기 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 수신하는 단계는 SIP OK 메시지를 수신하는 단계를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 11제 1 항에 있어서, 액세스 단말로부터의 액세스 요청을 중계하는 단계를 더 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 12제 11 항에 있어서, 상기 중계된 액세스 요청은 SIP 메시지를 이용하여 중계되는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 13제 11 항에 있어서, 상기 중계된 액세스 요청은 무결성 보호(integrity-protected) 표시를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 방법.
- 14운영자-제어 네트워크 엘리먼트로의 액세스를 위해 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템으로서, 운영자-제어 네트워크 내의 IPsec 어드레스 데이터세트를 관리하도록 구성되는 보안 게이트웨이 엘리먼트;상기 보안 게이트웨이 엘리먼트로부터 보안 연관을 요청하도록 구성되고, 보안 등록 인증서를 요청하도록 구성되는 적어도 하나의 펨토 액세스 포인트;및 상기 요청된 보안 등록 인증서를 구성하고 상기 요청된 보안 등록 인증서를 저장하도록 구성되고, 상기 요청된 보안 등록 인증서를 상기 펨토 액세스 포인트에 전송하도록 구성되는 적어도 하나의 운영자-제어 네트워크 엘리먼트를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 15제 14 항에 있어서, 상기 보안 게이트웨이 엘리먼트는 보안 게이트웨이의 기능을 수행하는 다른 운영자-제어 네트워크 엘리먼트인, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 16제 14 항에 있어서, 상기 IPsec 어드레스 데이터세트는 IPsec 내부 어드레스의 운영자-제어 데이터베이스를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 17제 14 항에 있어서, 상기 적어도 하나의 펨토 액세스 포인트는 SIP 메시지를 이용하여 보안 등록 인증서를 요청하도록 구성되는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 18제 14 항에 있어서, 상기 요청된 보안 등록 인증서를 상기 펨토 액세스 포인트에 전송하는 것은 호출 세션 제어 기능(CSCF) 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 19제 14 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 홈 가입자 서버(HSS)와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 20제 14 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 인가 컴포넌트와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 21제 14 항에 있어서, 상기 보안 등록 인증서를 요청하는 것은 SIP 메시지를 이용하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 22제 14 항에 있어서, 중계된 액세스 요청은 무결성 보호 표시를 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 23제 14 항에 있어서, 상기 요청된 보안 등록 인증서를 상기 펨토 액세스 포인트에 전송하는 것은 SIP OK 메시지를 전송하는 것을 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 통신 시스템.
- 24운영자-제어 네트워크 엘리먼트로의 액세스를 위해 펨토 액세스 포인트의 보안 등록을 수행하는 방법을 구현하는 컴퓨터 판독가능 매체로서, 상기 방법은, 적어도 하나의 상기 펨토 액세스 포인트에 대한 보안 연관을 설정하는 단계;상기 보안 연관을 이용하여 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하는 단계;적어도 하나의 인가 컴포넌트에 의해 상기 보안 등록 인증서를 구성하는 단계;및 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 상기 펨토 액세스 포인트에서 수신하는 단계를 포함하는, 컴퓨터 판독가능 매체.
- 25제 24 항에 있어서, 상기 보안 연관을 설정하는 단계는 보안 게이트웨이(SeGW)로부터 수신된 IPsec 보안 연관에 의해 설정되는, 컴퓨터 판독가능 매체.
- 26제 24 항에 있어서, 상기 보안 연관을 설정하는 단계는 보안 게이트웨이(SeGW)의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 컴퓨터 판독가능 매체.
- 27제 24 항에 있어서, 상기 보안 연관을 설정하는 단계는 IPsec 내부 어드레스의 적어도 하나의 운영자-제어 데이터베이스를 이용하여 수행되는, 컴퓨터 판독가능 매체.
- 28제 24 항에 있어서, 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하는 단계는 SIP 메시지를 이용하여 등록을 요청하는 단계를 포함하는, 컴퓨터 판독가능 매체.
- 29제 24 항에 있어서, 상기 보안 등록 인증서를 구성하는 단계는 호출 세션 제어 기능(CSCF) 엘리먼트와 관련하여 수행되는, 컴퓨터 판독가능 매체.
- 30제 24 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 홈 가입자 서버(HSS)와 교환하는, 컴퓨터 판독가능 매체.
- 31제 24 항에 있어서, 상기 보안 등록 인증서를 구성하는 단계는 CSCF 엘리먼트의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 컴퓨터 판독가능 매체.
- 32제 24 항에 있어서, 상기 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 수신하는 단계는 SIP OK 메시지를 수신하는 단계를 포함하는, 컴퓨터 판독가능 매체.
- 33제 24 항에 있어서, 액세스 단말로부터의 액세스 요청을 중계하는 단계를 더 포함하는, 컴퓨터 판독가능 매체.
- 34운영자-제어 네트워크 엘리먼트로의 액세스를 위해 펨토 액세스 포인트의 보안 등록을 수행하는 장치로서, 적어도 하나의 상기 펨토 액세스 포인트에 대한 보안 연관을 설정하기 위한 수단;상기 보안 연관을 이용하여 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하기 위한 수단;상기 보안 등록 인증서를 적어도 하나의 인가 컴포넌트에 의해 구성하기 위한 수단;및 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 상기 펨토 액세스 포인트에서 수신하기 위한 수단을 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 35제 34 항에 있어서, 상기 보안 연관을 설정하는 것은 보안 게이트웨이(SeGW)로부터 수신된 IPsec 보안 연관에 의해 설정되는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 36제 34 항에 있어서, 상기 보안 연관을 설정하는 것은 보안 게이트웨이(SeGW)의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 37제 34 항에 있어서, 상기 보안 연관을 설정하는 것은 IPsec 내부 어드레스의 적어도 하나의 운영자-제어 데이터베이스를 이용하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 38제 34 항에 있어서, 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하는 것은 SIP 메시지를 이용하여 등록을 요청하는 것을 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 39제 34 항에 있어서, 상기 보안 등록 인증서를 구성하는 것은 호출 세션 제어 기능(CSCF) 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 40제 34 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 홈 가입자 서버(HSS)와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 41제 34 항에 있어서, 상기 적어도 하나의 운영자-제어 네트워크 엘리먼트는 펨토 액세스 포인트 프로파일을 적어도 하나의 인가 컴포넌트와 교환하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 42제 34 항에 있어서, 상기 보안 등록 인증서를 구성하는 것은 CSCF 엘리먼트의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 43제 34 항에 있어서, 상기 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 수신하는 것은 SIP OK 메시지를 수신하는 것을 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 44제 34 항에 있어서, 액세스 단말로부터의 액세스 요청을 중계하는 수단을 더 포함하는, 펨토 액세스 포인트의 보안 등록을 수행하는 장치.
- 45운영자-제어 네트워크 엘리먼트로의 보안 액세스를 위한 펨토 액세스 포인트로서, 적어도 하나의 상기 펨토 액세스 포인트에 대한 보안 연관을 설정하고;상기 보안 연관을 이용하여 보안 등록 인증서를 요청하고;운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 펨토 액세스 포인트로의 상기 보안 등록 인증서를 수신하기 위한 적어도 하나의 프로세서 및 메모리를 포함하는, 펨토 액세스 포인트.
- 46제 45 항에 있어서, 상기 보안 연관을 설정하는 것은 보안 게이트웨이(SeGW)로부터 수신된 IPsec 보안 연관에 의해 설정되는, 펨토 액세스 포인트.
- 47제 45 항에 있어서, 상기 보안 연관을 설정하는 것은 보안 게이트웨이(SeGW)의 기능을 수행하는 적어도 하나의 운영자-제어 네트워크 엘리먼트와 관련하여 수행되는, 펨토 액세스 포인트.
- 48제 45 항에 있어서, 상기 보안 연관을 설정하는 것은 IPsec 내부 어드레스의 적어도 하나의 운영자-제어 데이터베이스를 이용하여 수행되는, 펨토 액세스 포인트.
- 49제 45 항에 있어서, 상기 보안 등록 인증서를 요청하는 것은 SIP 메시지를 이용하여 등록을 요청하는 것을 포함하는, 펨토 액세스 포인트.
- 50적어도 하나의 컴퓨터로 하여금 적어도 하나의 펨토 액세스 포인트에 대한 보안 연관을 설정하게 하는 코드;적어도 하나의 컴퓨터로 하여금 상기 보안 연관을 이용하여 상기 적어도 하나의 펨토 액세스 포인트로부터 보안 등록 인증서를 요청하게 하는 코드;적어도 하나의 컴퓨터로 하여금 상기 보안 등록 인증서를 적어도 하나의 인가 컴포넌트에 의해 구성하게 하는 코드;및 적어도 하나의 컴퓨터로 하여금 운영자-제어 네트워크 엘리먼트로의 액세스를 위해 상기 보안 등록 인증서를 상기 펨토 액세스 포인트에서 수신하게 하는 코드를 포함하는, 컴퓨터 판독가능 매체.
Independent claims50
230 paragraphs, as filed
METHODS AND APPARATUSES TO PERFORM SECURE REGISTRATION OF FEMTO ACCESS POINTS IN OPERATOR CONTROLLED NETWORK
<b>35 Claim of priority under USC 119</b>
This patent claims priority to U.S. Provisional Patent Application No. 61/118,397, filed on November 26, 2008, assigned to the present assignee, and expressly incorporated herein by reference.
