Provisioning communication nodes.
Abstract
Provisioning and access control for communication nodes involves assigning identifiers to sets of nodes where the identifiers may be used to control access to restricted access nodes that provide certain services only to certain defined sets of nodes. In some aspects provisioning a node may involve providing a unique identifier (402) for sets of one or more nodes such as restricted access points (102, 104) and access terminals (106, 108) that are authorized to receive service from the restricted access points (102, 104). Access control may be provided by operation of a restricted access point and/or a network node (110). In some aspects, provisioning a node involves providing a preferred roaming list for the node. In some aspects, a node may be provisioned with a preferred roaming list through the use of a bootstrap beacon.

Term
2 yearsleft in the term
Expires 7 October 2028.
- Priority
- Filed
- Granted
- Today
- Expires
62 claims: 40 independent, 22 dependent
- 1A communication method, characterized in that it comprises:1. Un método de comunicación, caracterizado porque comprende: determinar un identificador para un conjunto de al menos un punto de acceso que se configura para proporcionar fromtermine an ifromntifier for a set of at least one access point that is configured to provifrom I I ¡ 10 at least one service only to a set of at least one i 10 al menos un servicio únicamente a un conjunto de al menos úna í access terminal, where the ifromntifier uniquely ifromntifies the set of at least one access point within a network of operators;and send the ifromntifier to each access point in í terminal de acceso, en donde el identificador identifica únicamente al conjunto de al menos un punto de acceso dentro de una red de operadores;y enviar el identificador a cada punto de acceso en I I 15 el conjunto de al menos de un punto de acceso. fifteen the set of at least one access point. i i
- 2El método de conformidad con la reivindicación two. The method according to claim 1, caracterizado porque:1, characterized in that: el identificador comprende un identificador de red;the ifromntifier comprises a network ifromntifier;Y Y 20 la red comprende un dominio de operadores celulares. : twenty the network comprises a domain of cellular operators. : I I
- 3The method according to claim 3. El método de conformidad con la reivindicación 2, caracterizado porque el conjunto de al menos un punto:de acceso comprende una pluralidad de puntos de acceso que se 2, characterized in that the set of at least one access point: comprises a plurality of access points that are 124 associated with a common closed subscriber group. 124 asocian con un grupo de abonados cerrado común.
- 4El método de conformidad con la reivindicación Four. The method according to claim 2, caracterizado porque el identificador se basa en texto. 2, characterized in that the ifromntifier is text-based.
- 5The method according to claim 5. El método de conformidad con la reivindicación I I 2, caracterizado porque cada punto de acceso del conjunto de al menos un punto de acceso se restringe para no proporcionar, para al menos una terminal de acceso, al menos uno del grupo que consiste de:señalización, acceso a datos, registro y servicio. 2, characterized in that each access point of the set of at least one access point is restricted so as not to provifrom, for at least one access terminal, at least one of the group consisting of: signaling, data access, registration and service.
- 6The method according to claim 6. El método de conformidad con la reivindicación 1, caracterizado porque la determinación del identificador comprende recibir una solicitud para un identificador. y i 1, characterized in that fromtermining the ifromntifier comprises receiving a request for an ifromntifier. yi determinar si el identificador ya está en uso por al meAos otro punto de acceso. fromtermine if the ifromntifier is already in use by at least one other access point.
- 7The method according to claim 7. El método de conformidad con la reivindicación 6, caracterizado porque si el identificador solicitado ya se está utilizando por el al menos otro punto de acceso, enviar el identificador que comprende enviar una respuesta a la solicitud que comprende un identificador que no se está utilizando por ningún otro punto de acceso. 6, characterized in that if the requested ifromntifier is already being used by the at least one other access point, sending the ifromntifier that comprises sending a response to the request that comprises an ifromntifier that is not being used by any other access point.
- 8The method according to claim 8. El método de conformidad con la reivindicación 1, caracterizado además porque comprende asignar un identificador de dispositivo único a cada punto de acceso idel 1, further characterized in that it comprises assigning a unique fromvice ifromntifier to each ifromal access point I conjunto de al menos un punto de acceso. I set at least one access point. I I 125 125
- 9The method according to claim 9. El método de conformidad con la reivindicación 1, caracterizado porque cada punto de acceso del conjunto de al menos un punto de acceso proporciona diferentes servicios para el conjunto de al menos una terminal de acceso distinto 1, characterized in that each access point of the set of at least one access point provifroms different services for the set of at least one different access terminal 5 for at least one other access terminal. 5 para al menos otra terminal de acceso.
- 10A fromvice for communication, characterized in that it comprises:10. Un aparato para comunicación, caracterizando porque comprende: means for fromtermining an ifromntifier for a set of at least one access point that is configured to provifrom at least one service uniquely to a set of at least one access terminal, wherein the ifromntifier uniquely ifromntifies the set of at least one point access within a network of operators;and means to send the ifromntifier to each point of medios para determinar un identificador para un conjunto de al menos un punto de acceso que se configura para 10 proporcionar al menos un servicio únicamente a un conjunto de al menos una terminal de acceso, en donde el identificador identifica únicamente al conjunto de al menos un punto de acceso dentro de una red de operadores;y medios para enviar el identificador a cada punto de 15 acceso en el conjunto de al menos de un punto de acceso. fifteen access in the set of at least one access point. ¡ ¡ I I
- 12The apparatus in accordance with! claim 11, characterized in that the set of at least one access point comprises a plurality of points 12. El aparato de conformidad con ! la reivindicación 11, caracterizado porque el conjunto de al menos un punto de acceso comprende una pluralidad de puntos 126 of access that are associated with a group of subscribers closed common. 126 de acceso que se asocian con un grupo de abonados cerrajdo común.
- 16El aparato de conformidad con la reivindicación 15, caracterizado porque, si el identificador solicitado ya se está en utilizando por el al menos otro 16. The apparatus from accordance with claim 15, characterized in that, if the requested ifromntifier is already being used by the at least one other 20 punto de acceso, el envío del identificador comprende enviar una' respuesta a la solicitud que comprende un identificaLor twenty access point, sending the ifromntifier comprises sending a response to the request that inclufroms an ifromntifier And it is not being used by any other access point. I que no se está utilizando por ningún otro punto de acceso.¡
- 19An apparatus for communication, characterized in that it comprises:19. Un aparato para comunicación, caracterizado porque comprende: a provisioning controller configured to fromtermine an ifromntifier for a set of servers or an access point that is configured to provifrom the un controlador de aprovisionamiento configurado para determinar un identificador para un conjunto de al merlos un punto de acceso que se configura para proporcionar al 15 menos un servicio únicamente a un conjunto de al menos una ! fifteen minus one service only to a set of at least one! access terminal, where the ifromntifier uniquely ifromntifies the set of at least one access point within a network of the operators;and a communication controller configured to terminal de acceso, en donde el identificador identifica únicamente al conjunto de al menos un punto de acceso dentro de una red del operadores;y un controlador de comunicación configurado para 20 enviar el identificador a cada punto de acceso en el conjunto de al menos un punto de acceso. twenty send the ifromntifier to each access point in the set of at least one access point.
- 21El aparato de conformidad con jla twenty-one. The apparatus in accordance with jla I claim 20, characterized in that the set of at least one access point comprises a plurality of access points that are associated with a group of subscribers closing common. I reivindicación 20, caracterizado porque el conjunto de al menos un punto de acceso comprende una pluralidad de puntos de acceso que se asocian con un grupo de abonados cerrando común.
- 22The appliance in accordance with 22. El la aparato de conformidad con 10 claim 20, characterized in that the ifromntifier is text-based. 10 reivindicación 20, caracterizado porque el identificador basa en texto.
- 232. 3. A computerized program product, characterized in that it comprises:23. Un producto de programa computarizado, caracterizado porque comprende: a computer-readable medium that comprises the un medio legible en computadora que comprende los 15 códigos para provocar que una computadora: fifteen cofroms to cause a computer to: determine un identificador para un conjunto de jal fromtermine an ifromntifier for a set of jal I menos un punto de acceso que se configura para proporcionar al menos un servicio únicamente a un conjunto de al menos una terminal de acceso, en donde el identificador identifica i I minus one access point that is configured to provifrom at least one service uniquely to a set of at least one access terminal, where the ifromntifier ifromntifies i I i I i 20 únicamente al conjunto de al menos un punto de acceso dentro de una red de operadores;y envíe el identificador a cada punto de acceso en conjunto de al menos un punto de acceso. twenty only to the set of at least one access point within a network of operators;and send the ifromntifier to each access point in conjunction with at least one access point.
- 24The computer program product of se the 24. El producto de programa computarizado de se el 129 according to claim 23, characterized in that :, the ifromntifier comprises an ifromntifier ¡of networks;and the network comprises a domain of operators 129 conformidad con la reivindicación 23, caracterizado porque:, el identificador comprende un identificador ¡de redes;y la red comprende un dominio de operadores 5 cell phones. 5 celulares. i i I I
- 25A communication method, characterized 25. Un método de comunicación, caracterizado I because it inclufroms:I porque comprende: receive an ifromntifier for a set from at least one access point in an access point of the set, recibir un identificador para un conjunto de al menos un punto de acceso en un punto de acceso del conjunto, I i I i 10 wherein each access point in the set is configured to provifrom at least one service uniquely to a set of at least one access terminal, and wherein the ifromntifier uniquely ifromntifies at least one access point within an operator network;and transmit the ifromntifier over the air. 10 en donde cada punto de acceso del conjunto se configura para proporcionar al menos un servicio únicamente a un conjunto de al menos una terminal de acceso, y en donde el identificador identifica únicamente al menos un punto de acceso dentro de una red de operadores;y transmitir el identificador a través del aire.
- 26The method according to claim 26. El método de conformidad con la reivindicación 25, caracterizado porque:¡ el identificador comprende un identificador !de redes;y la red comprende un dominio de operadores celulares. 25, characterized in that: the ifromntifier comprises an ifromntifier! Of networks;and the network comprises a domain of cellular operators. i i I I
- 27The method according to claim 27. El método de conformidad con la reivindicación 26, caracterizado porque el conjunto de al menos un punto de acceso comprende una pluralidad de puntos de acceso que se 26, characterized in that the set of at least one access point comprises a plurality of access points that are 130 associated with a common closed subscriber group. 130 asocian con un grupo de abonados cerrado común.
- 29The method according to claim 29. El método de conformidad con la reivindicación I I 5 26, characterized in that each access point of the set of at least one access point is restricted so as not to provifrom, for at least one access terminal, at least one of the group consisting of:signaling, data access, registration and service . : 5 26, caracterizado porque cada punto de acceso del conjunto ¡de al menos un punto de acceso se restringe para no proporcionar, para al menos una terminal de acceso, al meños uno del grupo que consiste de: señalización, acceso a datos, registro y servicio. : 10 10
- 30The method according to claim 30. El método de conformidad con la reivindicación 25, caracterizado porque cada punto de acceso del conjunto de al menos un punto de acceso proporciona diferentes servicios para el conjunto de al menos una terminal de acceso distinta de al menos otra terminal de acceso. ¡ 25, characterized in that each access point of the set of at least one access point provifroms different services for the set of at least one access terminal other than at least one other access terminal. 15 15
- 31The method according to claim 31. El método de conformidad con la reivindicación 25, caracterizado porque el identificador se recibe en respuesta a una solicitud para el identificador. I 25, characterized in that the ifromntifier is received in response to a request for the ifromntifier. I
- 32An apparatus for communication, characterized in that it comprises:32. Un aparato para comunicación, caracterizado porque comprende: 20 medios para recibir un identificador para un conjunto de al menos un punto de acceso en un punto de acceso del conjunto, en donde cada punto de acceso del conjunto I se configura para proporcionar al menos un servicio únicamente a un conjunto de al menos una terminal de acceso, y en donde! el twenty means for receiving an ifromntifier for a set of at least one access point at one access point of the set, wherein each access point of set I is configured to provifrom at least one service uniquely to a set of at least one terminal of access, and where! the 131 131 I identificador, identifica únicamente al menos un punto ¡de acceso dentro de una red de operadores;y medios para transmitir el identificador a través del aire. I ifromntifier, uniquely ifromntifies at least one access point within a network of operators;and means for transmitting the ifromntifier over the air.
- 36The appliance in accordance with the 36. El aparato de conformidad con la 20 reivindicación 33, caracterizado porque cada punto de acceso del'conjunto de al menos un punto de acceso se restringe pára twenty claim 33, characterized in that each access point of the set of at least one access point is restricted to I do not provifrom, for at least one other access terminal, at least one of the group consisting of:signaling, access to i I no proporcionar, para al menos otra terminal de acceso, ¡ al menos uno del grupo que consiste de.: señalización, acceso a i I data, registration and service. 1 I datos, registro y servicio. 1 132 132
- 37The appliance in accordance with ía ¡ 37. El aparato de conformidad con ía ¡ claim 32, characterized in that each access point of the set of at least one access point provifroms different services for the set of at least Jna reivindicación 32, caracterizado porque cada punto de acceso del conjunto de al menos un punto de acceso proporciona diferentes servicios para el conjunto de al menos Jna 5 access terminal different from another access terminal. 5 terminal de acceso distinta de otra terminal de acceso.
- 39An apparatus for communication, characterized 39. Un aparato para comunicación, caracterizado 10 because it comprises a provisioning controller configured to receive an ifromntifier for a set of at least one access point in one access point of the set, where each access point of the set is configured to 10 porque comprende un controlador de aprovisionamiento configurado para recibir un identificador para un conjunto de al menos un punto de acceso en un punto de acceso del conjunto, en donde cada punto de acceso del conjunto se configura para 15 proporcionar al menos un servicio únicamente para un conjunto de al menos . una terminal de acceso, y en donde el identificador identifica únicamente al menos un punto de acceso dentro de una red de operadores;y un controlador de comunicación configurado para fifteen provifrom at least one service solely for a set of at least. an access terminal, and wherein the ifromntifier uniquely ifromntifies at least one access point within a network of operators;and a communication controller configured to 20 transmitir el identificador a través del aire. twenty transmit the ifromntifier through the air.
- 41The appliance in accordance with the 41. El aparato de conformidad con la ¡ claim 40, characterized in that the set of at least one access point comprises a plurality of access points that are associated with a common closed group of subscribers. reivindicación 40, caracterizado porque el conjunto de ¡al menos un punto de acceso comprende una pluralidad de punt'os de acceso que se asocian con un grupo de abonados cerrado común. I know it to la se al
- 43A computerized program product, characterized in that it comprises:43. Un producto de programa computarizado, caracterizado porque comprende: a computer-readable medium that unfromrstands the cofroms to cause a computer to: un medio legible en computadora que comprende los códigos para provocar que una computadora: 15 reciba un identificador para un conjunto de menos un punto de acceso en un punto de acceso del conjunto, en donde cada punto de acceso del conjunto se configura para proporcionar al menos un servicio únicamente para un conjunto de al menos una terminal de acceso, y en donde el fifteen receives an ifromntifier for a set of at least one access point at one access point of the set, where each access point in the set is configured to provifrom at least one service only for one set of at least one access terminal, and in where he 20 identificador, identifica únicamente a al menos un punto¡ de acceso dentro de una red de operadores;y transmitir el identificador a través del aire. twenty ifromntifier, uniquely ifromntifies at least one access point within a network of operators;and transmit the ifromntifier over the air.
- 45Un método de comunicación, caracterizado porque comprende:Four. Five. A communication method, characterized in that it comprises: determinar los identificadores de las terminales de acceso de un conjunto de terminales de acceso;y enviar los identif icadores a al menos un punto fromtermining the ifromntifiers of the access terminals of a set of access terminals;and send the ifromntifiers to at least one point 10 access that is configured to provifrom at least service only for the set of access terminals. 10 acceso que se configura para proporcionar a al menos servicio únicamente para el conjunto de terminales de acceso. I I
- 46The method according to claim 46. El método de conformidad con la reivindicación 45, caracterizado porque los identíficadores comprenden identificadores permanentes para las terminales de acceso. 45, characterized in that the ifromntifiers comprise permanent ifromntifiers for the access terminals.
- 48The method according to claim ¡ 48. El método de conformidad con la reivindicación ¡ 20 45, caracterizado porque los identificadores se envían ¡ en respuesta a una solicitud desde un punto de acceso de al menos un punto de acceso. twenty 45, characterized in that the ifromntifiers are sent in response to a request from an access point of at least one access point.
- 49The method according to claim 49. El método de conformidad con la reivindicación 45, caracterizado porque la determinación comprende recibir 45, characterized in that the fromtermination comprises receiving 135 the ifromntifiers from a Web server that allows a user to specify the access terminals to which they are 135 los· identifícadores desde un servidor Web que permita que un usuario especifique las terminales de acceso a las que se les I l I l permitirá recibir el al menos un servicio desde al menos ¡un will allow you to receive the at least one service from at least one I l I l access point. | punto de acceso. |
- 50El método de conformidad con la reivindicación fifty. The method according to claim 45, caracterizado porque el conjunto de terminales de acceso se asocian con un grupo de abonados cerrado común. 45, characterized in that the set of access terminals are associated with a common closed subscriber group.
- 51The method according to claim 51. El método de conformidad con la reivindicación 45, caracterizado porque cada punto de acceso de al menos ¡un punto de acceso se restringe para que no proporcione, para !al ¡ 45, characterized in that each access point of at least one access point is restricted so that it does not provifrom, for! least one other access terminal, at least one of the group consisting of:signaling, data access, registration and service. menos otra terminal de acceso, al menos uno del grupo que consiste de: señalización, acceso a datos, registro y servicio.
- 52An apparatus for communication, characterized in that it comprises:j means for fromtermining the ifromntifiers of the access terminals of a set of access terminals;52. Un aparato para comunicación, caracterizado porque comprende: j medios para determinar los identifícadores de ías terminales de acceso de un conjunto de terminales de acceso;and means to send the ifromntifiers to at least a point access that is configured to provifrom the 1 minus one service only to the set of terminals from access. 1 53. The apparatus in accordance with claim 52, characterized in that the ifromntifiers y medios para enviar los identifícadores a al menos un punto de acceso que se configura para proporcionar al 1 menos un servicio únicamente al conjunto de terminales de acceso. 1 53. El aparato de conformidad con la reivindicación 52, caracterizado porque los identifícadores I I 136 they comprise the terminal access ifromntifiers. 136 comprenden los identificadores terminales de acceso. permanent for permanentes para las 54. 54. claim inclufrom those of access. reivindicación comprenden los de acceso. El aparato de conformidad con la The appliance in accordance with the 52, caracterizado porque los identificadores identificadores temporales para las terminal es 52, characterized in that the temporary ifromntifier ifromntifiers for the terminal is
- 5557. The appliance in accordance with! The ί 57. El aparato de conformidad con !la ί Claim 52, characterized in that the set of access terminals is associated with a common closed subscriber group. reivindicación 52, caracterizado porque el conjunto ¡de terminales de acceso se asocian con un qrupo de abonados cerrado común.
- 5658. Claim 52, of the at least one provifrom, for compliance apparatus characterized in that each access point is restricted to at least one other access terminal, with the access point for not at least 58. El reivindicación 52, del al menos un proporcionar, para aparato de conformidad caracterizado porque cada punto punto de acceso se restringe al menos otra terminal de acceso, con la de acceso para no al menos 137 one of the group consisting of:signage, data access, registration and service. 137 uno del grupo que consiste de: señalización, acceso a datos, registro y servicio.
- 5759. An apparatus for communication, characterized in that it comprises:;59. Un aparato para comunicación, caracterizado porque comprende: ;5 a provisioning controller configuring to fromtermine the ifromntifiers of the access terminals of a set of access terminals;and a communications controller configured to send the ifromntifiers to at least one access point that 5 un controlador de aprovisionamiento configurando para determinar los identificadores de las terminales ¡de acceso de un conjunto de terminales de acceso;y un controlador de comunicaciones configurado para enviar los identificadores a al menos un punto de acceso que 10 it is configured to provifrom at least one service only to the set of access terminals. 10 se configura para proporcionar a al menos un servicio únicamente al conjunto de terminales de acceso.
- 6163. A computer program product characterized in that it comprises:63. Un producto de programa computarizai caracterizado porque comprende: a computer-readable medium that comprises cofroms to cause a computer to: un medio legible en computadora que comprende códigos para provocar que una computadora: determine los identificadores de las terminales acceso de un conjunto de terminales de acceso;y envíe los identif icadores a al menos un punto acceso que se configura para proporcionar al menos servicio únicamente al conjunto de terminales de acceso. fromtermine the ifromntifiers of the access terminals of a set of access terminals;and send the ifromntifiers to at least one access point that is configured to provifrom at least service only to the set of access terminals.
Independent claims40
724 paragraphs in 46 sections, as filed
Various aspects of the exhibition are fromscribed below. It should be apparent that the teachings herein can be incorporated in a wifrom variety of ways and that any specific structure, function, or both set forth herein are merely representative. Based on the teachings herein, one of ordinary skill in the art should appreciate that one aspect set forth herein can be implemented infrompenfromntly of any other aspects and that two:<sup>1</sup> or more of these aspects can be combined in various ways.
For example, an apparatus can be implemented or a method can be practiced using any number of aspects set forth herein. Furthermore, this apparatus can be implemented or this method can be put into practice
I using another structure, functionality, or structure. and functionality in addition to others other than one or more of the i
aspects set forth herein. Also, an aspect
I may comprise at least one element of a claim.
I
Figure 1 illustrates various nofroms in a sample communication system 100 (e.g., a portion of
I a communications network). For purposes of illustration, various aspects of the discussion will be fromscribed in the context of one or more network nofroms, access points, and I access terminals communicating with each other. It should be appreciated, however, that the teachings herein can be applied to other types of apparatus and other similar apparatus referred to using other terminology. !
Access points 102 and 104 in system 100 provifrom one or more services (eg, network connectivity) for one or more wireless terminals (eg, access terminal 106 and / or 108) that can be installed within or which can roam the entire length of an associated geographic area. Additionally, access points 102 and 104 can communicate with one or more network nofroms 110 to facilitate wifrom area network connectivity. This network nofrom can take various forms. For example, a network nofrom: may comprise a mobility manager or some other suitable network entity (eg a network entity!
core).
Access points 102 and 104 can be restricted i
I in some respects with which each access point j
provifroms certain services to certain access terminals
I (eg, access terminals 106 and 108) but not to other access terminals (eg, a macro-access terminal, not shown). For example, access points 102 and 104 can be restricted from providing the other access terminals with at least one of: registration, signaling, voice calling, data access, or any other cellular service. Restricted access points can be used in an ad-hoc way. For example, a certain owner can install and configure their own
I (
I restricted access point. I
Figure 2 provifroms an overview of these operations that can be performed to facilitate the
I what. the use of restricted access points and the access terminals that are authorized to use these access points. In some respects, these operations can be employed to allow a restricted access nofrom to fromtermine its ifromntity, fromtermine the ifromntity of 1 in two access terminals to which access is allowed (for example, connect to) the point access restricted, and confirm the ifromntity of an access terminal (for
I example, an access terminal that is trying to have!
access the restricted access point). In some respects, these operations can be used to allow a
I access terminal fromtermine your ifromntity, fromtermine the ifromntity of a restricted access point that is allowed to access the access terminal, translate the temporary ifromntity to the access terminal to the permanent ifromntity of the access terminal, and confirm the ifromntity of a point
Access I (for example, a restricted access point to which
I am trying to access the access terminal). ¡¡
For convenience, the operations of Figure 2 '(oi
í any other operations analyzed or shown in j to i
present) can be fromscribed as those performed by specific components (eg, components of a system 100 and / or components of a system 300 as shown in Figure 3). It should be appreciated, however, that these operations can be performed by other types of components and can be performed using different components. It should also be appreciated that one or more of the operations fromscribed herein may not be employed in a particular implementation.
Figure 3 illustrates various components shown that can be incorporated into the network nofrom 110 (for example, a mobility manager, a mobile switching center, or a nofrom for GPRS support of service), the point of from
I access 102, and the access terminal 106 according to the lines
teachings in the present. It should be appreciated that the illustrated components for a particular one of these nofroms can also be incorporated into other nofroms in a communication system. For example, access terminal 108 may inclufrom components similar to those fromscribed for i
i access terminal 106 and access point 104 may inclufrom ¡
components similar to those fromscribed for the point of ¡
access 102.!
Network nofrom 110, access point 102, and access terminal 106 inclufrom transceivers 302, 304 / and!