The following disclosure relates generally to wireless communications, and more particularly, to secure registration of a femto access point.
Historically, telephony (eg, telephone lines) has been made possible using circuit switched infrastructure operated by telephone companies. Conversely, mobile phone systems (eg, mobile phones) are being enabled using packet switched infrastructure operated by mobile operator companies. As mobile telephony is deployed, these mobile telephony systems are utilizing packet switched infrastructure for edge communications and circuit switched infrastructure to complete long haul telephony calls. As mobile communication systems become more popular, and as mobile communication systems function to provide more services (eg, multimedia functions, sophisticated voice functions, video conferencing, etc.), more functions suitable for packet switched infrastructure. tends to be used towards Also, more equipment is being deployed to connect to packet switched networks, such as femto cells, including, for example, user-used femto cells. At the same time, more services (eg, multimedia services, low-cost long distance calls, etc.) are being made available using relatively more packet-switched network infrastructure (eg, the Internet and other IP-based networks).
This trend has created an environment in which more infrastructure is placed under the control of entities other than telephone system operators, resulting in new security issues (eg, secure registration of femtocells described above) surface.
In the following, a simplified summary of one or more aspects is provided in order to provide a basic understanding of these aspects. This summary is not an exhaustive overview of all contemplated aspects, and is intended to neither identify key elements nor cover the scope of all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the detailed description that is presented later.
A method, apparatus, and system for performing secure registration of a femto access point for trusted access to an operator-controlled network element are disclosed. The method steps include establishing a security association for at least one femto access point, and making a request to an operator-controlled network element using the security association. Thereafter, the operator-controlled network element configures a security registration credential and sends the security registration certificate to the requesting femto access point to be trusted by the requesting femto access point to access the operator-controlled network element. grant access. Embodiments include establishing a security association via an IPsec security association received from a security gateway within an operator-controlled domain and using an operator-controlled database of IPsec internal addresses. In some embodiments, the femto access point performs a message exchange using one or more IMS protocol, and components including call session control function elements, which may authorize the femto access point in the IMS domain, and authorize may or may not access non-IMS network elements for
To the achievement of the foregoing and related objects, embodiments of the present invention are described below and particularly specified in the claims. The following description and associated drawings set forth in detail certain illustrative aspects of one or more embodiments. These embodiments, however, represent only a few of the various ways in which the principles of various embodiments may be employed, and the presented aspects are to be construed as including both such aspects and their equivalents.
The features, nature and advantages of the present disclosure will become apparent from the detailed description set forth with reference to the drawings. 1 illustrates a multiple access wireless communication system according to an embodiment of the present invention. 2 is a block diagram of a transmitter system and a receiver system according to an embodiment of the present invention. 3 illustrates a communication system that enables deployment of a femto access point in a network environment according to an embodiment of the present invention. 4 is an IMS environment in which the step of establishing security registration of a femto access point may be performed according to an embodiment of the present invention. 5 is an IMS system including components for establishing secure registration of a femto access point, in accordance with an embodiment of the present invention. 6 is a diagram of a system for establishing secure registration of a femto access point, according to an embodiment of the present invention. 7 is a flowchart of processing used to perform secure registration of a femto access point, in accordance with an embodiment of the present invention. 8 is a flow diagram of processing used to secure an enrollment certificate for a femto access point, in accordance with an embodiment of the present invention. 9 is a flowchart of performing a check for an existing/current/valid authorization for secure registration of a femto access point, according to an embodiment of the present invention. 10 is a protocol diagram illustrating a messaging protocol for performing secure registration of a femto access point using a convergence server in an IMS environment, according to an embodiment of the present invention. 11 is a protocol diagram illustrating a messaging protocol for performing secure registration of a femto access point in a full IMS environment, according to an embodiment of the present invention. 12 shows a block diagram of a system for secure registration of a femto access point seeking access to an operator-controlled network element, in accordance with an embodiment of the present invention. 13 shows a block diagram of a system that performs certain functions of a communication system for performing secure registration of a femto access point to access with an operator-controlled network element, in accordance with an embodiment of the present invention. FIG. 14 shows a block diagram of an apparatus for performing secure registration of a femto access point to access with an operator-controlled network element using hardware and software means, according to an embodiment of the present invention. 15 shows a block diagram of a system for performing specific functions of a femto access point, according to an embodiment of the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Various aspects are now described with reference to the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following disclosure, for purposes of explanation, various specific details are set forth in order to provide a thorough understanding of one or more aspects. It will be evident, however, that such aspect(s) may be practiced without these specific details. In other instances, well-known structures and devices are presented in block diagram form in order to facilitate describing one or more aspects.
In addition, various aspects of the present disclosure are described below. It should be understood that the following teachings may be embodied in a wide variety of forms and that any specific structure and/or function disclosed is merely representative. Based on the following teachings, one of ordinary skill in the art will appreciate that the disclosed aspect may be implemented independently of other aspects and that two or more aspects may be combined in various ways. For example, an apparatus may be implemented and/or a method may be performed using any number of the aspects presented. In addition, an apparatus may be implemented and/or a method may be performed using other structure and/or functionality other than or in addition to one or more aspects presented. By way of example, many of the described methods, devices, systems, and apparatuses are described in the context of implementing a system for performing secure registration of a femto access point in a wireless environment that includes a heterogeneous deployment of a femto access point. Those of ordinary skill in the art will appreciate that similar techniques may be applied to other communication environments.
BACKGROUND Wireless communication systems are widely deployed to provide various types of communication content such as voice, data, and the like. These systems may be multiple access systems capable of supporting communication with multiple users by sharing the available system resources (eg, bandwidth and transmit power). Examples of such multiple access systems include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, 3GPP long term evolution (LTE) systems, and orthogonal frequency division multiple access (OFDMA) systems. ) system is included.
Conventional fixed line communication systems, such as digital subscriber lines (DSL), cable lines, dial-up networks, or similar connections provided by Internet Service Providers (ISPs), are alternative and sometimes competing communication platforms for wireless communication. . However, recently, users are replacing fixed line communication with mobile communication. A number of advantages of mobile communication systems, such as user mobility, relatively small size of user equipment (UE), and easy access to the Internet as well as public switched telephone networks, make these systems very convenient and very popular. As users become more dependent on mobile systems for communication services that were conventionally obtained through fixed line systems, demands for increasing bandwidth, reliable services, high voice quality, and low prices are intensifying.
In general, a wireless multiple access communication system can simultaneously support communication for multiple wireless terminals. Each terminal communicates with one or more base stations via communications on the forward and reverse links. The forward link (or downlink) refers to the communication link from the base stations to the terminals, and the reverse link (or uplink) refers to the communication link from the terminals to the base stations. These communication links can be established through single input single output, multiple input single output, or multiple input multiple output (MIMO) systems.
In addition to the currently used mobile phone networks, a new class of small base stations is emerging. These small base stations have low power and typically use fixed line communications to connect to the network operator's core network. In addition, these base stations can be distributed for personal/private use in homes, offices, apartments, private hospitality facilities, etc., providing indoor/outdoor wireless coverage to mobile units. These private base stations are generally known as femto cells, or personal femto access points, or access points or Home Node B Units (HNBs), or Home-Evolved eNode B Units (HeNBs). Typically, these small base stations are connected to the Internet and the operator's network via a DSL router or cable modem. Femtocell base stations provide a new paradigm for mobile network access, enabling direct subscriber control over mobile network access and access quality.
The use of various types of wireless access points into communication networks (eg, public land mobile networks (PLMNs), network operators, mobile operator core networks, etc.) There is one solution provided to make this possible. This convergence, also known as fixed-wireless convergence, relates to the degree of interoperability between fixed line networks (eg, intranets, the Internet, etc.) and mobile communication networks (eg, cellular telephone networks). A femto access point described herein includes any suitable node, router, switch, hub, etc. configured to communicatively couple an access terminal (AT) using a communications network. A femto access point may be wired (eg, using Ethernet, Universal Serial Bus (USB), or other wired connection for communication), wireless (eg, using a wireless signal for communication), or both. have. Examples of femto access points include access point base stations (BSs), wireless local area network (WLAN) access points, wireless wide area network (WWAN) access points, including Worldwide Interoperability for Microwave Access (WiMAX) BSs, and the like. A femto access point includes an access point to a communications operator's network, such as a mobile operator's network, a circuit switched voice network, a combined circuit switched and packet switched voice and data network (or any packet voice and data network), and the like. Examples of femto access points include Node B (NB), Base Station Transceiver (BTS), Home NodeB (Home NodeB, Home) of various cell sizes/transmission power including macro cell, micro cell, pico cell, femto cell, etc. NodeB, HNB), home-evolved eNodeB (HeNB), or simply BS. In accordance with the aforementioned trend, the continuous deployment of femtocells can be expected to have more IP Multimedia Subsystem (IMS) based functions. Thus, a femto access point may be described as an IMS client femto access point with sufficient IMS functionality.
The introduction of various types of femto access points into conventional macro BS networks allows significant flexibility and customer control over personal access to such networks. A user terminal can often be configured to select a nearby femto access point or macro network BS depending on which one provides a better signal and/or other factors. In addition, femto access points may offer favorable rates compared to macro networks, at least in some circumstances, allowing users to reduce usage charges.