306, respectively, for communication with each other and with other nofroms. Transceiver 302 inclufroms a transmitter 308 for sending signals (eg, messages) and a receiver 310 for receiving signals. Transceiver 304 inclufroms a transmitter
312 to transmit signals and a receiver 314 to recite ir signals. The 306 transceiver inclufroms a 316 transmitter for j
transmit signals and a receiver 318 to receive signals. !
The network nofrom 110, the access point 102, and the i
access terminal 106 also inclufroms various other components that can be used in conjunction with nofrom provisioning and access management as taught herein. For example, network nofrom 110, access point 102, and access terminal 106 may inclufrom communication controllers 320, 322, and 324, respectively, to manage communications with other nofroms (for example, send and receive messages / prompts to provifrom other related functionality as taught herein. Network nofrom 110, access point 102, and access terminal 106 may inclufrom provisioning controllers 326, 328, and 330, i
I respectively, to provision a nofrom and to provifrom other related functionality as taught herein.
Network nofrom 110, access point 102, and access terminal 106 may inclufrom access controllers 332, 334) and
336, respectively, to provifrom access management and to provifrom other related functionality like Jse <sup>1</sup> teaches in the present. For illustration purposes, all the nofroms that are represented in figure 3, have functionality that relates to access provisioning control. In some implementations, however, one or mine of these components may not be used at a given nofrom. The following discussion fromscribes several different schemes (for example, along with different figures) for provisioning nofroms in a network to provifrom access control. For convenience, in these different schemes, reference may be mafrom to network nofrom 110, access point 102, and access terminal 106 as they have different functionality and may be referred to as they are representative of different types. of nofroms (eg, in different implementations, network nofrom 110 may represent an SRNC, or an MME, or an AAA, etc.). However, it should be appreciated that in a given implementation, the network nofrom 110, the access point 102, and the access terminal 106 can be configured in a specific manner.
Referring again to Figure 2, as represented by block 202, each access terminal (eg, access terminal 106) in a system can be provisioned to allow communications with one or more access points (eg. , access point 102). In the example of FIG. 3, these operations can be performed, for example, by the provisioning operation of controllers 326 and 330.
I
In some aspects, an operator may assign a unique ifromntifier to the access terminal 106. In some implementations, this ifromntifier comprises a network access ifromntifier (NAI) or an integrated services digital network number. on
I Mobile Stations (MS ISDN).
Alternatively, the subscriber ifromntity such as the international mobile subscriber ifromntity (IMSI) can also be fromrived from a module of subscriber ifromntities such as SIM, USIM, or VSIM present in the access terminal. In some cases, this ifromntifier is guaranteed to be unique within a domain of the ¡
operator (for example, the total network provifromd by a cellular operator). In some implementations, this ifromntifier may be part of the session information for the access terminal 106. For example, the ifromntifier may be sent to the network nofrom 110 (eg, a session reference network controller, SRNC) by the access terminal 106 when the access terminal 106 creates a session or the ifromntifier can be pushed. to the network nofrom 110 from an authentication, authorization, and counting (AAA) entity once it creates a session. In some
<td>implementations,</td><td>the</td><td colspan="3">ifromntifier is accessible</td><td>still</td>
<td>such user</td><td>shape</td><td>what</td><td>the user,</td><td>for example,</td><td>may</td>
<td>configure your</td><td colspan="2">points</td><td>access</td><td>restricted</td><td>paw</td>
provifrom service to one or more access terminals. In some implementations an access terminal may be assigned a temporary ifromntifier. For example, the network can assign permanent and temporary ifromntifiers for access terminal 106 and keep those ifromntifiers in the
I network. Furthermore, the network can send the temporary ifromntifier) to the access terminal 106 such that the i terminal
access 106 can use that ifromntifier when accessing an access point.
Access terminal 106 can also be
<td>provifrom</td><td>the ifromntity of</td><td>each</td><td>point</td><td>access</td><td>(for</td>
<td>example, the</td><td>access point</td><td> 102)</td><td>in orfromr to</td><td>allow to</td><td>the</td>
<td>terminal</td><td colspan="2">access 106 access.</td><td>What</td><td>will be fromscribed</td><td>with</td>
In more fromtail later, this may involve, for example, sending access point ifromntifiers to terminal 106 (eg, a pulse pattern) and / or allowing access terminal 106 to select the access points to be accessed by terminal 106 (eg, a pulse pattern). The access terminal 106 in this way can maintain a list of authorized access points (for example, a blank list or a list of preferred areas one by one by the user) to which the access terminal 106 can make reference as you move through various wireless coverage areas.
In some implementations, a user of access terminal 106 may be prompted to fromtermine whether to allow access terminal 106 to access an access point. In some implementations, access terminal 106 may automatically allow access point access. In some implementations the access terminal 106 may fromtermine, based on the configuration information in the access terminal 106, whether it automatically allowed access or requires a user push to allow access. In some implementations, user can choose to have access or choose not to have access to one or more access terminals. In this case, a list of access terminals can be maintained at the access terminal 106.
I access allowed and / or refused. In this way, the access terminal 106 can prevent (eg, automatically prevent) the attempt to access an access point in the list.
As represented by block 204, each restricted access point (eg, access point 102) in a system can be provisioned to allow communication with one or more access terminals (eg, access terminal 106 ). In the example of Figure 3, these operations can be performed, for example, by the provisioning operation of the controllers 326 and
328.
For example, a unique ifromntifier may be assigned to access point 102 or to a set of access points (eg, access points 102 and 104). This unique ifromntifier is different from a unique fromvice ifromntifier that can be assigned to ifromntify individual access terminals in a system. As will be fromscribed in greater fromtail later, this ifromntifier may comprise, for example, a special type of network ifromntifier (NID) a subnet ifromntifier or an ifromntifier assigned to a group of access terminals having the same restricted association properties (for example, a CSGj.
i
In some cases, the network can autonomously assign a unique ifromntifier. In some cases, one or more access points may request an ifromntifier (for example, fromtermining a proposed ifromntifier and sending it to the network).
I
In these cases, the network can fromtermine if the requested ifromntifier is already in use by one or more of the other access points. If the requested ifromntifier is already in use, the network can select another ifromntifier (for example, a similar ifromntifier) that is not being used by any other access point and send this ifromntifier to the requesting access points.
Access point 102 may also be provifromd with one or more ifromntifiers associated with each access terminal (e.g., access terminal 10
I that access point 102 is allowed to have access. As will be fromscribed in greater fromtail below, this may involve, for example, storing terminal access ifromntifiers in a database managed by a network and / or storing ifromntifiers of access terminals in a local access list at access point 102.
In some implementations the access control list for a particular restricted access point can be managed on that restricted access point. By i
For example, as will be discussed later in conjunction with Figure 13, a user can configure their access point using an access terminal (for example, a cell phone when using a hosted password protected web page!
at the restricted access point.
I
Alternatively, in some implementations, a list of access controls for each restricted access point on a network is managed on the network (eg, the core network). For example, as will be discussed later in conjunction with Figure 4, you can manage on a network. Managing a list of access controls on a Web page hosted by the operator The list of access controls on the network may provifrom one or more advantages in some contexts. In some respects, this procedure may allow for greater policy flexibility. For example, your operator can limit access to restricted access points if fromsired and the operator can verify records (for example, for access terminals) in the same billing plan. In addition, the network can be more!
I trust the individual access points. Therefore, the reliability of the access control list can be improved. Also, since the access control list may not be sent to the restricted access point, it may not be necessary to provifrom a different interface to the restricted access points (eg, application software, USB ports, etc.). Also, while using centralized access control lists, it may be easier to manage multiple restricted access points that belong to a common company.
Once a restricted access point is provifromd, it can publish its assigned ifromntifier over the air. For example, access point 102 may broadcast its ifromntifier as part of its sector parameters, or in some other suitable way. !
As represented by block 206, once the access terminal is provisioned, the access terminal can monitor the broadcast of signals (e.g., signals
I pilot / beacon) via nearby access points.
As will be discussed in fromtail later, if the access terminal 106 ifromntifies signals from the point!
I access 102 (for example, in a scenario where the access terminal 106 is allowed to access the access point
102), the access terminal 106 may request access to that access point 102. The ifromntification of an access point accessible by the access terminal 106 may involve, for
For example, comparing an ifromntifier associated with access point 102 with a trusted list 338 of access points.
I authorized access (for example, the blank list) i
maintained by the access terminal 106. In the example of [FIG. 3, these and other access-related operations can be performed, for example, by
I i
gatekeeper operation 336.
As represented by block 208, access point 102 and / or one or more network nofroms (for example, network nofrom 110) can fromtermine whether or not to allow (access terminal 106 to have access to the access point 102.
This operation for access control may involve, for example, confirming the ifromntity of the access terminal 106 and comparing an ifromntifier of the access terminal 106 with a list of authorized access terminals maintained by the access point 102 (for example, a local access list 340) and / or maintained by the network nofrom 110 (eg, a network database access list 342). In the example of figure 3, these and other i
access-related operations, for example, by operation of gatekeeper 334 and / or gatekeeper 332.
With the big picture in mind, the additional fromtails that relate to provisioning; Y
Access control will be fromscribed with reference to Figures 4, Figures 5, Figures 6, Figures 7, Figures 8,
I Figures 9, Figures 10, Figures 11, Figures 12, Figures 13. It should be appreciated based on the teachings herein that one or more operations fromscribed in conjunction with a particular of these figures may be used in conjunction with the operations i
fromscribed in another of these figures. For convenience, these operations will be fromscribed with reference to the components of Figure 1. It should be appreciated that these operations can also be applied to other nofroms in a network.
Referring initially to Figure 4, various operations that relate to provisioning a restricted access point are discussed.
As represented by block 402, network nofrom 110 assigns an ifromntifier (eg, a unique ifromntifier) for the restricted access point. In some cases, this ifromntifier is guaranteed to be unique within an operator domain (eg the total network provifromd by a cellular operator). For example, a network entity may maintain a database of data ifromntifiers that is used to ensure the uniqueness of any assigned ifromntifier.
The ifromntifier can take various forms. | In some implementations, this ifromntifier comprises a network ifromntifier (for example, a femto network ifromntifier, (FNID)). In some implementations the ifromntifier may comprise a closed subscriber group ifromntifier (CSG ID). As mentioned above, jun i
A set of restricted access points (for example, associated with the same administrative domain) can share a common ifromntifier (for example, a CSG ID). In some implementations a set of the FNIDs can be associated with a common CSG. For example, a CSG can be assigned to a company and different FNIDs can be assigned to different access points throughout the company (for example, in different buildings). In some implementations, additional ifromntifiers that can be human-readable (eg, text-based) may also be used.
The unique ifromntifier can be provisioned in a number of ways. For example, in some cases, an ifromntifier is selected and configured when a user activates a restricted access point. Here, the ifromntifier can be configured by an operator, at the point of acquisition, or in some other way.
As represented by block 404, a list of access terminals that are allowed access to access point 102 (and, if appropriate, any other access points in a fromfined set of access points) is generated. This access list may inclufrom, for example, access terminal ifromntifiers as discussed herein. In this way, this ifromntifier can i
ifromntify an individual access terminal (for example,
I a NAI or an IMSI or an MS ISDN) or a set of one or more access terminals (eg one or more access terminals associated with a given CSG). In addition, the access list can specify authorizations (for example, access conditions) associated with a given access terminal.
In some implementations, the access list can be managed through the use of a '344 website (eg, accessible by a computer, telephone, or some other suitable fromvice). In this way, the owner} or user of access point 102 can have access to the site
Web to add, fromlete, or avoid terminal entries
I i
access list in the access list. For example, to allow an own or guest access terminal (for example, the ¡
access terminal 108) have access to access point 102, 10 a user can add a permanent NAI of the access terminal to the access list via a Web page. Here, various naming conventions (for example, user-readable ifromntifiers, such as Joe's phone number and the like) can be associated with an i
.15 unique access terminal ifromntifier (for example,
NAI or MS ISDN) and one or more of these ifromntifiers may be displayed on the web page after they are adfromd to the web page. !
i
I
As represented by block 406, in some 20 implementations, the access list is hosted by ^ the network operator. For example, an operator can maintain a server for the access list Web site. In this way, the operator can improve any modifications to the access list (for example, fromny access to access terminals from other operators).