As wireless communication bandwidth and data rates increase over time, and AT processing and user interface capabilities become more sophisticated, users will be able to use mobile devices to perform functions that were previously only available through personal computers and fixed line communications. can
However, since conventional macro networks are often deployed in large-scale public use as a primary market, indoor reception will be poorer than outdoor reception (eg, due to absorption of radio frequency signals by buildings, insulators, landscaping, etc.) This makes mobile devices more inefficient than fixed line computers in these environments. However, a femto access point BS can provide a significant improvement in this environment. As an example, HNB and HeNB technologies (hereinafter collectively referred to as HNB) provide users with significant control over their personal wireless access, indoors and outdoors, avoiding most or all of these connectivity problems. Thus, HNB can further extend AT mobility even in sub-optimal environments for macro networks.
With the significant benefits of HNB and other access point deployments, opportunities for new services are emerging, and with these new services some challenges are surfaced. For example, mobile cellular services may include services that rely on Internet content (eg, news, video, video, etc.) and/or are enabled by Internet applications (real-time location services, online games, etc.). Services (eg, phone calls, voicemail, etc.) and text services (eg, SMS) are expanding. In some circumstances, a mobile user terminal (AT) may provide services using only an Internet Protocol (IP) network - even without participation of the mobile operator core infrastructure. As the provision of mobile operator communication services adopts more IP technologies, overall service provision is converging. Converged communication services are becoming universally available in a growing number of autonomous devices (eg, ATs, PDAs, smartphones and laptops).
In some cases, a session running an application can be started and fully completed without utilizing the mobile operator's core network infrastructure. In other cases, the application may be downloaded and installed on an autonomous device. For example, an application conforming to the IMS centralized service specification establishes a peer-to-peer session, performs some protocol implementing aspects of that application, exchanges multimedia content, and establishes a peer-to-peer session. can be terminated
IMS was initially recognized as part of the Third Generation Partnership Project (3GPP) specification for third generation (3G) cell phone networks. The 3rd Generation Partnership Project Specification defines the characteristics of IMS to deliver new services and applications to users of 3G cell phones. Part of this specification ensures that IMS is access network independent so that network operators can provide new services over different types of air interfaces and different types of cell phones.
For example, convergence addresses a number of technical deployment issues, including security, roaming, and quality of service (QoS). Among them, aspects of managing security will be described here. Security protocols attempt to ensure proper user authentication, authorization, and secrecy. In some implementations, the user's access terminal is authenticated (via a signing process), and this authentication is used to access a range of services accessed by the user.
Of course, any network-oriented authentication and/or authorization procedure is subject to compromise of certificates (e.g., cloning of certificates), malicious attacks (e.g., configuration attacks, software update fraud), malicious protocol attacks (e.g., man-in-the-middle attacks), denial of service attacks, attacks on user identity or network identity (e.g. false SIP messages such as INVITE or BYE) and any specific susceptible protocol (e.g. SAE/TLE TS33) .401) or deployment concepts (eg closed subscriber group concepts) are threatened, including user secret attacks (eg eavesdropping), or any of a variety of other attacks related to network use. Thus, network operators can use countermeasures to thwart these threats. Some exemplary countermeasures include techniques for mutual authentication, establishment of secure tunnels for backhaul links, use of trusted environment technologies inside network components, security mechanisms for operation, operation and maintenance (OAM), and authentication techniques on the host side. includes
In the deployment of 3GPP network infrastructure, femto access point deployment is usually unplanned or semi-planned, which means that the femto access point is installed without the control of the network operator. Thus, operators are limiting the capacity to implement secure deployment of these femto access points. Femto access points may be located in unsecured physical locations and thus may be physically exposed to malicious intent. Referring back to security threats related to deployment of femto access points, femto access points use Session Initiation Protocol (SIP) procedures specified in IETF RFC 3261, 3GPP, and 3GPP2 IMS specifications to provide network services (eg, GSM services). , UMTS, CDMA2000, circuit switched services, etc.) can register themselves with the operator's network. To ensure that these procedures are not abused by a femto access point that may be deployed in an unsecured physical location, a secure method for registering such a femto access point with a network is required.
For purposes of explanation, the following paragraphs introduce terminology used to describe embodiments of the present invention.
As is known, in accordance with various embodiments of the present invention, an AT may communicate a mobile station identifier (MSID). If the AT can have multiple identities, the user or AT selects (under user control or autonomously by the AT) a specific mobile station identity valid during the session. The MSID may be a mobile identification number (MIN) or an international mobile station identity (IMSI). A mobile identification number is a 34-bit number that is a digital representation of a decimal number assigned to a mobile station. The International Mobile Station Identity is a number up to 15 digits in length that uniquely identifies the mobile station internationally.
The techniques described herein include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal FDMA (OFDMA) systems, single carrier FDMA (SC-FDMA) systems, and other systems. It can be used for a variety of wireless communication systems, such as The terms "system" and "network" are often used interchangeably. A CDMA system implements radio technologies such as Universal Terrestrial Radio Access (UTRA), CDMA2000, and the like. UTRA includes Wideband CDMA (W-CDMA) and other variants of CDMA. CDMA2000 also includes IS-2000, IS-95, and IS-856 standards. A TDMA system may implement a radio technology such as General System for Mobile Communications (GSM). OFDMA systems can implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash OFDM®, etc. . UTRA and E-UTRA are part of the Universal Mobile Telecommunications System (UMTS). 3GPP Long Term Evolution (LTE) is the next release using E-UTRA, which uses OFDMA in the downlink and SC-FDMA in the uplink. UTRA, E-UTRA, UMTS, LTE and GSM are presented in documents from an organization named "3rd Generation Partnership Project (3GPP)". Also, CDMA2000 and UMB are presented in documents from an organization named "3rd Generation Partnership Project 2 (3GPP2)".
Single carrier frequency division multiple access (SC-FDMA) using single carrier modulation and frequency domain equalization is a technique with performance similar to OFDMA systems and essentially the same overall complexity. SC-FDMA signals have a lower peak-to-average power ratio (PAPR) due to their unique single-carrier structure. SC-FDMA can be used, for example, for uplink communication, where lower PAPR is more advantageous for access terminals in terms of transmit power efficiency. Therefore, SC-FDMA can be implemented as an uplink multiple access scheme in 3GPP Long Term Evolution (LTE) or Evolved UTRA.
As used herein, the terms "component," "module," "system," and the like are intended to refer to a computer-related entity, hardware, software, executable software, firmware, middleware, microcode, and/or any combination thereof. . For example, a module can be, but is not limited to being, a process running on a processor, an object, an executable thread of execution, a program, a device, and/or a computer. One or more modules may reside within a processor and/or thread of execution, and a module may be localized within one electronic device, and/or distributed between two or more electronic devices. In addition, these modules may execute from various computer readable media having various data structures stored therein. Modules may communicate via a network such as the Internet with another system, for example via a signal having one or more data packets (eg, data and/or signals from one component interacting with another component in a local system, distributed system, etc.) data) through local and/or remote processes. Further, the components or modules described herein may be reconfigured and/or supplemented by additional components/modules/systems to facilitate the achievement of various aspects, objects, advantages, etc. related thereto, It is not limited to the same configuration as depicted in certain drawings as will be appreciated by those skilled in the art.
In addition, various aspects are described in connection with an access terminal. AT may also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile communication device, mobile device, remote station, mobile terminal, access terminal (AT), user agent (UA), user device, user equipment (UE), etc. can A subscriber station may be a cellular telephone, cordless telephone, session initiation protocol (SIP) telephone, wireless local loop (WLL) station, personal digital assistant (PDA), portable device having wireless connection capability, or other processing device or processing device connected to the wireless modem. It may be a similar mechanism that facilitates wireless communication with the device.
As used herein, a computer storage medium can be any physical medium that can be accessed by a computer. By way of example and not limitation, such storage media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, smart cards and flash memory devices (eg, cards, sticks, key drive, etc.) or any other medium that can be used to convey or store program code in the form of instructions or data structures and that can be accessed by a computer. Hardware communication media may include any suitable device or data connection that facilitates transfer of a computer program from one entity to another using, at least in part, electrical, mechanical, and/or electromechanical hardware. In general, a data connection may be considered a computer-readable medium. For example, if the Software is transmitted from a website, server, or other remote source via coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave; Coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave may be included in the definition of such a medium, and any suitable hardware components associated with such medium may be included in the definition of a hardware communication medium. can Disks and discs as used herein include compact discs (CDs), laser discs, optical discs, DVDs, floppy disks, and Blu-ray discs, where the disk reproduces data magnetically, while the disc uses a laser to Optically reproduce data. Combinations of the above should also be included within the scope of computer-readable media.
In a hardware implementation, various illustrative logic, logic blocks, modules, and circuits of a processing unit described in connection with the aspects disclosed herein include one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing device (DSPD), programmable logic device (PLD), field programmable gate array (FPGA), discrete gate or transistor logic, discrete hardware components, general purpose processor, controller, microcontroller, microprocessor or performing the functions described It may be implemented or implemented in other electronic units designed to do so, or a combination thereof. A general purpose processor may be a microprocessor, but in the alternative, the processor may be a commercial processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, such as, for example, a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other suitable configuration. Further, at least one processor may include one or more modules operable to perform one or more of the steps and/or operations described herein.
In addition, various aspects or features described herein may be implemented in a method, apparatus, or article of manufacture using standard programming and/or engineering techniques. Further, steps and/or operations of a method or algorithm described in connection with the aspects disclosed herein may be implemented directly in hardware, in a software module executed by a processor, or in a combination of the two. may be implemented. Further, in some aspects, the steps and/or operations of a method or algorithm are implemented as codes and/or instructions on a device-readable medium, a machine-readable medium, and/or a computer-readable medium, which may be incorporated into a computer program product. may reside as at least one of, or any combination thereof, or a set thereof. As used herein, the term "article of manufacture" is intended to include a computer program accessible from any computer readable device or medium.
Also, the term "exemplary" is used to mean serving as an example, example, or illustration. Any aspect or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, use of the term illustrative is intended to present concepts in a concrete manner. As used herein and in the appended claims, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from context, "X employs A or B" is intended to mean one of the natural implicit permutations. That is, X employs A; X employs B; or if X employs both A and B, then "X employs A or B" is satisfied for any of these cases. Also, unless otherwise specified or unless the context is clear as to designating a singular form, the singular in the specification and claims should generally be construed to mean "one or more."
1, a multiple access wireless communication system 100 according to one embodiment is shown. The femto access point 102 (AP) consists of one antenna group including antennas 104 and 106 , another antenna group including antennas 108 and 110 , and an additional group of antennas including antennas 112 and 114 . Includes multiple antenna groups. However, although in Figure 1 only two antennas are shown for each antenna group, more or fewer antennas may be used for each antenna group. Access terminal 116 (AT) communicates with antennas 112 and 114 , where antennas 112 and 114 transmit information to access terminal 116 over forward link 120 and reverse link 118 . Receive information from the access terminal 116 through Access terminal 122 communicates with antennas 106 and 108 , where antennas 106 and 108 transmit information to access terminal 122 over forward link 126 and reverse link 124 . Receive information from the access terminal 122 . In a frequency division duplex (FDD) system, communication links 118 , 120 , 124 , and 126 may use different frequencies for communication. For example, forward link 120 may use a different frequency than that used by reverse link 118 .
Each group of antennas and/or the area in which they are designed to communicate is often referred to as a sector of a femto access point. In the embodiment of FIG. 1 , each antenna group is designed to communicate with access terminals within a sector of the areas covered by the femto access point 102 .
In communication over forward links 120 and 126 , the transmit antennas of access point 102 use beamforming to improve the signal-to-noise ratio of the forward links to different access terminals 116 and 122 . In addition, an access point that uses beamforming to transmit to access terminals randomly scattered throughout the femto access point's coverage is more likely to be transmitted to access terminals in neighboring cells than to a femto access point that transmits to all of its access terminals via a single antenna. It causes less interference.
A femto access point may be a fixed station used to communicate with a terminal, and may be referred to as an access point, a Node B, an evolved Node B (eNB), or some other terminology. An access terminal may also be referred to as a user equipment (UE), a wireless communication device, a terminal, or an access terminal may be referred to as a term consistent with some other terminology.
2 is a block diagram of an embodiment of a transmitter system 210 (also known as a femto access point) and a receiver system 250 (also known as an access terminal) of a MIMO system 200 . At the transmitter system 210 , traffic data for multiple data streams is provided from a data source 212 to a transmit (TX) data processor 214 .
In one embodiment, each data stream is transmitted via a respective transmit antenna. TX data processor 214 formats, codes, and interleaves the traffic data for each data stream based on a particular coding scheme selected for the data stream to provide coded data.
The coded data for each data stream may be multiplexed with pilot data using OFDM techniques. The pilot data is typically a known data pattern that is processed in a known way and can be used in the receiver system to estimate the channel response. For each data stream, the multiplexed pilot and coded data is modulated (i.e., symbol mapping ) to provide modulation symbols. The data rate, coding, and modulation for each data stream may be determined by instructions performed by the processor 230 using the memory 232 .
The modulation symbols for all data streams may be provided to a TX MIMO processor 220, which may further process the modulation symbols (eg, for OFDM). Then, the TX MIMO processor 220<sub>T</sub> N modulation symbol streams<sub>T</sub> transmitters (TMTR) 222a to 222t. In a particular embodiment, the TX MIMO processor 220 applies beamforming weights to the symbols of the data streams and to the antenna from which the symbols are transmitted.
Each transmitter 222 receives and processes each symbol stream to provide one or more analog signals, and further modulates (eg, amplifies, filters, and upconverts) the analog signals suitable for transmission over a MIMO channel. It provides a modulated signal. Also, N from transmitters 222a through 222t<sub>T</sub> The modulated signals are N<sub>T</sub> are transmitted from each of the antennas 224a to 224t.
In the receiver system 250, the transmitted modulated signals are<sub>R</sub> Received by antennas 252a to 252r, and a signal received from each antenna 252 is provided to a respective receiver (RCVR) 254a to 254r. Each receiver 254 modulates (eg, filters, amplifies, and downconverts) each signal, digitizes the conditioned signal to provide samples, and further processes the samples for a corresponding "received" symbol. provides a stream.
The RX data processor 260 may generate N based on a particular receiver processing technique.<sub>R</sub> N from receivers 254<sub>R</sub> Receive and process N received symbol streams<sub>T</sub> provides "detected" symbol streams. RX data processor 260 demodulates, deinterleaves, and decodes each detected symbol stream to recover traffic data for the data stream. The processing by RX data processor 260 is complementary to processing performed by TX MIMO processor 220 and TX data processor 214 in transmitter system 210 .
Processor 270 using memory 272 periodically determines which precoding matrix to use, as described above. Processor 270 also formulates a reverse link message comprising a matrix index portion and a rank value portion.
The reverse link message may include various types of information about the communication link and/or the received data stream. The reverse link message is processed by a TX data processor 238 , which also receives traffic data for multiple data streams from a data source 236 , modulated by a modulator 280 , and transmitters 254a through 254r. is adjusted by , and transmitted back to the base station 210 .
In transmitter system 210 , modulated signals from receiver system 250 are received by antennas 224 , conditioned by receivers 222 , demodulated by demodulator 240 , and an RX data processor ( 242 ) to extract the reverse link message transmitted by receiver system 250 . In addition, the processor 230 determines which precoding matrix to use to define the beamforming weight, and processes the extracted message.
In one aspect, logical channels are classified into control channels and traffic channels. The logical control channels include a broadcast control channel (BCCH), which is a DL channel for broadcasting system control information, and a paging control channel (PCCH), which is a DL channel for carrying paging information. Multicast Control Channel (MCCH) is a point-to-multipoint DL channel used to transmit multimedia broadcast and multicast service (MBMS), scheduling and control information for one or several MTCHs. am. In general, after establishing an RRC connection, this channel is only used by ATs receiving MBMS (note that it is old MCCH+MSCH). A Dedicated Control Channel (DCCH) is a point-to-point bidirectional channel used by ATs that transmit dedicated control information and have an RRC connection. In one aspect, the logical traffic channels are: a Dedicated Traffic Channel (DTCH), which is a point-to-point bidirectional channel dedicated to one UE for conveying user information, and a Point-to-Multipoint DL for transmitting traffic data. It includes a multicast traffic channel (MTCH), which is a channel.
In one aspect, Transport Channels are classified into DL and UL. The DL transport channel includes a broadcast channel (BCH), a downlink shared data channel (DL-SDCH) and a paging channel (PCH), and a PCH (DRX cycle) for support of AT power saving is transmitted to the network. indicated by the AT) is broadcast for the entire cell and mapped to PHY resources that can be used for other control/traffic channels. The UL transport channels include a random access channel (RACH), a request channel (REQCH), an uplink shared data channel (UL-SDCH) and a plurality of PHY channels. PHY channels include a set of DL channels and UL channels.