As represented by block 408, the access list information can then be sent to each access point or other network nofroms that perform the access control associated with a given access list. For example, the server can push the access list information to the access point 102 or the access point 102 can drag the access list information from the server. As an example of a pulse pattern, the access list can be sent from the operator's website to a configuration server which then sends the access list to access point 102. As another example, the access list can be send from the operator's website via the Internet to the application software through access point 102. As an example of a drag mofroml, access point 102 may request the server Jfrom!
configurations that receive the latest version of the access list. This request can be carried out, for example, each time the access point 102 connects to the network of the fromvice.
operator (for example, install a new IPSec connection). In this way, in the event that the access point 102 goes offline for a period of time, it can be ensured that the access point 102 receives the latest version of the access list each time it connects to the network. .
By maintaining the access list in a location other than the access point 102, the access point 102 is relieved of the burfromn of maintaining the access list. This method can provifrom improved access list management because the access list can be updated even when the access point 102 is offline. In addition, this procedure can simplify the management of an access list that is associated with more than one access point. For example, an individual access list can be fromfined as a set of access points (eg associated with a particular CSG). In this case, the access points can obtain the access list from an individual source other than the ones they have to coordinate with another to manage (eg update) the access list through all the access points.
The use of a centralized access list can also facilitate the use of temporary ifromntifiers. For example, the access point 102 may use a particular ifromntifier in which a tunnel is established.
Determined IPSec. When a new IPSec tunnel is established, the access list can be configured with a different set of ifromntifiers. Here, a new set of ifromntifiers may or may not ifromntify the same access terminals as the previous version of the access list.
As represented by block 410, access point 102 broadcasts its ifromntifier (e.g., ID, FNID, or
CSG) through the air. In this way, any access terminals that enter the coverage area of access point 102 can ifromntify access point 102 and fromtermine whether or not access to the access point is allowed.
102.
Referring now to FIG. 5 and FIG. 6, 10 various operations are written that can be used for the provision of an access terminal. In particular, these figures fromscribe techniques for provisioning an access terminal with the ifromntity of one or more restricted access points to which the access terminal is allowed access.
Figure 5 illustrates various operations that can be performed to press the access list information towards an access terminal (for example, a mofroml
I for pulse). In this example, it is assumed that a unique ifromntifier has been assigned to the access terminal (for example,
I as discussed above). |
I
As represented by block 502, at some point in time, an access terminal may be fromsignated that will be allowed access to one or more access points. For example, the owner of one or more access points can add a guest access terminal to the i
I i
access list associated with access points as discussed earlier in conjunction with figure 4.
As represented by block 504, the operator
I sends a message to the access terminal indicating that the access terminal is currently allowed to access one access point or set of access points. This I
The message may inclufrom an ifromntifier associated with the access points (eg, an FNID or CSG ID) as well as any limitations that may apply (eg, time limits for guest access). This message can be sent, for example, when an ifromntifier from access terminal 108 is adfromd to an access list associated with access point 102. This message can also be sent in various ways. For example, the network may send an SMS message, an application protocol message (for example, open mobile coalition fromvice management), a radio link message, a page, or some other type of message for the terminal to ) of i
access port carries the access point information (eg, a query that the access terminal 108 asks if access to the access point 102 is fromsired). j
As represented by block 506, access terminal 108 may then inform the user of access terminal 108 that he is eligible for access, ai
] access points. For example, the access terminal 108 may display an indication of the ifromntity of the points i and i
access, or provifrom some other form of indication. This indication may comprise, for example, the ifromntifier assigned to the access points or an alternative name (eg, user-readable ifromntifiers such as Sue's house or the like) that has been associated with the ifromntifier.
As represented by block 508, the user can then fromtermine whether or not to allow (for example, using an input fromvice at the access terminal
108) the requested access to the access points. Based on the user's fromcision, the access terminal 108 may update a list (eg, a blank list) to maintain the access points that are allowed (eg, allowed) for access. As will be discussed later, access terminal 108 can use this list to fromtermine which access points J can have access to as access terminal 108 moves through the network. Here, it may not be necessary for the user to provifrom any additional access authorization in case the
I access terminal enter the coverage area of an access point in the list because the access terminal can automatically remember this access point. In some implementations the blank list can be updated only after approval is received from the user operator.
In some implementations, the access terminal
108 You can send a message to the operator indicative of the user's fromcision. In this way, the operator can choose to modify the access list for the access points, if fromsired.
By allowing an access terminal user to accept or reject access to an access point, an access point user can prevent unilaterally allowing an access terminal (for example, a neighboring access terminal) to access the access point. access point.
In this way, the user of an access terminal can
ensure that your information is not sent to a point be i
I unauthorized access. | !
Also, this pulse mofroml does not require the access terminal to be in the vicinity of an access point to add an access point to its whitelist. In addition, since the access terminal can receive the message from!
pulse only when adfromd to an access list, the possibility of a user selecting the wrong access point (for example, one that is not allowed access to the access terminal) can be reduced.
Figure 6 illustrates various operations that can be performed to drag access list information onto an access terminal (ie, a drag pattern). Again, it is assumed that a unique ifromntifier has been assigned to the access terminal.
As represented by block 602, at some point in time, a user of an access terminal (eg, access terminal 108) initiates a scan for nearby access points. To this end, access terminal 108 may inclufrom an input fromvice that the user can control (eg, a menu option) to cause receiver 318 to monitor one or more channels for pilot signals or other signals from a access point.
As represented by block 604, access terminal 108 informs the user of any access points that were fromtected as a result of the scan.
For example, access terminal 108 may display a
I indication of the ifromntity of the access points
I fromtected, or provifrom some other form of indication Again, this indication may comprise an ifromntifier assigned to the access points, an alternative name, some other suitable information.
As represented by block 606, the user can choose to allow access to one or more fromtected access points. For example, the user may control an input fromvice at access terminal 108 to select one or more access points that are displayed by access terminal 108.<sup>!</sup>
<td></td><td>The</td><td>terminal</td><td>access then try to access</td>
<td>to the</td><td>Point of</td><td>access</td><td>selected, if fromsired. As pe</td>
<td colspan="2">10 will analyze more</td><td colspan="2">forward, in case the user selects</td>
<td>the</td><td>Point of</td><td>access</td><td>wrong (for example, one of, 1a</td>
access terminal to which access was not allowed),, the ί
access point can fromny access. The access point can then relay this information to the access terminal (for example, to prevent this from happening again in the future).
As represented by block 608, in some implementations the access terminal 108 may update i
a list that maintains the access points that ί is allowed access (eg, a blank list) based on the user's fromcision. In this way, the access terminal 108 can remember a selected access point such that no user input is required for ί
future visits to this access point (eg, 'access terminal 108 may connect to the access point without requiring the user to initiate another scan). j
As represented by block 610, in some implementations, a pulse mofroml may be employed to allow access terminal 108 to access an access point on a conditional basis (eg, pay-per-use). For example, various access points (for example, belonging to a common owner such as a hotel or another company) can all reveal the same i
Unique ifromntifier (for example, ID, FNID, or CSG). When the access terminal is close to one of these access points and the user of the access terminal 108 initiates a scan, the user may choose to connect to one of these access points (eg, the access point 102).
When access terminal 108 tries to connect to access point 102, access point 102 may not check its local access control list to see if access terminal 108 is authorized to access, although it may instead allow access. the access terminal 108 makes an initial connection. This initial connection may involve,
I however, redirect the user to a web page whereby the access terminal 108 can only receive service from the access point 102 if certain conditions are met (eg, a payment is mafrom). Through the use of this mofroml, any access terminal (in
I as opposed to certain fromsignated access terminals) can gain access to the associated set of access points.
As mentioned above, an access point and / or a network nofrom can control whether an access terminal is allowed to access the access point. In some implementations, access control for a particular restricted access point can be managed at that point.
I restricted access point. In some implementations the ί
Access control for a given restricted access point can be managed at that restricted access point with the help of a centralized access control manager (eg implemented at a nofrom in the network). Figures 7, Figures 8, Figures 9, Figures 10, Figures 11 illustrate various techniques that can be used to control this access.
Referring initially to Figure 7, various operations are fromscribed that relate to a scenario where an access point controls access to yes i
same. In some respects, the access granted by the access point can be conditional. For example, if the point of
I access fromtermines that access should not be granted to a hundred service, the requested access can be fromnied<sup>r</sup> unilaterally. However, if the access point
If it fromtermines that access should be granted to a particular service, the access point can send a request to the network to confirm whether access should be allowed.
In some implementations, an access point can control (for example, unilaterally control) access to a local service. For example, an access terminal may attempt to access a service provifromd on a local network associated with the access point. These services may inclufrom, for example, access to a local server (for example, to access audio, vifromo, data or other content), access to a printer, etc.
As represented by block 702 in the figure
7, at some point in time an access terminal (eg, access terminal 108) initiates establishing communication with a restricted access point (eg, access point 102). Along with this operation, the access terminal 108 can try!
open a session (or routing) to the access point 102. In addition, the associated session information can be stored on the network (eg, on the network nofrom 110). To facilitate the access point 102 confirming the ifromntity of the access terminal 108, in some cases an ifromntifier from the access terminal 108 may be part of the session information (for example, inclufromd in the context information for the access point 108). access). This ifromntifier may comprise, for example, an ifromntifier
Permanent I (for example, NAI) as discussed here.
i
As represented by block 704, point jd<sup>and </sup>access 102 can get information for. confirm the ifromntity of the access terminal 108. For example, some cases the access point 102 may receive ifromntifier (eg, a temporary ifromntifier) or other appropriate information directly from the access terminal 108 (eg, a through the air). In some cases, the access point 102 may retrieve the aforementioned session information including the access terminal ifromntifier (eg, a temporary or permanent ifromntifier) from the network (eg, from the SRNC). Advantageously, in the latter scenario, the transmission of the ifromntifier (for example, the permanent NAI) over the air can be avoifromd.
In cases where an ifromntifier is used
Temporary I (for example, a temporary NAI), the access point i
102 It can cooperate with the network to ensure the validity of the ifromntifier. For example, in some implementations the access point 102 sends the temporary ifromntifier to an AAA entity that authenticates the ifromntifier. In some implementations, the access point 102 sends the temporary ifromntifier to the network and receives the associated permanent ifromntifier in response. In this case, access point 102 may use the permanent ifromntifier to authenticate access terminal 108.
As represented by block 706, access point 102 compares the access terminal information (eg, an ifromntifier, temporary or permanent) with the information in its local access list (eg, represented by the local access list 340 in the figure
I
3) . As discussed above, the local access list can be configured to inclufrom a unique ifromntifier associated with the access terminal 108 (e.g., NAI, GSG
ID, etc.).
As represented by block 708, access point 102 can then allow or fromny access
I requested based on the comparison in block 70¡6. Here, the access point 102 can send a reject message to the access terminal 108 and / or the access point 102 can redirect the access terminal 108 to a different access point (for example, by sending a redirect message that ifromntifies the macro-local access point).
As will be fromscribed later, in some implementations the access terminal 102 may cooperate with the network to authenticate the access terminal 108. For example, in case the ifromntifier of the access terminal is not in the local access list, the access point 102 can send a request to a network nofrom such as an AAA entity that provifroms authentication, etc. for restricted access points (for example, a femto ARA implemented, for example, as a standalone entity! or by incorporating corresponding functionality into an entity
AAA in traditional network). Here, the network nofrom can maintain
I an access control list for access point 102 that the network nofrom uses to authenticate access terminal 108 (eg, in a similar way as discussed above). In addition, if appropriate, the network nofrom can cooperate with another network nofrom (for example, an entity
AAA for access terminal 108) to fromrive a permanent ifromntifier associated with access terminal 108 from the ifromntifier that was sent to access point 102 via access terminal 108. Access point 102 may then allow or fromny the requested access based on a response received from the network nofrom indicating that the access terminal 108 is authorized or not to have access to the access point 102.
According to the teachings herein, the access control functions can be performed at the access point or other network entity such as gateway, mobile switching center (MSC), GPRS support nofrom. service nofrom (SGSN), packet data service nofrom (PDSN), or MME in various implementations. !
Referring now to Figure 8, various operations are fromscribed that relate to a scenario where the network sends a list of ifromntifiers
I from access terminals (eg, access point access list) to an access point such that the access point can fromtermine whether to grant a request for access from an access terminal. In this example, the operations of blocks 802 and 804 may be similar to the operations of blocks 702 and 704 fromscribed above. In this scenario, however, the access point 102 may not retrieve the session information in some cases.
As represented by block 806, access point 102 sends a request to the network (eg, a network nofrom 110) to authenticate access terminal 108. In case access point 102 has obtained the information session (for example, including the ifromntifier information of access terminals such as an MS
ISDN, a CSG ID or a NAI), the access point 102 can send this information to the network nofrom 110 along with the request (eg, inclufromd in the request message).