DL PHY channels include:
Acknowledgment Channel (ACKCH)
Common Control Channel (CCCH)
Common Pilot Channel (CPICH)
DL Physical Shared Data Channel (DL-PSDCH)
Load Indicator Channel (LICH)
Multicast Control Channel (MCCH)
Paging Indicator Channel (PICH)
Shared DL Control Channel (SDCCH)
Shared UL Assigned Channel (SUACH)
Synchronization Channel (SCH)
UL Power Control Channel (UPCCH)
UL PHY channels include:
Acknowledgment Channel (ACKCH)
Antenna Subset Indicator Channel (ASICH)
Wideband Pilot Channel (BPICH)
Channel Quality Indicator Channel (CQICH)
Physical Random Access Channel (PRACH)
Share Request Channel (SREQCH)
UL Physical Shared Data Channel (UL-PSDCH)
For the purposes of this document, the following abbreviations apply:
AMD Response Confirmed Mod Data
ARQ Auto Resend Request
AT access terminal
ATM Response Confirmed Mode
BCCH broadcast control channel
BCH broadcast channel
C-Control-
CCCH Common Control Channel
CCH control channel
CCTrCH coded composite transport channel
CP cyclic prefix
CRC Cyclic Redundancy Check
CSG Closed Subscriber Group
CTCH common traffic channel
DCCH dedicated control channel
DCH dedicated channel
DL downlink
DL-SCH downlink shared channel
DSCH Downlink Shared Channel
DTCH dedicated traffic channel
FACH Forward Link Access Channel
FDD Frequency Division Duplex
HLR Home Position Register
HNBID Femtocell ID
HSS Home Subscriber Server
Call session control function of I-CSCF statement
IMS IP Multimedia Subsystem
IMSI International Mobile Station Identity
L1 Layer 1 (Physical Layer)
L2 Layer 2 (Data Link Layer)
L3 Layer 3 (Network Layer)
LI length indicator
LSB least significant bit
MAC Media Access Control
MBMS Multimedia Broadcast Multicast Service
MBSFN Multicast Broadcast Single Frequency Network
MCCH MBMS Point-to-Multipoint Control Channel
MCE MBMS Coordination Entity
MCH multicast channel
MRW Moving Receive Window
MSB most significant bit
MSC Mobile Switch Center
MSCH MBMS Point-to-Multipoint Scheduling Channel
MSCH MBMS control channel
MTCH MBMS Point-to-Multipoint Traffic Channel
NASS Network Access Subsystem
P2P peer-to-peer
PCCH paging control channel
PCH paging channel
P-CSCF proxy call session control function
PDCCH Physical Downlink Control Channel
PDSCH Physical Downlink Shared Channel
PDU protocol data unit
PHY physical layer
PhyCH physical channel
RACH random access channel
RACS resource and admission control subsystem
RLC radio link control
RRC radio resource control
SAP service access point
S-CSCF serving cell session control function
SDU service data unit
SeGW Security Gateway
SHCCH Shared Channel Control Channel
SIP Session Initiation Protocol
SLF Subscriber Position Function
SN sequence number
SUFI Super Field
TCH traffic channel
TDD time division duplex
TFI Transport Format Indicator
TISPAN Telecom & Internet Convergence Service & protocol
TM transparent mode
TMD transparent mode data
TMSI Temporary Mobile Subscriber Identity
TTI Transmission Time Interval
U-User-
UE user equipment
UL Uplink
UM unacknowledged mode
UMD Unacknowledged Mode Data
UMTS Universal Mobile Communication System
UTRA UMTS Terrestrial Radio Access
UTRAN UMTS Terrestrial Radio Access Network
3 illustrates an example communication system 300 that facilitates deployment of a femto access point (BS) (eg, HNB) in a network environment. The communication system 300 includes a number of femto access points implemented as femto access point(s) 310 and/or IMS femto access point(s) 311 installed in a small network environment. Examples of small network environments may include virtually any indoor and/or indoor/outdoor facility 330 . Femto access point(s) 310 may be configured to serve an associated access terminal 320 (AT), such as, for example, an AT that may be included in an access group (eg, CSG) associated with the femto access point. or, optionally, configured to serve an alien or visited access terminal 320 . The access terminal 320 communicates with the macro cell via a wireless link 360 , and via the wireless link 361 and/or the wireless link 362 , one or more femto access points 310 and/or one or more IMS femto access points. It communicates with point 311 . Each femto access point (eg, femto access point 310 and/or IMS femto access point 311 ) is connected to a DSL router (not shown), or alternatively, a cable modem, broadband access via power line, satellite It is further coupled to the IP network 340 via an IP network connection or similar broadband IP network connection 370 . Additional networks are accessible via IP network 340 including mobile operator core network 350 , IMS network 390 , and/or third party operator network 380 . The mobile operator core network may include a mobile switch center (MSC).
In some embodiments, the femto access point 310 communicates with a femto access point gateway. The femto access point gateway may be implemented as an HNB gateway (HNB-GW) or a home-evolved eNodeB gateway (HeNB-GW) or other gateway device capable of performing message exchange under the control of a computer.
The femto access point 310 may be implemented as a Home NodeB Unit (HNB), or a Home-Evolved NodeB Unit (HeNB). As shown, the access terminal 320 may operate in a macro cellular environment and/or in a residential small network environment using various techniques described herein. Thus, at least in some disclosed aspects, the femto access point 310 may be compatible with any suitable existing access terminal 320 . While the aspects described herein use the 3GPP specification, these aspects include variants of 3GPP (Release 99 [Rel99], Rel5, Rel6, Rel7) as well as 3GPP2 technologies (1xRTT, 1xEV-DO, Rel0. RevA, RevB) and other It should be appreciated that known and related techniques may also be applied. In this embodiment described herein, the owner of the HNB 310 subscribes to a mobile service, such as, for example, a 3G mobile service provided via the mobile operator core network 350 . Access terminal 320 may operate in both macro cellular environments and residential or private small network environments. The femto access point 310 is compatible with any existing access terminal 320 .
In some embodiments of the present invention, a Femto Access Point (FAP) is used to interface within an IP Multimedia Subsystem (IMS) environment to provide network services such as GSM, UMTS, LTE/dual mode, CDMA2000, circuit switched services, etc. can be To ensure that this use is not abused by the FAP (which may be hosted in a location not known to be trusted by the network operator), it would be advantageous to provide a secure method and apparatus for registering the FAP with the network. .
In some embodiments of the present invention, a femto access point (FAP) or HNB registers itself with an operator's network to provide network services such as GSM, UMTS, LTE/dual mode, CDMA2000, circuit switched services; It uses SIP procedures specified in IETF RFC 3261 and 3GPP and 3GPP IP Multimedia Subsystem (IMS) specifications. To ensure that this procedure is not abused by the FAP (which may be hosted in a location not known to be trusted by the network operator), it would be advantageous to provide a secure method and apparatus for registering the FAP with the network. .
4 is an IMS environment in which an environment for setting security registration of a femto access point may be implemented, according to an embodiment of the present invention. Optionally, this environment 400 may exist in the context of the architecture and functionality of FIGS.
The illustrated IMS architecture organizes the networking infrastructure into separate planes with standardized interfaces to each other. Each interface is specified with reference points that define protocols and functions. Functions may be mapped to any one or more planes; A single device may include multiple functions.
Environment 400 consists of three planes: an application plane 402 , a control plane 404 and a user plane 406 .
The application plane 402 provides the infrastructure for provision and management of services, and a standard interface to common functions including configuration storage, identity management, user state (eg, presence and location) and other functions. define In some cases, the data corresponding to the above may be stored and managed by a home subscriber server (HSS).
The application plane 402 may include a number of application servers 408 (AS) for performing various services (eg, telephony application servers, IP multimedia service switching functions, open service access gateways, etc.). The application server is responsible for performing functions for subscriber session management, including managing the status of phone calls. A service provider may deploy one or more application servers to create new applications. In addition, the application plane provides an infrastructure for provision of the charging function 410 and other charging-related services. The application plane provides the infrastructure for control of voice and video calls and messaging, and additional services can be provided by functions within that control plane.
As shown, the control plane 404 is logically disposed between the application plane 402 and the user plane 406 . In the illustrative case, the control plane routes call signaling, performs aspects of authentication and authorization, and performs some private functions. Functions in the control plane may interface with the charging function 410 and may generate certain types of charging related services.
In some embodiments, the control plane may organize logical connections between various other network functions and facilitate registration of endpoints, routing of SIP messages, and overall coordination of media and signaling resources. As shown, the control plane contains all session control functions, which include a proxy CSCF (shown as P-CSCF 412), a serving CSCF (shown as S-CSCF 414), and an inquiry CSCF (I- may be integrally implemented by the CSCF (shown as 416). The control plane may also include a Home Subscriber Server (HSS) database. The HSS maintains a service profile for each user including registration information, preferences, roaming information, voicemail options, friends list, and the like. In addition, the HSS may maintain service profile information related to the femto access point (eg, the femto access point 310 and/or the IMS femto access point 311 ). Centralization of subscriber information can facilitate provision of services, constant application access, and profile sharing among multiple access networks. In some cases, the Home Location Register (HLR) may be reachable over the network and may operate in place of (or in conjunction with) the HSS. Multiple core networks 420 (eg, mobile operator core networks 350 ) may be reached via interconnect boundary control function component 418 . Access to the core network 420 is through a border gateway (eg, I-BCF 418 ). A perimeter gateway may be deployed to enforce access policies and control the flow of traffic to and from the core network 420 . In some circumstances, the Interconnect Boundary Control Function (I-BCF) controls transport level security and notifies the RACS 426 which resources are required for the call.
Control plane 404 implements a call session control function (CSCF) that includes:
Proxy CSCF (P-CSCF 412) is the first point of contact for the user by IMS. The P-CSCF is responsible for the security of messages between the network and users, as well as the allocation of resources for media flows.
· Query CSCF (I-CSCF 416) is the first point of contact from the peered network. The I-CSCF is responsible for querying the HSS to determine the S-CSCF for the user, and also hides the operator's topology from the peer network (e.g., using a topology-hiding inter-network gateway, ie, THIG). can do.
Serving CSCF (S-CSCF 414) is responsible for processing registration to record each user's location, user authentication, and call processing (including routing of calls to applications). The operation of the S-CSCF may be partially controlled by a policy stored in the HSS.
User plane 406 provides access from user equipment 424 (eg, terminal 320) via various networks (eg, mobile, WiFi and broadband networks, etc.) to the core QoS-enabled IPv6 network. (422). This infrastructure is designed to provide a wide range of IP multimedia server-based and peer-to-peer (P2P) services.
5 is an IMS system including components for establishing secure registration of a femto access point, in accordance with an embodiment of the present invention. Alternatively, the system 500 may be implemented in the context of the architecture and functionality of FIGS. 1-4 . It should be understood, however, that system 500 or any operation of the system may be performed in any desired environment.
The difference shown in FIG. 5 compared to FIG. 4 is a representation of a femto access point 310, a femto access point gateway 506 (FAP-GW) and an operator-controlled network 521 connected with the user equipment 424, The operator-controlled network 521 includes (as shown) a secure gateway (eg, SeGW 502 ), and an operator-controlled IPsec address dataset 504 .
In some embodiments, one or more femto access points 310 register themselves with the S-CSCF of the IMS domain using SIP. Certain procedures and/or rules may be invoked to provide guaranteed security and threat-resistance registration to network environments and protocols. E.g:
The FAP mutually authenticates itself to a secure gateway (eg SeGW) located in the operator's network and establishes a secure tunnel (eg IPSec ESP);
A FAP forwards any IP packets from another FAP with a source IP address that has an address equal to the address defined by that FAP (eg IPSec tunnel inner header source IP address, source IP address of the FAP); will not process;
Any SIP message originating from the FAP 310 will use the IPSec tunnel internal address assigned by the SeGW (ie use an operator-controlled database of IPSec internal addresses);
· The address space inside the tunnel will be under the control of the operator;
· The FAP subnet address is not reused for any other purpose by the operator of the communication network;
In addition to the above rules, other rules may apply.
Various authentication techniques have been proposed for IMS registration (eg, IMS AKA, SIP digest (with or without TLS), GPRS IMS bundle authentication, NASS IMS bundle authentication, trusted node authentication (to ICS), i.e. TNA, etc.). These authentication technologies and how they coexist in IMS are defined by 3GPP of TS 33.203 (Rel-8), which specification is incorporated herein by reference in its entirety.
The techniques described above are deployed to create additional requirements or problems. Embodiments of the invention described herein may utilize some of the techniques known as Trusted Node Authentication (TNA) for secure registration of femto access points. Assumptions related to various embodiments include:
· A trusted node is a node that is completely under the control of an operator or has been verified to be trusted (eg, through some independent authentication, software code signing, etc.).
· A trusted node (such as FAP) inserts an integrity-protected flag (eg, with a value of "Authenticated").
· No P-CSCF exists between the trusted node and the I/S-CSCF (ie, the P-CSCF may remove the integrity-protect flag).
Following this rule, if the FAP is authenticated by the home network (eg, using FAP device authentication), components within the IMS domain may treat the FAP as a trusted node. More specifically, performing IMS FAP registration may use a trusted node authentication technique; A FAP can be considered a trusted node if it has been authenticated to the operator network. In some embodiments, the network operator may further verify (eg, using methods such as secure boot, code signing, etc.) that the FAP remains trusted.
The techniques described above for FAP IMS registration do not require any further configuration or development in the FAP, however, in some embodiments, the FAP may use a SIP digest for the IMS registration procedure.
Once the FAP is successfully registered using one of the authentication methods, the FAP may use its IMS infrastructure and provide network services (eg circuit switched services, etc.) to the AT using SIP messaging.
System 500 implements a communication system that performs secure registration of a femto access point for access to an operator-controlled network element. Various functions are shown including a secure gateway element (eg, SeGW 502 ) configured to manage an IPsec address dataset 504 within an operator-controlled network 521 . The femto access point (eg, FAP 310 ) is configured to request a security association from a secure gateway element and to request a security enrollment certificate from a network element within the operator-controlled network 521 . This operator-controlled network element may be configured to configure the requested security enrollment certificate and send the requested security enrollment certificate to the femto access point. The requested security enrollment credential may be stored in non-volatile memory and may be cached for subsequent requests for the same secure enrollment credential. The communication system includes at least one secure gateway element (eg, IPsec address dataset 504) for managing IPsec internal addresses. As shown, the femto access point sends a SIP message (see message 1140). ) using a Session Control Function (CSCF) element (e.g., P-CSCF 412, S-CSCF 414 ), I-CSCF 416, etc.) The communication system may exchange a message containing the femto access point profile (eg, such as the femto access point's IMS identity) with the authorization component, A component may include a home subscriber server, one or more components within the mobile operator core network 350 , and one or more components within a third party operator network 380 .
6 is a diagram of a system for establishing secure registration of a femto access point, according to an embodiment of the present invention. Alternatively, the system 600 may be implemented in the context of the architecture and functionality of FIGS. 1-5 . It should be understood, however, that system 600 or any operation of the system may be performed in any desired environment.
As shown, system 600 includes an access terminal 320 that communicates with one or more network elements 625 via a wireless link (eg, wireless link 361 , wireless link 362 ). More particularly, access terminal 320 is shown in communication with a femto access point (eg, femto access point 310 and IMS femto access point 311 ). The femto access point communicates with an IP network 340 (eg, the Internet), and the IP network communicates with a plurality of operator-controlled network elements 626 . In some embodiments, the operator-controlled network element 626 includes one or more authorization components 635 . The operator-controlled network element 626 may include one or more operator-controlled network elements 626 (eg, FAP-SW 506 , one or more CSCF components, one or more security gateways 502 , and one or more femtocell convergence servers). (610)). A Femtocell Convergence Server (FCS) can be included in an IMS environment and act as an interworking gateway emulating the protocols and functions of a Mobile Switch Center (MSC), as well as operating or emulating as an IMS application server, and switching between the two. Thus, the existing MSC-related service is delivered to the femto access point deployed in the IMS environment.
Also shown is an application component 635 . The authorization component may consist of one or more network components capable of performing one or more authorization operations for secure registration of the femto access point. Examples of authorization component 635 include HSS 620 , one or more components within operator core network 350 (eg, HLR 630 ), and one or more components within third party operator network 380 . do.
The femto access point gateway 506 (FAP-GW) is configured to support messaging by and between any network elements within the operator-controlled network element 626 and one or more femto access points (eg, a femto access point). 310 , which serves for messaging by and between IMS femto access points 311 ), possibly including a secure gateway 502 . The secure gateway 502 may be implemented as a separate component from the femto access point gateway as shown, or the secure gateway 502 may be implemented as a module within the femto access point gateway as described below.
Any one or more of the authorization components 635 may include a list (eg, IPsec address dataset 504 ), which list may include various types of identifiers or identifiers. The list may also be configured to associate one type of identifier with another type of identifier (eg, a list of pairs, a list of tables, etc.). Such a list may be stored in memory, and valid identifiers and/or pairs of valid identifiers for identifying valid accesses (eg, any one or more access rights), or any configuration of identifiers identifying valid accesses. may include relationships in
Any one or more network elements 625 may include a processor and memory. For example, the femto access point 310 may include a femto access point processor and a femto access point memory. Similarly, femto access point gateway 506 may include a femto access point gateway processor and femto access point gateway memory.
In one embodiment of the present invention, system 600 may be used to perform secure registration of a femto access point for access to an operator-controlled network element. More specifically, a femto access point (eg, FAP 310 , IMS FAP 311 ) may be configured to establish a security association, and a security association (eg, including an IPsec internal address, etc.) may be used to request a security enrollment certificate from an operator-controlled network element 626 (eg, P-CSCF 412 , S-CSCF 414 , etc.). This operator-controlled network element 626 configures the requested security registration certificate and is configured to send (ie, directly or via relay) the security registration certificate to the requesting femto access point for access to the operator-controlled network element. can be In some cases, establishing the security association is established by a function of a security gateway (such as SeGW 502 ), which function in association with at least one operator-controlled network element using an operator-controlled database of IPsec internal addresses. can be performed.
In an exemplary embodiment, the femto access point registers using a SIP message sent to a call session control function element (eg, P-CSCF 412 , S-CSCF 414 , IS-CSCF 416 , etc.) may be configured to request Of course, the session control function element may be configured to hold a certificate, or the session control function element may include an authorization component 635 (eg, HSS 620 , HLR 630 , mobile operator core network 350 , It may also be configured to obtain a security registration certificate via a network message exchange with a third party operator network 380, etc.).
Any one of the operator-controlled network elements 626 described above may be configured to relay an access request from an access terminal (eg, access terminal 320 , UE 424 , etc.), the relayed access request may be relayed using a SIP message. Any one or more operator-controlled network elements may be configured such that the relayed access request includes an integrity-protection indication.
7 is a flowchart of processing used to perform source registration of a femto access point, in accordance with an embodiment of the present invention. Alternatively, the system 700 may be implemented in the context of the architecture and functionality of FIGS. 1-6 . It should be understood, however, that system 700 or any operation of the system may be performed in any desired environment.
As shown, the steps performed by the femto access point to become a trusted node of the IMS domain include powering the femto access point components (see act 710 ) and physically connecting to the IP network (see act 710 ). see operation 720). Once the physical layer connection is established, the femto access point begins to establish a connection at the MAC and link layer, and at some points, the femto access point requests a security association from a component in the IMS domain. The request for a security association may be granted by the secure gateway, or a proxy to the secure gateway that is a member of the operator-controlled network element 626 (see act 730 ). In embodiments of the present invention, the femto access point may process a SIP message, and thus, the femto access point sends a SIP register message (see operation 740 ), which message is sent by the CSCF component in the IMS domain. can be processed. The CSCF component requests authorization by the authorization component 635 , which is a member of the operator-controlled network element 626 .
The CSCF may request authorization (act 750) and receive the requested authorization from an authorization component. If authorized (see decision 755 ), the CSCF may send a SIP OK message to the requesting femto access point (see operation 760 ). Of course, it is possible for the authorization request to be denied, in which case decision 755 would deny the authorization request.