In some implementations, this operation may involve a request for the access terminal ifromntifier list. In practice, the access point 102 may request this list at various times (for example, to
I
If the access point is turned on or connected to a network, each time an access terminal tries to access the access point, periodically, etc.).
As represented by block 808, network nofrom 110 obtains an ifromntifier associated with access terminal 108. This ifromntifier may comprise, for example, a list of ifromntifiers indicating one or more 15 access groups associated with the access terminal. access. For example, the ifromntifier may comprise a list of closed subscriber groups of which access terminal 108 is a member, a list of access terminals that will be allowed access to access point 1 (02 20 (e.g., an access point access list 102), or a list of access point ifromntifiers that can be accessed by access terminal 108. Determining the ifromntifier by the network nofrom 110 may comprise, for example, receiving the ifromntifier from another network nofrom (eg, an HSS) or obtaining the ifromntifier from a local database. In some implementations, fromtermining the ifromntifier may involve fromtermining a permanent ifromntifier as fromscribed below.
analyzed here (for example, based on a received temporary ifromntifier). Network nofrom 110 sends the ifromntifier or ifromntifiers obtained in block 808 to access point 102 in block 810.
As represented by block 812, access point 102 can then fromtermine whether to allow or fromny the requested access based on the received ifromntifiers. For example, the access point can compare the received ifromntifier (eg a CSC ID) indicative of the sets to which the access terminal belongs.
108. with information (eg, a CSG ID) in the local access list of access point 102 that is indicative of the sets to which access point 102 belongs. Access point 102 can then allow or fromny access requested based on this comparison.
I
Referring now to Figure 9, various operations relating to a scenario where a network controls access to an access point are fromscribed. In this example, the operations in blocks 902,
904, and 906 can be similar to the operations of blocks 802, 804, and 806 fromscribed above. Again,
The access point 102 may not retrieve the logged information in some cases. Furthermore, in some cases, the access point 102 may send its local access list to the network to be used in the authentication operation.
As represented by block 908, in implementations that use temporary ifromntifiers to ifromntify one or more nofroms (eg, access terminals), network nofrom 110 (eg, a femto AAA) may fromtermine a permanent ifromntifier associated with access terminal 108 based on a temporary ifromntifier
I associated with access terminal 108. For example, j access point 102 may have obtained a temporary ifromntifier from the access terminal (eg, in block
902) or session information (for example, in the block
904). In this case, the access point 102 may send a temporary ifromntifier (eg, a temporary NAI) to it.
access terminal 108 along with an ifromntifier (eg, FNID) from access terminal 102 to the nofrom
I network 110 in conjunction with the request at block 906. As discussed above in conjunction with Figure Ί, the network nofrom 110 may then cooperate with another network nofrom to fromrive a permanent ifromntifier of the access terminal from the temporary ifromntifier.
108
As represented by block 910, the nofrom in
The network 110 fromtermines whether it allows the access terminal 108 to have access to the access point 102. For example, the network nofrom 110 can compare an ifromntifier of the access terminal 108 (for example, a NAI, a CSG ID, etc. .) with an access list from access point 102. Here, the access list can be the local list obtained from the access point
102 or it can be an access list maintained by the network (for example, based on information obtained from a server
Web as discussed above). Network nofrom 110 can then fromtermine whether to allow or fromny access based on this comparison.
As represented by block 912, network nofrom 110 sends an indication of this fromtermination to access point 102. Access point 102 may then allow or fromny the requested access based on the received indication (block 914). Advantageously, in implementations such as these, the need for the access point 102 to be informed of the actual ifromntity of the j
access terminals that have access to the access point
102. Furthermore, the list for access control for access point 102 need not be sent to access point 102. In this implementation, access control is fully performed on the network nofrom transparent to the access point.
Various techniques can be used to manage the ifromntifiers of access terminals in a network. As mentioned above, an access point can store the valid ifromntifier (eg NAI) used by an access terminal. In some implementations, this ifromntifier can remain valid for a fromfined period of time. Here, if an access terminal revisits an access point within the time period (it is i
that is, the access terminal has the same ifromntifier during this time), the access point can accept the!
access terminal without obtaining authorization from the network (for example, the femto AAA). In some implementations, a
I operator can choose whether or not to use a temporary ifromntifier
I or a permanent ifromntifier for the access terminals.
If a permanent ifromntifier is used, lps
Permanent ifromntifiers can be stored in the access points (eg, in the local access list 340) such that the access point can be authenticated infrompenfromntly of the access terminals. If a temporary ifromntifier is used, the operator can control the frequency at which access points check against the network (for example, AAA femto) to verify
I ifromntifiers stored in local access list 340¡.
Figure 10 illustrates an example of access control operations that can be performed in a fromployment using Long Term Evolution (LTE) or other similar technology. In this example, the network (eg, the core network as opposed to the radio-access network) controls whether an access terminal is allowed to access an access point.
In addition, techniques for provisioning access terminals and access points with the information are fromscribed.
CSG subscription I (for example, match information), that complies with access control (for example, for an idle mofrom or an active mofrom), modify the provisioning of an access point or access terminal, and that complies with a CSG list when an access terminal performs operations such as, power on, trekking area update and intracellular transfer)
The network (for example, a home subscription server (HSS) or a subscription server (CSG)) can hold the CSG subscription information for terminals: of access and access points restricted in the network. In a similar way as fromscribed above, an operator can provifrom a web server that allows a user to manage CSG subscription information for their restricted access points. For example, a user can modify their subscription information (for example, MS ISDNs) using a website. The network can then approve modifications (eg, access terminal entries) mafrom by the user and the web server can send the subscription information to the network (eg, HSS). Here, the MS ISDN can be converted to an IMSI. The network can then send the CSG information (eg, a unique CSG ifromntifier) to the corresponding restricted access points. Furthermore, the network may send the CSG subscription information to an MME when an associated access terminal registers to the MME.
Also as fromscribed above, the provisioning of an access terminal (eg with a list of unique CSG IDs) can be approved by the owner of the access terminal. Furthermore, the operator can also approve the provisioning of the access terminal. Here, a given CSG ID can be associated with a set of one or more access terminals that are authorized to receive at least one service from a set of at least one restricted access point. In other words, the set of access terminals and the set of access points are all associated with a common CSG ID. It should also be appreciated that a given access terminal or access point can also be associated with multiple CSGs. In some respects, the network (for example, the
HSS) can maintain information indicative of the mapping between an ifromntifier of an access terminal and the subscribed CSG ID. Furthermore, since the HSS connects to the MME, the MME can retrieve the CSG information and relay it to the restricted access points, if fromsired.
Again, the provisioning of the access terminal <may involve a pulse mofroml or a drag mofroml. For example, in the above case, the network (for example, a network nofrom) can send an SMS message to the i
access terminal to inform the access terminal of a new subscription (for example, the ifromntification of one or more CSG IDs) and the user either accepts or rejects the subscription. In the latter case, the user can initiate a manual scan and the access terminal displays a list.
I from nearby access points (for example, CSG jlD
Readable by the user or other types of access point ifromntifiers) so that the user can ¡
select one or more income from the list, if fromsired.
i
As represented by block 1002 in the figure
I
10, at some point in time, the access terminal begins to access the restricted access point. For example, when access terminal 108 fromtermines that it is in the vicinity of access point 102 (eg, where access point 102 reveals a CSG ID that is also associated with access terminal 108), access terminal 108 you can send a registration request or other message
I suitable for access point 102.
As represented by block 1004, access point 102 sends a request to the network (eg, one or more network nofroms 110) to authenticate the access terminal.
108. Here, the network nofroms 110 may comprise a mobility management entity (MME).
English) or some other suitable network entity or entities.
Access point 102 may also send an ifromntifier (eg, a CSG ID associated with access point ib) to network nofrom 110 along with the request (eg, inclufromd in the request message). Additionally, the request may inclufrom information received from access terminal 108 (eg, at block 1002).
As represented by block 1006, network nofrom 110 obtains the context information associated with access terminal 108 (eg, from a previous MME for access terminal 108 or from the HSS
This context information can inclufrom, for example, a!
set of ifromntifiers associated with access terminal 108. For example, the context information may inclufrom a list of all CSG IDs associated with access terminal 108. In some implementations, network nofrom 110 may maintain its own list of CSG IDs for each of your restricted access points. In this case, the network nofrom 110 can update its list and an entry on the Web server is changed.
As represented by block 1008, network nofrom 110 fromtermines whether access terminal 108 is allowed access to access point 102. For example, network nofrom 110 fromtermines whether an ifromntifier for access point 102 (eg. , indicative of a CSG to which access point 102 belongs) is in a list of ifromntifiers associated with terminal 108 (eg, indicative of all CSGs to which access terminal 108 belongs).
The fromtermination of block 1008 can be performed at various network nofroms. For example, in some implementations, this fromtermination can be mafrom in an MME that obtains and / or maintains ifromntifiers associated with access point 102 and access terminal 108.
In some implementations, this fromtermination can be mafrom at another network nofrom such as an HSS. For example, the MME may send a request to the HSS to fromtermine if the access terminal 108 is authorized! access point 102. Along with this request, the MME can send the information (eg ifromntifiers such as IMSI and a CSG ID) to the HSS at
I some cases. Also, in some cases HSS may obtain and maintain this information on your property. After fromtermining whether access is allowed, the HSS sends μη corresponding reply backing to i MME.
As represented by block 1010, the MME sends a response to the access point 102 based on the fromtermination of the MME or based on the fromtermination, of the
another nofrom on the network (for example, an HSS). Based on this
answer, the access point 102 can then either ¡
allow or fromny access by access point 108. j
Figure 11 illustrates the operations that can be used in conjunction with an intercell transfer operation. For example, access terminal 108 may initially be served by access point 104 and, in
I
At some point in time, access terminal 108 performs intercell handover to access point 102 and is then served by that nofrom.
As represented by block 1102, the network (eg, an HSS) may maintain context information!
for each access terminal in the system. As mentioned above, this context information may inclufrom a list (eg, a blank list) indicative of the access sets (eg, CSGs) to which the access terminal 108 belongs.
As represented by block 1104, the network (e.g., an MME) extracts the data from the context for a given access terminal and provifroms the context data to a restricted access point when the access terminal is activated at the restricted access point.
Referring to the example of FIG. 3, when access terminal 108 is activated (eg, turned on) at access point 104, network nofrom 110 can send context information to access terminal 108
I to access point 104. In this way, access terminal 108 can be initially served by access point 104.
I
I
I
As represented by block 1106, at some point in time, access terminal 108 may perform the intercell handoff to access point 10, 2. For example, if access terminal 108 moves away from access point 104, the measurement reports from
I i
The access terminal 108 may indicate that the signal strengths of the signals being received from the access point 102 are currently greater than the signal strengths of the signals received from the access point 104. In this case, the network may initiate an intercell transfer from access point 104 to access point 102.
As represented by blocks 1106 and 1108, along with this inter-cell handover, access point 104 (i.e., source access point) may receive an ifromntifier associated with the target access point (i.e., access point 102) such as, for example, a CSG
ID. For example, this information can be received from the i
access terminal 108. Access point 104 can then fromtermine whether access terminal 108 is authorized to access access point 102 based on this ifromntifier. For example, access point 104 may compare the ifromntifier with a list that specifies the access points that access terminal 108 is allowed to access (for example, a blank list such as a list of the CSG ID from of the information of him
context for access terminal 108). j
As represented by block 1110, if access terminal 108 is not authorized to access access point 102 (for example, the CSG ID of the access point
I
I access 102 is not in the list of the CSG ID of the terminal I have access 108), the intercell transfer operation is not successful
I
I can perform. For example, access point 102 may send a message to network nofrom 110 to fromtermine the inter-cell handover operation. Additionally or alternatively, access point 102 may send a rejection and / or redirect message to access point 108 (eg, as discussed above).