As shown, the CSCF requesting authorization (operation 750 ) sends a SIP OK message to the requesting femto access point (see operation 760 ), the requesting femto access point being authorized by the authorization component 635 . becomes a trusted node in the network domain corresponding to the domain to which it was authorized (see operation 770).
As noted above, the authorization component may be an authorization component within the set of operator-controlled network elements 626 , such authorization component being an HSS, HLR, authorization component within a mobile operator core network or a third party operator network 380 . It may be an authorization component.
The femto access point that sent the SIP register message (operation 740) may receive the requested authorization, and if authorized (see operation 770), the femto access point that transmitted the SIP register message is trusted within the authorized domain. become a node that becomes In an exemplary embodiment, the femto access point utilizes SIP messaging that includes a no-determination protection indication field set to "authorized" (see act 780). The femto access point starts receiving messages from the AT (legacy AT, UE, SIP phone, etc.) and converts it to SIP as needed (see act 790).
8 is a flow diagram of processing used to secure an enrollment certificate for a femto access point, in accordance with an embodiment of the present invention. Alternatively, the system 800 may be implemented in the context of the architecture and functionality of FIGS. 1-7 . It should be understood, however, that system 800 or any operation of the system may be performed in any desired environment.
As shown, the CSCF (eg, serving CSCF 414 ) receives the SIP registration request (see act 810 ), and checks for existing/current/valid authorization (see decision 825 ). (see operation 820). If the device corresponding to the received SIP registration request is authorized in operation 810, the request is satisfied with "OK" (see operation 830). Otherwise, the registration request is interpreted as a request for a new authorization, and a request is made to an authorization component (eg, HSS, HLR, mobile operator core network or third party operator network, etc.) (see act 840 ). The authorization component responds to the requestor, and the CSCF receives the requested certificate (see act 850). In some examples, an additional check related to authorization may be performed (see act 860 ), and if the authorization test is successful (see decision 865 ), then if the credential is verified by the requestor (eg, a femto access point or a femto access point) gateway, etc.). Of course, an authorization check is performed (see act 860), and if the authorization test fails, the registration request is rejected (see act 870). In some cases, the registration request is rejected by returning a message indicating the reason for rejecting the request, in other cases no response is returned to the requestor, and the requestor does not receive the requested certificate. In another example, the registration request is granted and an authorization certificate is sent to the requestor (see act 880).
9 is a flowchart for performing a check for an existing/current/valid authorization for secure registration of a femto access point. Alternatively, the system 900 may be implemented in the context of the architecture and functionality of FIGS. It should be understood, however, that system 900 or any operation of the system may be performed in any desired environment.
System 900 may be invoked whenever an operator-controlled network element attempts to satisfy an authorization request (see act 820 ). In some cases, the CSCF or other operator-controlled network element may store the femto access point's authenticated authorization in cache memory (see act 910 ). In some cases, an authenticated authorization for the femto access point may not exist in cache memory, and the CSCF or other operator-controlled network element may attempt to retrieve a genuine authorization from the authorization component 635 . In such a case, the operator-controlled network element may select one or more authorization components (see act 920 ) and perform network messaging to establish authentication of the selected authorization components (see operation 930 ). If the authentication step described above is successful, the operator-controlled network element may submit a request for an authorization certificate (see act 940), receive such authorization certificate, and proceed to cache the certificate (act 950). )), and may transmit the certificate to the requestor (see operation 960 ).
10 is a protocol diagram illustrating a messaging protocol for performing secure registration of a femto access point using a convergence server in an IMS environment, according to an embodiment of the present invention. Alternatively, the system 1000 may be implemented in the context of the architecture and functionality of FIGS. 1-9 . It should be understood, however, that system 1000 or any operation of the system may be performed in any desired environment.
As shown, the protocol 1000 is an authorization in the form of an access terminal AT/UE 1010 , a femto access point FAP 1012 , a security gateway SeGW 1014 , a CSCF (IMF) 1016 , and an HSS 1018 . It is performed by the components that contain the component. Also participating in the protocol is the femtocell convergence server FCS 1020 .
The protocol may start at any point in time, and the specific order and interleaving of messages and actions contained in the protocol is provided for purposes of illustration.
As shown, the FAP 1012 initiates a protocol exchange, possibly via a femto access point gateway (not shown), to establish an IPsec security association from the SeGW 1014 (see message 1022 ). The SeGW may respond by returning the requested IPsec association (see message 1024). Using the obtained IPsec association, the FAP 1012 may send a SIP Register message to the CSCF (see message 1026). In some cases the CSCF may verify authorization (see operation 1028 ), and in some other cases the CSCF may request authorization from an authorization component (eg, HSS 1018 ). In this case, the CSCF sends a request (including the femto access point profile) to the authorization component (see message 1030 ). Assuming that the authorization component can satisfy the authorization request, the authorization component returns an authorization certificate (see message 1032 ). A CSCF having sufficient credentials to authorize at least some access to the network elements covered by that certificate may perform additional authorization steps (see act 1034) and send a SIP OK message to the requestor (message (1036)). In some cases, the CSCF may perform additional registration steps; For example, the CSCF may initiate a third-party core network registration (see message 1037), and the third-party core network registration may return a certificate to the CSCF (not shown).
Given the presence of message 1036, a femto access point is a node trusted within the domain corresponding to its certificate, and may be considered a node trusted by that domain. Thus, the access terminal (eg, AT/UE 1010 ) may initiate an attach or register request (see message 1038 ), which may be converted to a SIP message (see operation 1039 ). It is usually forwarded to the CSCF as a SIP INVITE message (see message 1040), and transmitted and/or relayed to the FCS 1020 (see message 1042). As noted above, FCS functions to bridge IMS domain services with non-IMS domain services (eg, in a circuit switched domain) and includes converting SIP messages to legacy messages (see act 1043). . Thus, the SIP INVITE message received at the FCS can be converted into a request (see message 1044) and an authorization response from the non-IMS domain (see message 1046), and the authorization is converted back to the SIP message format (see message 1046). see operation 1047), possibly returned to the requestor by a relay (see message 1048, message 1049). As shown, this relay becomes an attach or register "OK" message and is sent to the legacy AT 1010 (see message 1052).
11 is a protocol diagram illustrating a messaging protocol for performing secure registration of a femto access point in a full IMS environment, according to an embodiment of the present invention. Alternatively, the system 1100 may be implemented in the context of the architecture and functionality of FIGS. 1-10 . It should be understood, however, that system 1100 or any operation of the system may be performed in any desired environment.
As shown, protocol 1100 includes authorization in the form of access terminal AT/US 1010 , femto access point FAP 1012 , secure gateway SeGW 1014 , CSCF (IMF) 1016 , and HSS 1018 . It is performed by components that contain components. This protocol may be initiated at any point in time, and the specific order and interleaving of messages and actions contained in the protocol is provided for purposes of illustration. As shown, the FAP 1012 initiates a protocol exchange to establish an IPsec security association from the SeGW 1014 (see message 1122 ). The SeGW may respond by returning the requested IPsec association (see message 1124). Using the obtained IPsec association, the FAP 1012 may send a SIP Register message to the CSCF (see message 1126). In some cases the CSCF may verify authorization (see operation 1128 ), and in some other cases the CSCF may request authorization from the authorization component HSS 1018 . In this case, the CSCF 1016 sends a request (including the femto access point profile) to the authorization component HSS 1018 (see message 1130 ). Assuming the authorization component can satisfy the authorization request, the authorization component returns an authorization certificate (see message 1132 ). The messaging protocol that performs secure registration of a femto access point within a full IMS environment does not require interaction with the FCS 1020 (eg, third-party registration). This service can be delivered completely within the IMS domain. Also, the CSCF 1016 possibly connected to the HSS has an essential database for checking whether the FAP is a trusted node. That is, CSCF 1016 and HSS 1018 are members of a group of operator-controlled network elements 626 operating within operator-controlled network 521 . Thus, the CSCF 1016 possibly associated with the HSS may access an authorization database containing at least the IPsec address dataset 504 and respond with a SIP "OK" message (see message 1135), which The message is relayed to the requesting FAP 1012 (see message 1137). In other situations, HSS 1018 may not have direct access to the necessary authorization database and may perform some operations including additional messaging (not shown) to check for the existence of authorization certificates (act 1134 ). ) Reference). Given the presence of message 1137, the femto access point is a node trusted within the domain corresponding to its certificate, and may be considered as a node trusted by that domain. Thus, the access terminal (eg, AT/UE 1010 ) may initiate an attach or registration request (see message 1138 ), which request is forwarded to CSCF 1016 possibly as a SIP INVITE message. (see message 1040), transmitted and/or relayed to CSCF 1016 (see message 1142), CSCF 1016 may provide or manage IMS domain services using IMS domain networking components. (ie, the assistance of the FCS 1020 or the assistance of any non-IMS domain component is unnecessary). Thus, the SIP INVITE message received at the CSCF 1016 may initiate a SIP protocol exchange for provision of IMS services, and the provision of such services may include transmission of the SIP message to the FAP 1012 (see message 1144); and transmission to the AT/UE 1010 (see message 1150 ).
12 shows a block diagram of a system for performing secure registration of a femto access point for access to an operator-controlled network element. Alternatively, the system 1200 may be implemented in the context of the architecture and functionality of the embodiments described herein. It should be understood, however, that system 1200 or any operation of the system may be performed in any desired environment. As shown, system 1200 includes a plurality of modules each coupled to communication link 1205 , any module may communicate with other modules via communication link 1205 . Modules of this system may perform the method steps in system 1200 individually or in combination. Any method steps performed within system 1200 may be performed in any order unless specified in a claim. As shown, system 1200 implements a method for access to an operator-controlled network element, wherein system 1200 includes a module (module 1210) for establishing a security association for at least one femto access point. ) Reference); a module for requesting a security enrollment certificate from at least one femto access point using a security association (see module 1220 ); a module (see module 1230) for configuring a secure enrollment certificate by at least one authorization component; and a module (see module 1240 ) for receiving, at the femto access point, a security enrollment certificate for access to the operator-controlled network element.
13 shows a block diagram of a system for performing certain functions of a communication system for performing secure registration of a femto access point. Optionally, the system 1300 may be implemented in the context of the architecture and functionality of the embodiments described herein. It should be understood, however, that system 1300 or any operation of the system may be performed in any desired environment. As shown, system 1300 includes a plurality of modules including a processor and memory, each module coupled to a communication link 1305 , and any module to other modules via a communication link 1305 . can communicate with Modules of this system may perform the method steps in system 1300 individually or in combination. Any method steps performed within system 1300 may be performed in any order unless specified in a claim. As shown, FIG. 13 illustrates a secure gateway element (see module 1310 ) configured to implement a communication system in accordance with system 1300 , and to manage IPsec address datasets within an operator-controlled network; at least one femto access point (see module 1320 ) configured to request a security association from a secure gateway element and configured to request a security enrollment certificate; at least one operator-controlled network element (see module 1330 ) configured to configure the requested security enrollment credential and to store the requested secure enrollment credential, and to transmit the requested secure enrollment credential to the femto access point; Included modules.
14 shows a block diagram of an apparatus for performing secure registration of a femto access point for access to an operator-controlled network element using hardware and software means. Optionally, the system 1400 may be implemented in the context of the architecture and functionality of the embodiments described herein. It should be understood, however, that system 1400 or any operation of the system may be performed in any desired environment. As shown, system 1400 includes a plurality of hardware and software components, each of which may communicate with one another via a communication link 1405 . The system 1400 may perform the method steps within the system 1400 individually or in combination. Any method steps performed within system 1400 may be performed in any order unless specified in a claim. As shown, FIG. 14 implements an apparatus for access to an operator-controlled network element: means for establishing a security association for at least one femto access point (see component 1410 ); means for requesting a security enrollment certificate from the at least one femto access point using the security association (see component 1420 ); means (see component 1430) for configuring a secure enrollment certificate with at least one authorization component; and components implementing means (see component 1440 ) for receiving, at the femto access point, a security enrollment certificate for access to the operator-controlled network element.
15 shows a block diagram of a system that performs certain functions of a femto access point. Optionally, the system 1500 may be implemented in the context of the architecture and functionality of the embodiments described herein. It should be understood, however, that system 1500 or any operation of the system may be performed in any desired environment. As shown, system 1500 includes a plurality of modules including a processor and memory, each module coupled to a communication link 1505 , and any module to other modules via a communication link 1505 . can communicate with The modules of this system may perform the method steps in system 1500 individually or in combination. Any method steps performed within system 1500 may be performed in any order unless specified in a claim. As shown, FIG. 15 illustrates a system 1500 that implements a femto access point, a module including at least one processor and memory (see module 1510 ); a module for establishing a security association for at least one femto access point (see module 1520 ); a module for requesting a security enrollment certificate using a security association (see module 1530); and modules including a module (see module 1540 ) for receiving a security enrollment certificate at the femto access point for access to the operator-controlled network element.
The foregoing includes examples of aspects of the claimed subject matter. Of course, it will be impossible to describe every combination of components or methods contemplated for purposes of describing claimed subject matter, but one of ordinary skill in the art will appreciate that additional combinations and permutations of the disclosed subject matter are possible. . Accordingly, the claimed subject matter is intended to cover all such variations, modifications, and alterations falling within the spirit and scope of the appended claims. Also, with respect to the terms "includes", "has or having" as used in this specification or claims, the term "comprising" is used as a transitional word in the claim. As "comprising" is to be interpreted, it is intended in an inclusive manner.
It is understood that the specific order or hierarchy of steps in the disclosed process is an example of an exemplary approach. It is understood that, depending on design preferences, the specific order or hierarchy of steps in this process may be rearranged while remaining within the scope of the present disclosure. The appended method claims present the various steps in a sample order and are not meant to be limited to the specific order or hierarchy presented.
Those of skill in the art will appreciate that information and signals may be represented using various types of different technologies. For example, data, instructions, instructions, information, signals, bits, symbols, and chips referenced throughout the foregoing description may indicate voltage, current, electromagnetic wave, magnetic field or magnetic particle, light field or light particles, or any combination thereof.
Those skilled in the art will also appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps may be implemented as electronic hardware, computer software, or a combination of the two. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functions in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.
Logic blocks, modules, and circuits described in connection with the embodiments disclosed herein may be general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable circuits. It may be implemented or performed as a logic device, discrete gate or transistor logic, discrete hardware components, or a combination thereof designed to implement the described functions. A general purpose processor may be a microprocessor, but in the alternative, the processor may be a commercial processor, controller, microcontroller, or state machine. A processor may be implemented as a combination of computing devices, such as, for example, a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any combination of such configurations.
The steps of the method or algorithm described in connection with the above-described embodiments may be implemented directly in hardware, as a software module executed by a processor, or as a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, portable disk, CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integrated into the processor. The processor and storage medium may be located in the ASIC. Additionally, the ASIC may be located in the user terminal. Alternatively, the processor and storage medium may exist as separate components in the user terminal.
In one or more exemplary embodiments, the functions described may be implemented through hardware, software, firmware, or a combination thereof. If implemented in software, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media includes computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A storage medium may be any available medium that can be accessed by a computer. For example, such computer readable media may store the required program code means in the form of RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or instructions or data structures. or any other medium that can be used to convey and can be accessed by a general purpose computer or special purpose computer or special purpose processor. Also, any connecting means may be considered a computer-readable medium. For example, if the Software is transmitted from a website, server, or other remote source via coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave; Coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave may be included in the definition of this medium. Disks and discs as used herein include compact discs (CDs), laser discs, optical discs, DVDs, floppy disks, and Blu-ray discs, where the disk reproduces data magnetically, while the disc reproduces data optically through a laser. play data with Combinations of the above should also be included within the scope of computer-readable media.
The above description of the embodiments is provided to enable any person skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the scope of the invention. Accordingly, the present invention is not intended to be limited to the embodiments presented herein, but is to be accorded the widest scope consistent with the principles and novel features as defined by the following claims.
16 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1775976A1 | Cites | European Patent Office (EPO) | Search report |
| US2008076425A1 | Cites | United States of America | Search report |
| US2008244148A1 | Cites | United States of America | Search report |
| US20080076425A1 | Cites | United States of America | – |
| EP1775976A | Cites | European Patent Office (EPO) | – |
| US20080244148A1 | Cites | United States of America | – |
19 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 61118397 | United States of America | – | |
| 11839708 | United States of America | P | |
| 12625047 | United States of America | – | |
| 62504709 | United States of America | A | |
| 2009065972 | United States of America | W |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| US2010130171A1 | United States of America | A1 | |
| WO2010062983A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010062983A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2010062983A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW201043053A | Taiwan Province of China | A | |
| KR20110091022A | Republic of Korea | A | |
| KR20110091022A | Republic of Korea | A | |
| EP2368384A2 | European Patent Office (EPO) | A2 | |
| CN102224748A | China | A | |
| JP2012510241A | Japan | A | |
| KR101315205B1This record | Republic of Korea | B1 | |
| KR101315205B1This record | Republic of Korea | B1 | |
| JP5524232B2 | Japan | B2 | |
| JP2014132767A | Japan | A | |
| US8886164B2 | United States of America | B2 | |
| CN102224748B | China | B | |
| CN105101204A | China | A | |
| JP5826870B2 | Japan | B2 | |
| CN105101204B | China | B |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-1315205
- Application
- 1020117014785
Titles4
- Korean
- 운영자 제어 네트워크에서 펨토 액세스 포인트들의 보안 등록을 수행하기 위한 방법 및 장치
- English
- METHODS AND APPARATUSES TO PERFORM SECURE REGISTRATION OF FEMTO ACCESS POINTS IN OPERATOR CONTROLLED NETWORK
- Unlabeled
- 운영자 제어 네트워크에서 펨토 액세스 포인트들의 보안 등록을 수행하기 위한 방법 및 장치{METHODS AND APPARATUSES TO PERFORM SECURE REGISTRATION OF FEMTO ACCESS POINTS IN OPERATOR CONTROLLED NETWORK}
- Unlabeled
- METHODS AND APPARATUSES TO PERFORM SECURE REGISTRATION OF FEMTO ACCESS POINTS IN OPERATOR CONTROLLED NETWORK
Classification
- CPC, 6
- H04W12/06
- H04L63/0823
- H04L9/32
- H04W84/045
- H04L65/1073
- H04W12/069
- IPC, 2
- H04L9 32
- H04L29 06