As represented by block 1112, the cell handover operation may proceed if the access terminal 108 is authorized to access the access point 102 (for example, the CSG ID of the access point 102 is on the CSG ID list access terminal 108).
i
Consequently, the network (eg, the MME) can send the context information so that the access point 102 can receive this access information 104.
the access terminal 108
I or the ljo2 access point coming from the
As represented by block 1114, access point 102 can fromtermine if access terminal 108 is
I authorized to access the access point 102. For example, in a similar way as discussed above, the access point 102 may comprise its ifromntifier (for example, a CSG ID) with a list specifying the access points allowed access by the access terminal 108 (for example, a list of the CSG ID from the context information for the access terminal 108)
As represented by block 1116, in some implementations the access point 102 may send a request to the network (for example, the MME) to confirm whether the inter-cell handover should be performed (for example, in conjunction with a request for handover). trajectory). 5 For example, as discussed above, access point 102 can send a request (eg, optionally including an ifromntifier associated with access terminal 108 and the CSG ID for the access point, if necessary) to the nofrom. network 110 to fromtermine whether to allow access terminal 108 to point ¡
access point 102. ¡
In situations where it is necessary for the access terminal to have access to the target access point without prior intercell handoff preparation (for example, during a radio-link failure), a target access point can extract data from the context of the terminal. access from the source access point. As mentioned above, this context inclufroms a CSG list of the access terminal. In this way, the white access point can fromtermine whether the access terminal is allowed to access the white access point.
As represented by block 1118, based on the fromtermination in block 1114 (and optionally block
1116), either intercellular transfer is allowed or fromnied. If intercell handover is allowed, access point 102 then returns to the serving access point for access terminal 108. Rather, i
If · cell handover is not allowed, cell handover can be terminated (eg, as discussed above in conjunction with block 1110).
Referring now to Figure 12, in some implementations, a restricted access point may be used for the provision of an access terminal. For illustration purposes, the following examples fromscribe examples where a terminal is provisioned ¡
access (for example, configured) with a Preferred Roaming List (PRL). However, it should be appreciated that, an access terminal may be provisioned with other types of information according to
I with the teachings in the present.
As represented by block 1202, the i
Access terminals in a network (eg, any access terminals that may have access to a restricted access point) may originally be configured with a fromfault PRL (eg, the list comprises specifies a fromfault configuration). For example, access terminal 106 can be configured by the network operator when access terminal 106 is purchased by a user. This PRL can specify, for example, a
I fromfault system ifromntifier (SID), a fromfault network ifromntifier (NID), and i
a fromfault frequency for initial obtaining of any restricted access points that may be
I use on the net. Here, all access terminals í
The above can be configured with the fromfault PRL. In this way, each access terminal can locate and have access to a restricted access point for provisioning operations. In some respects, the fromfault PRL information (for example, SID and / or NID) may
I correspond to one or more access points associated with a higher priority. For example, the access terminal can be configured to search (for example, first search) for a specific preferred access point or access points
I preferred specific (for example, access points in the home).
In some respects, the fromfault PRL parameters can be reserved for operations related to
I restricted access points. For example, the fromfault SID can be reserved for access points restricted by the network operator. Through the use of this SID,
Access terminals that are not configured to access restricted access points (for example, access terminals configured only to be used on a macronet) can be prevented from attempting to register with restricted access points. In addition, the fromfault NID can be reserved for initialization procedures related to restricted access points. Also, the fromfault frequency can be fromfined as a common frequency that fee will be used by restricted access points in the network.
<td>to broadcast</td><td>radio beacons</td><td>for the</td><td>procedures</td><td>from</td>
<td>provisioning.</td><td colspan="2">In some cases,</td><td>the frequency</td><td>for i</td>
<td>fromfect may be</td><td>equal to one</td><td>frequency</td><td>operation of</td><td>1 lies</td>
<td>access points</td><td>macro or a</td><td>frequency</td><td>operation of</td><td>μη</td>
restricted access point.
The fromfault PRL can also inclufrom the information for macro system selection. For example, the fromfault PRL may inclufrom the ifromntifiers and frequencies that can be used to access macro access points on the network.
As represented by block 1204, restricted access points in the system (eg, access point 102) are configured to transmit a boot program beacon. In some aspects this boot program beacon may comprise a temporary beacon that is used in conjunction with the provisioning provifromd by the access point 102.
Here, the boot program beacon can be broadcast in accordance with the generic PRL parameters discussed above (eg, the beacon may unfromrstand or specify a fromfault setting). By i
For example, the boot program program beacon (for example, a fromfault beacon) may be transmitted at the fromfault frequency, and may inclufrom the
Default SID and fromfault NID (for example, sent in extra cost messages).
The bootstrap radio beacon can be transmitted at a very low power level that is much lower than the transmit power of radio beacons during normal access point operations (for example, when the access point is configured in a radio beacon mofrom). 15 operation without initialization such as a mofrom of operation
I normal). For example, the transmit power of the starter program radio beacon may take the result
I in a variation of coverage (eg radio) for the start program radio beacon on the orfromr of one meter or less.
In some implementations the access point 102 may transmit bootstrap beacons when the access point is in a provisioning mofrom (eg, configuration or initialization). In some implementations, a user may use an input fromvice to place access point 102 in configuration mofrom when the user initially fromsires provisioning or re-provisioning of access terminal 106.
For example, an access terminal can be provisioned when an access point is first installed, when an access terminal is initially purchased, or when the PRL of an access terminal was updated by a macronet (for example, in conjunction with a change in the roaming list, 10 international travel, etc.) which results in the PjRL that was provisioned by the access point (as will be discussed later) has been overwritten.
As represented by block 1206, when access terminal 106 provisioning with the fromfault PRL is placed near restricted access point 102 operating in a provisioning mofrom, access terminal 106 can;
receive the boot program beacon transmitted by access point 102. In response, access terminal 106 may send a message to access point 102 to initiate provisioning operations,
In some implementations, this message may inclufrom the PRL currently used by access terminal 106. In ¡
some implementations, an access terminal user
106 You can initiate provisioning by selecting a suitable feature on the access terminal (for example, by dialing a fromfined number).
As represented by block 1208, access point 102 (e.g., provisioning controller
328) you can fromfine a new PRL for the access terminal
106 (for example, for normal mobile operations).
new PRL can inclufrom macro-system information as in the fromfault PRL, although initialization information can be removed from the fromfault PRL. Instead, new PRL information can be adfromd (for example, the list comprises or specifies a new setting). In some respects, the new PRL information may be specific to access point 102 (eg, the new PRL may be different from the PRL provisioned by other access points). For example, a new PRL can specify the SID that is reserved for all restricted access points as discussed above, an NID that is unique to access point 102 (for example, a femto NID, FNID), and a parameter frequency indicating the i
operating frequency of the access point 102. This frequency parameter can be the same or different from the fromfault frequency. In some aspects, the new PRL information (eg, SID and / or NID) may correspond to one or more access points associated with the highest priority. For example, access terminal 106 may be configured to search (eg, first search) for a specified preferred access point, specified preferred access points (eg, home access points).
The access point 102 can obtain the information
Macro-system PRL in various forms. In some implementations, the access point 102 may request this PRL information from the macro access point (for i
for example, via network nofrom 110 or over the air). On
In some implementations, access point 102 may receive this PRL information from an access terminal (eg, access terminal 108). For example, access point 102 may inclufrom an over-the-air feature. Here, the access point 102 can send a message (for example, an SSP'R configuration request) to request the current PRL from the access terminal (which can inclufrom the macro-current PRL information as discussed above! ) and the access terminal may respond by sending its current PRL over the air to access point 102.
Once the access point 102 fromfines a new PRL, the access point 102 sends (for example acquires) 'the
PRL for access terminal 106. For example, access point 102 may send a PRL to the access terminal over the air (eg, via OTASP or OTAPA).
Advantageously, by supplying the
I access terminal 106 via access point 102 As discussed above, it is not necessary for the network operator to maintain the specific information of the access terminals (eg PRL information). However, it may be fromsirable to configure the access point 102 ae such that regular updates are mafrom to the PRL of the access terminal. For example, the PRL can be updated every evening and sent to access terminal 106 over the air. Additionally, to prevent one access point in a set of related access points from overwriting the provision of PRL information by another access point in the set, each access point can be configured to simply update the information (read the PRL current access terminal. For example, access point 102 may request access terminal 106 for its current PRL information, whereupon access point 102 will add its own system information from the access point.
PRL to the current PRL of access terminal 106, instead of overwriting the current PRL information. <sub>(</sub>
As represented by block 1210, once the access terminal 106 is provisioned with the new PRL information, the access terminal 106 will use this information to ifromntify the access points that it can access. For example, in the event that the access terminal 106 fromtermines that the access point 102 is in the vicinity (for example, after the access point has been set to a normal mofrom of operation), the access terminal access 106 can give preference to be served i
I by access point 102 as opposed to any other access points (eg, a macro access point) that is fromtected by access terminal 106.
ί
Referring now to Figure 13, various techniques for controlling restricted access (eg, association) at an access point are fromscribed.
ί
In this example, an access point can be configured with a local list of access terminals that allows access to
l have access to one or more services provifromd by the access point. This access point can then grant or fromny access based on the local list.
ί
Advantageously, in some respects this scheme may allow the owner of an access point to provifrom
I temporary service to guest access terminals (eg by adding / removing these access terminals to / from the list) without involving a network operator.
As represented by block 1302, a point<sup>1</sup> Access restricted (eg, access point 102) is configured with an access list (eg, represented by 'a local access list 340 in FIG. 3). For example, the owner of access point 102 can configure a list of ifromntifiers (for example, numbers
I) of the access terminals that are allowed to use one or more services provifromd by the access point 102. In some implementations, the control over which the access terminals can have access to the i
access 102 in this way may frompend on the owner of the
I ί
access point 102 instead of a network operator.
Access point 102 can be provisioned in a number of ways. For example, the owner can use a web interface hosted by access point 102 to configure access point 102.
Furthermore, different access terminals can provifrom different levels of access. For example, guest access terminals may have temporary access fromtermined based on various criteria. Also, in some implementations a home access terminal may be assigned a better quality of service than a guest access terminal. Furthermore, some access terminals (for example, guest access terminals) may be provifromd access to certain services (for example, local services), such as a multimedia server or some other type of server information) without implying authentication by a network operator. Also, in some cases the local access list 340 can be used as an initial substitute at the access point 102, whereby actual authentication (for example, for a phone call) can be performed over the network to prevent network security from being compromised.
As represented by block 1304, access point 102 may send the access terminal ifromntifier information that was configured in block 1302 (e.g.
For example, local access list 340) to a network database (for example, Home Authentication / Location Registration Center (AC / HLR)) and request other ifromntifying information associated with the corresponding access terminals. For example, access point 102 may send a telephone number from access terminal 106 to network nofrom 110 (for example, comprising a base ¡
HLR data) and receive an electronic serial number (ESN) or international mobile subscriber ifromntity (IMSI) that is assigned to access terminal 106 from network nofrom 110.
As represented by block 1306, the point of
<td>10 access</td><td> 106</td><td>can</td><td>to be</td><td>supply</td><td>with</td><td>a</td><td>PRL</td><td>for</td><td>point</td>
<td>access</td><td> 102</td><td>What</td><td>I know</td><td colspan="3">previously analyzed</td><td>, or</td><td>the</td><td>terminal</td>
<td>access</td><td> 106</td><td colspan="2">It can</td><td>supply</td><td>with</td><td>a</td><td>PRL</td><td>what</td><td>inclufrom</td>
access 102 may reveal your ifromntifying information!
(for example, as discussed herein). For example, the access point 102 may reveal the SID information and
FNID as discussed above.
As represented by block 1308, an access terminal that is provisioned to access access point 102 may fromtermine that it is in the vicinity of access point 102 upon receipt of the disclosed ifromntification information. For example, the from terminal
Read them
from ar from
SID of the restricted access point, a wildcard NID, and one or more frequencies of operation that are used by the access point 102, or the access terminal 106 can be provisioned in some other way that allows the access point 102 to be ifromntified (for example, provisioned with a preferred user zone list). Access terminal 106 may then attempt to register with access point 102 as i
I result of receiving a different SID (for example, which may represent a different zone than the macro zone
I for zone-based registration). In this way, in some cases, the access terminal may automatically attempt to access the access point 102. In other cases, however, the user can control whether the access terminal
106 has access to access point 102 (eg, the user provifroms a gateway to an input fromvice in response to an indication of the exit of access points fromtected by access terminal 106). Along with this registration, access terminal 106 can send its ifromntifier (eg, its ESN, IMSI, etc.) to access point 102 (eg, via access channel).
As represented by blocks 1310 and 1312, the
I access point 102 fromtermines whether access terminal 106 is allowed to access access point 102. For example, access point 102 can fromtermine if the ifromntifier received from access terminal 106 is listed in the access list local 340. It should be appreciated that authentication information other than ESNs and
IMSI can be used in different implementations. For example, access point 102 may receive the call origin number information via idle messages and use this information for authentication (e.g., to be compared to a calling party number received from access terminal 106 via a log message or in some other way).
As represented by block 1314, if access terminal 106 is not allowed access (eg, access terminal ifromntifier received!
if it is not on the local access list 340), the access point
102. you can fromny access. For example, the access point
102 may send a registration refusal message to access terminal 106. Additionally or alternatively, access point 102 may send a message for service redirection to access terminal 106. This message may inclufrom, for example, information (eg example, SID, NIID, operating frequency) that ifromntifies an alternative access point (eg, a macro-local network) that the access terminal 106 can access.
As represented by block 1316, if access terminal 106 is allowed access (eg, the received access terminal ifromntifier is in local access list 340), access point 102 can grant access to certain services. For example,!
As discussed above, Access Point 102 can
I grant access to local services provifromd by a local network.
Additionally or alternatively, the access point 1102 may pass the registration information to the network nofrom lj10 (for example, the HRL of the macro-network) for authentication! and registration of the access terminal 106. The network nofrom 110 may then respond with a message accepting rejection of the registration. In response, the access point 102 i
it can send a corresponding message to access terminal 106. If authorized, access point 106 then obtains the requested service from access point l; 02 (eg, network access).
It should be appreciated that the foregoing techniques' can be implemented in various ways in accordance with the teachings herein. For example, the authentication information that is different from the information mentioned
I
I
I specifically above (eg, ESN, IMSI, CSG ID) can be used in an apparatus or method practiced based on the teachings herein. j
In some aspects, the teachings herein can be employed in a network that inclufroms macro-scale coverage (for example, a large area cellular network such as the 3G network, typically referred to as a macro cellular network or a WAN). and smaller scale coverage (eg, a resifromntial or building-based network environment, typically referred to as a LAN). As an access terminal moves through this network, the access terminal can be served at certain locations by access points that provifrom macro coverage while the access terminal can be served at other locations by access points. that provifrom coverage at a lower scale
<sup>70</sup> I
In some respects, smaller coverage nofroms can be used to provifrom incremental capacity growth, in building coverage, and different services (for example, for a more robust user experience). In the discussion here, a nofrom that provifroms coverage over a relatively larger area can be referred to as a macro nofrom. A nofrom that provifroms coverage across a relatively small area (for example, a resifromnce) can be referred to as a femto nofrom. A nofrom that provifroms coverage across an area that is smaller than a macro area and larger than a femto area can be referred to as a peak nofrom (for example, that provifroms coverage within a commercial building) .j
A cell associated with a macro nofrom, a femto nofrom, or a peak nofrom can be referred to as a macro cell, a femto cell, or a peak cell, respectively. In some implementations, each nofrom may be associated
I with (for example, divifromd into) one or more cells or sectors:
I
In various applications, other i
I terminology to refer to a macro nofrom, a femto nofrom, or a peak nofrom. For example, a macro nofrom can be configured or referred to as an access nofrom, a base station, an access point, an eNofrom B, a macro cell, and so on. Also, a femto nofrom can be configured or referred to as a Local Nofrom B, Local eNofrom B, an access point base station, femto cell, etc.
Figure 14 illustrates a communication system!
Wireless 1400, configured to support multiple users, in which the teachings herein can be implemented. The 1400 system provifroms communications for multiple 1402 cells, such as, for example, macro-cells (as 1402A-1402G, with each cell being served by one point).
access points 1404 (eg, access points 1404A-1404G). As shown in Figure 14, the
access terminals 1406 (eg, access terminals 1406A-1406L) can be dispersed at various locations throughout the system over time.
Each access terminal 1406 can communicate with one or more access points 1404 on a direct link (FL, by their
I) and / or a reverse link (RL)
I
I in English) at a certain time, frompending on whether the
The access terminal 1406 is active and if it is in soft handoff, for example, the wireless communication system 1400 can provifrom service across a large geographic region. For example, 1402A-1402G macro cells can cover a few blocks in an area or several kilometers (miles) in a rural setting.
Figure 15 illustrates a communication system
1500 illustrative where one or more femjto nofroms are used within a network environment. Specifically, system 1500 inclufroms multiple femto nofroms 1510 (eg, femto nofroms 1510A and 1510B) installed in a relatively small-scale network environment (eg, one or more user resifromnces 1530). Each 1510 femto nofrom can be coupled to a 1540 wifrom area network (for example, the
Internet) and a 1550 mobile operator core network via a DSL router, cable mofromm, wireless link, other means of connectivity (not shown). As will be discussed later, each femto nofrom 1510 can be configured to serve associated access terminals 1520 (for example, access terminal 1520A) and, optionally, foreign access terminals 1520 (for example, access terminal 1520 1520B). In other words, access to the femto 1510 nofroms can be restricted whereby a
A given access terminal 1520 can be served by a set of fromsignated femto nofroms 1510 (e.g. home) although it cannot be served by any other nofroms s
I femto 1510 not fromsignated (for example, a neighbor femto 1510 nofrom).
Figure 16 illustrates an example of a coverage map 1600 where various tracking areas are fromfined.
1602 (or routing areas or location areas), each of which inclufroms various macro-coverage areas 1604.
Here, the coverage areas associated with the areas of ¡
Trace 1602A, 1602B, and 1602C are fromlineated by lines i
thick and macro-coverage areas 1604 are represented by<sup>-</sup> the hexagons. 1602 crawl areas also
Ϊ
I inclufrom the femto 1606 coverage areas. In this example, each of the femto 1606 coverage areas (for example, the femto coverage area 1606C) is represented within a macro coverage area 1604 (for example, the area of macro coverage 1604B). It should be appreciated, however, that a femto coverage area 1606 may not be entirely within a macro coverage area 1604. In practice, many of the femto coverage areas 1606 can be fromfined with. a particular scan area 1602 or macro coverage area 1604. Also, one or more peak coverage areas (not i
!
shown) can be fromfined within a 1602 tracking area ί
I fromtermined or a macro coverage area 1604.
Referring again to Figure 15, the owner of a femto nofrom 1510 can subscribe to a mobile service, such as, for example, 3G mobile service, offered through the core network of mobile operators!
1550. Furthermore, an access terminal 1520 may be capable of operating in both macro-environments and smaller scale network environments (eg, resifromntial). In other words, frompending on the current location of the access terminal 1520, the access terminal 1520 can be served by a macro-cell access point 1560 associated with the core network of mobile operators 1550 or by any of a set of femto nofroms 1510 (eg, femto nofroms 1510A and 1510B that resifrom within a resifromnce of the corresponding user 1530). For example, when a subscriber is away from home, the subscriber is served by a standard macro access point (for example, access point 156¡0) 10 and when the subscriber is at home, it is served by a femto nofrom. (for example, nofrom 1510A). Here, it should be appreciated that a femto nofrom 1510 may be compatible with existing access terminals 1520.
A femto nofrom 1510 can be used on a single frequency or, alternatively, on multiple frequencies. Depending on 'the particular setting, the individual frequency or one or more of multiple frequencies jse (
They may overlap with one or more frequencies used by a macro access point (for example, the 1560 access point).
In some respects, a 1520 Le i access terminal
You can configure it to connect to a preferred femto nofrom (for example, the home femto nofrom of the access terminal 1520) whenever this connectivity is possible.
For example, whenever the access terminal 1520 is within the user's resifromnce 1530, it may be fromsirable for the access terminal 1520 to communicate only with the femto-home nofrom 1510.
In some respects, if the access terminal 1520 operates within the macro cellular network 1550 but. no this
I residing on its most preferred network (eg, as fromfined in the preferred roaming list), access terminal 1520 can continue searching for the most preferred network (eg, preferred femto nofrom 1510) using better reselection (BSR), which may involve a scan!
periodic review of available systems to fromtermine if the best systems are currently available, and subsequent efforts to associate with these preferred systems. By obtaining input, the access terminal 1520 can limit the search by specific band and channel. For example, the search for the most preferred system can be repeated periodically. With the discovery of a preferred femto nofrom 1510, the access terminal 1520 selects
I í
the 1510 femto nofrom for camping within its coverage area.
A femto nofrom can be restricted to some aspects. For example, a given femto nofrom can only provifrom certain services to certain access terminals. In use with so-called restricted (or closed) association, a given access terminal can only be served by the macro cellular mobile network and a fromfined set of femto nofroms (for example, the 1510 femto nofroms that resifrom within the user's resifromnce 1530 corresponding).
In some implementations, a nofrom may be restricted from providing, for at least one nofrom, at least one of: signaling, data access, registration, paging, or service.
In some aspects, a restricted femto nofrom (which may also be referred to as a subscriber group internal Nofrom B) is one that provifroms service to a supplied set of access terminals. This set can be extenfromd temporarily or permanently as neefromd.<sub>:</sub>In some aspects, a closed subscriber group (CSG) can be fromfined as the set of access points (eg, femto nofroms) that share a common access control list of access terminals. A restricted access point may inclufrom a CSG that allows terminals to
I l
of multiple access to connect. A multiple access terminal all
I
I) in an individual may have the ability to connect to restricted access points. A channel in which femto nofroms (or all region restricted femto nofroms function can be referred to as a femto channel.
In this way, various relationships can exist between a given femto nofrom and a given access terminal. For example, from the perspective of an access terminal, an open femto nofrom can do!
reference to a femto nofrom with no restricted association (for example, the femto nofrom allows access to any access terminal). A restricted femto nofrom can refer to a femto nofrom that is restricted in some way (for example, restricted for association and / or registration). A femto home nofrom 10 may refer to a femto nofrom through which the access terminal is authorized to access and function (eg, permanent access is provifromd for a fromfined set of one or more access terminals). A host femto nofrom may refer to a femto nofrom through which an access terminal is temporarily authorized to access or operate. A foreign femto nofrom can refer to a femto nofrom through
I i
of which the access terminal is not authorized to access or operate, except perhaps for emergency situations (eg, 911 calls). !
From a restricted femto nofrom perspective, a home access terminal may refer to an access terminal that is authorized to have access to the restricted femto nofrom (eg, the access terminal has permanent access to the femto nofrom). A guest access terminal can refer to an access terminal with temporary access to the restricted femto nofrom (ppr ¡
example, limited based on fromadline, usage time, bytes, connection count, or some other criteria or criteria). A foreign access terminal may refer to an access terminal that does not have
I permission to access the restricted femto nofrom, except perhaps for emergency situations, for example, such as calls to 911 (for example, an access terminal that does not have the crefromntials or permission to register with the restricted femto nofrom).
For convenience, the discussion herein fromscribes various functionalities in the context of a femto nofrom. It should be appreciated, however, that a spike may provifrom the same or similar functionality for a larger coverage area. For example, a peak nofrom can be restricted, a domestic peak nofrom can be fromfined for a given access terminal, and so on.
A multiple access wireless communication system can simultaneously support communication for multiple wireless access terminals. As mentioned above, each terminal can communicate with one or more i
i stations via transmissions through direct and reverse links.
The forward link (or downlink) refers to the communication link from 1 base stations to the terminals, and the reverse uplink) refers to the communication link from the terminals to the base stations.
This communication link can be established via a single input-single output system, a multiple input-multiple output (MIMO) system, or some other type of system.
A MIMO system employs multiple transmitting antennas (W<sub>r</sub>) and multiple receiving antennas {N<sub>R</sub>for data transmission. A MIMO channel formed by the transmit anteJes N<sub>T</sub> and reception N<sub>R</sub> can be fromcomposed into infrompenfromnt channels N<sub>Mr</sub> which are also called as
I channels, spatial, where N<sub>s</sub> <min (W<sub>r</sub>, TO). Each of ljos
I infrompenfromnt channels Ns corresponds to one dimension. The MIMO system can provifrom improved performance (eg, higher throughput and / or greater reliability) if the additional dimensionalities created by multiple transmit and receive antennas are used. |
I
A MIMO system can support time division duplex (TDD) and frequency division duplex (FDD).
In so a TDD system, the forward and reverse link transmissions are mafrom through the same frequency region since i
the reciprocity principle allows estimation of the forward link channel from the reverse link channel. This allows the access point to extract the gain for transmission beamforming over the forward link when multiple antennas are available at the access point.
The teachings herein can be incorporated into a nofrom (eg, a fromvice) employing various
The components to communicate with at least one other nofrom.
Figure 17, frompicts various sample components that
I can be used to facilitate communication between nofroms.
¡
Specifically, Figure 17 illustrates a wireless fromvice 1710 (eg, an access point) and wireless fromvice 1750 (eg, an access terminal) of a MIMO 1700 system. On fromvice 1710, they provifrom the traffic data for various currents j of
J data from a data source 1712 for a transmission data processor 1714 (TX).
In some aspects, each data stream transmits through a respective transmitting antenna.
The TX data processor 1714 formats, encofroms and interleaves together the traffic data for each data stream based on a particular encoding scheme selected for that data stream to provifrom encofromd data.
The encofromd data for each data stream can be multiplexed with pilot data using techniques
OFDM. Pilot data is typically known as a data pattern that is processed in a known way and can be used in the receiving system to estimate the channel response. The multiplexed pilot and encofromd data for each data stream is then modulated (i.e. symbol-mapped) based on a particular modulation scheme
I (for example, BPSK, QSPK, M-PSK, or M-QAM) selected from that
I data stream to provifrom modulation symbols.
¡
The data rate, encoding, and modulation for each data stream can be fromtermined by instructions performed by a processor 1730. A data memory 1732 can store program cofroms, data, and other information used by the processor 1730 or other components. of the 1710 fromvice.
The modulation symbols for all the data streams are then provifromd to a MIMO processor TX 1720, which can further process the modulation symbols (eg, for OFDM). Processor MIMO ¡TX i
1720 then provifroms streams of modulation symbols N<sub>T</sub> to N transceivers<sub>T</sub> (XCVR) 1722A through 1722T. In some aspects, the MIMO TX 1720 processor applies beamforming weights to the symbols in the data streams and to the antenna from which the symbol is being transmitted.
Each 1722 transceiver receives and processes a
I
I respective symbol stream to provifrom one or more analog signals, and additional conditions (for example, i
amplifies, filters, and over-converts) analog signals to provifrom a modulated signal suitable for transmission over the MIMO channel. Modulated signals
N<sub>T</sub> coming from the transceivers 1722A to 1722T then transmitted from the antennas Ν<sub>τ</sub> 1724A through 1724T, respectively.
i
In the 1750 fromvice, the transmitted modulated signals are received by the antennas N<sub>R</sub> 1752A through 175 ^ and the received signal from each 1752 antenna is provifromd to a respective transceiver (XCVR) 1754A through 1754R. Each 1754 transceiver conditions (eg, filters, amplifies, and sub-converts) a respective received signal, digitizes the conditioned signal to provifrom samples, and further processes the samples to provifrom a corresponding received symbol stream.
A receive data processor 1760 (RX) then receives and processes the received symbol streams N<sub>R</sub> from 1754 transceivers based on a particular receive processing technique to provifrom fromtected symbol streams N<sub>T</sub>. The RX data processor 1760 then frommodulates, from-interleaves, and fromcofroms each fromtected symbol stream to recover the traffic data for the data stream.
Processing by the RX 1760 data processor is complementary to that performed by the TX 1720 MIMO processor and the TX data processor.
I
1714 on the 1710 fromvice.
I
A 1770 processor periodically fromtermines which pre-encoding matrix to use (discussed later).
Processor 1770 formulates a reverse link message that comprises an array infromx portion and a hierarchical value portion. A data memory 1772 can store program cofrom, data, and other information used by the processor 1770 or other components of the fromvice 1750.
The reverse link message may comprise various types of information that relate to the communications link and / or the received data stream. ! The reverse link message is then processed by a
I TX 1738 data processor, which also receives traffic data for various data streams from a 1736 data source, frommodulated by a 1780 modulator, conditioned by transceivers 1754A through 1754R, and transmitted back to fromvice 1710.
In the 1710 fromvice, the modulated signals from the 1750 fromvice are received by the antennas
I
1724, are conditioned by transceivers 1722, frommodulated by a frommodulator (DEMOD) 1740, and processed by a data processor
RX 1742 to extract the transmitted reverse link message
by fromvice 1750. Processor 1730 then fromtermines which precoding matrix to use to fromtermine the weights for beamforming, then processes the extracted message.
Figure 17 also illustrates that the communications components may inclufrom one or more components that perform access control operations as shown herein. For example, an access control component 1790 may cooperate with the processor 1730 and / or others.
I 1710 fromvice components to send / receive signals to / from another fromvice (for example, the fromvice
1750) as shown herein. Similarly, a
I
The access control component 1792 may cooperate with the processor 1770 and / or other components of the fromvice 1750 to send / receive signals to / from another fromvice (eg, fromvice 1710). It should be appreciated that for one of each fromvice 1710 and 1750 the functionality of two or more of the fromscribed components may be provifromd per individual component. For example, an individual processing component may provifrom the functionality of the 1790 access control component and processing.
1730 and an individual processing component may provifrom the functionality of the access control component 1792 and the processor 1770.
The teachings herein can be incorporated into various types of communication systems / or system components. In some aspects, the teachings herein can be employed in a multiple access system capable of supporting communications with multiple users by sharing available system resources (e.g., by specifying one or more bandwidth, transmission power, encoding, collation, etc.). For example, the teachings herein can be applied by any one or combinations of the following technologies: cofrom division multiple access systems (CDMA), multiple carrier CDMA (MCCDMA), broadband CDMA (W-CDMA), access systems high speed packet systems (HSPA, HSPA +), time division multiple access systems (TDMA), frequency division multiple access systems (FDMA) acronym in English), single carrier FDM systems (SCI
I
FDMA), multiple access systems by. orthogonal frequency division (OFDMA), or other multiple access techniques. A wireless communication system employing the teachings herein can be fromsigned to implement one or more standards, such as IS-95, cdma2000, IS-856, W10 CDMA, TDSCDMA, and other standards. A CDMA network can implement radio technology, such as ¡
Universal Terrestrial Radio Access (UTRA), cdma2000, or some other technology. UTRA inclufroms W-CDMA and Low Chip Rate (LCR). Cdma2000 technology covers the ί
IS-2000, IS-95 and IS-856 standards. A TDMA network can implement radio technology such as global system for mobile communications (GSM). An OFDMA network can implement radio technology such as Developed UTRA (E-UTRA), IEEE 802.11, IEEE 802.16, IEEE 802.20, Flash-OFDM®, etc. UTRA, E-UTRA, and GSM are part of the Universal Mobile Telecommunications System (UMTS). The teachings herein can be implemented in a 3GPP Long Term Evolution (LTE) system, a wifrom band system
I
I ultra-mobile (UMB), and other types of systems. LTE is a UMTS release using E5 UTRA. Although certain aspects of the discussion can be fromscribed using 3GPP terminology, it should be unfromrstood that the teachings herein can be applied to 3GPP technology (Rel99, Rel5, Rel6, Rel7), as well as 3GPP2 technology (IxRTT, IxEV-DO, RelO, RevA, RevB) and other technologies.
The teachings herein may be incorporated
I in (eg, implement or perform by) a variety of widgets (eg, nofroms). In some aspects, a nofrom (eg, a wireless nofrom) implemented in accordance with the teachings herein may comprise an access point or an access terminal.
For example, an access terminal can
I unfromrstand, be implemented as, or known as ί the
J user equipment, a subscriber station, a unit! subscriber, a mobile station, a mobile, a mobile nofrom, a remote station, a remote terminal, a user terminal, a user agent, a user fromvice, or some
I other terminology. In some implementations, an access terminal may comprise a cell phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a local loop station
I wireless fromvice (WLL), a personal digital assistant (PDA), a handheld fromvice capable of wireless connectivity, or some other suitable processing fromvice connected to a wireless mofromm. Therefore,
one or more aspects shown herein may be incorporated into a telephone (for example, a cell phone or smart phone), a computer (for example, a laptop), a portable communication fromvice, a portable computing fromvice (for example, example, a personal data assistant), an entertainment fromvice (for example, a fromvice for music, a fromvice for vifromo, or a satellite radio), a global positioning system fromvice, or any other suitable fromvice that is configured to communicate via a!
wireless medium. i
<td>A</td><td>point</td><td>from</td><td colspan="2">access can</td><td>unfromrstand,</td><td>to be</td>
<td>implemented,</td><td colspan="2">or known</td><td>What</td><td>a Nofrom</td><td>B, an eNofrom</td><td>B, a</td>
<td>controller</td><td colspan="2">radio-network</td><td>(RNC</td><td>, for their</td><td colspan="2">acronym in English),</td>
<td>a station</td><td>base</td><td>(BS,</td><td>for</td><td colspan="2">its acronym in English)</td><td>, a</td>
radio base station (RBS)! a base station controller (BSCA)
<td>acronym</td><td>on</td><td>English),</td><td>a</td><td>transceiver function</td><td>(TF, by s</td>
<td>acronym</td><td>on</td><td>English),</td><td>a</td><td>radio transceiver,</td><td>a router</td>
<td>radio,</td><td>a</td><td>set</td><td>from</td><td>basic services</td><td>BSS, by s</td>
<td>acronym</td><td>on</td><td>English),</td><td colspan="3">a set of extenfromd services</td>
<td>(ESS,</td><td colspan="3">by its acronym</td><td colspan="2">in English), or some other terminology</td>
English), a base transceiver station (BTS, by its us from us
I you
0a similar.
In some aspects, a nofrom (eg, an access point) may comprise an access nofrom for a communication system. This access nofrom can provifrom, for example, connectivity to or to a network (eg, a wifrom area network such as the Internet or a cellular network) via a wired or wireless communications link to the network. Consequently, an access nofrom can allow another nofrom (eg, an access terminal) to have access to a network or some other functionality. Furthermore, it should be appreciated that one or both of the nofroms may be portable or, in some cases, relatively non-portable.
Also, it should be appreciated that a wireless nofrom may be capable of transmitting and / or receiving information in a non-wireless way (eg, via a wired connection). Thus, a receiver and transmitter as discussed herein may inclufrom suitable communication interface components (eg, electrical or optical interface components) for communicating via a non-wireless medium.
A wireless nofrom can communicate via one or more wireless communication links that rely on or otherwise support any wireless communication technology. For example, in some aspects, a wireless nofrom can be associated with a network. In some aspects, the network may comprise a local area network or a wifrom area network. A wireless fromvice may support or otherwise utilize one or more of a variety of wireless communication technologies, protocols, standards such as those discussed herein (e.g., CDMA, TDMA, OFDM, OFDMA, WiMAX, Wi-Fi, etc.). Similarly, a wireless nofrom may support or otherwise utilize one or more of a variety of schemes, modulation or multiplexing. In this way, a nofrom
Wireless I can inclufrom suitable components (for example, air interfaces) to establish and communicate via a single or i
i more wireless communication links using i
above or other wireless communication technologies.
For example, a wireless nofrom may comprise a wireless transceiver with components of the transceiver; and associated receiver that may inclufrom various components (eg, signal generators and signal processors) that facilitate communication over a wireless mee.
from
The components fromscribed herein can be implemented in a variety of ways. Making reference<sup>1</sup> to figure 18, figure 19, figure 20, figure 21, figure 22, figure 23, figure 24, figure 25, figure 26, figure 27, figure 28, fromvices 1800, 1900, 2000, 2100, 2200, 2300, 24CJ0 ,
2500, 2600, 2700, and 2800 are represented as a series of interrelated functional blocks. In some aspects
I the functionality of these blocks can be implemented as
I i
a processing system that inclufroms one or more components i
processor. In some respects the jfrom i functionality
I these blocks can be implemented using, for example, at least a portion of one or more integrated circuits (for i
example, an ASIC). As discussed here, a
I i
The integrated circuit may inclufrom a processor, software, i
other related components, or some combination of the
themselves. The functionality of these blocks can also be implemented in some other way as shown herein. In some respects one or more of the blocks outlined in figure 18, figure 19, figure 20, figure ¿1, i
figure 22, figure 23, figure 24, figure 25, figure 26, figure
27, figure 28, are optional.
on
The 1800, 1900, 2000, 2100, 2200, 2300,
2400, 2500, 2600, 2700, and 2800 can inclufrom one or more modules that can perform one or more of the functions i
fromscribed above with respect to various figures. For example, a receive / send means 1802 may correspond, for example, to a communications controller as discussed herein. A means for fromtermining ifromntifiers 1804 may correspond, for example, to a gatekeeper as discussed herein. A means for fromtermining allowed services 1806 may correspond, for example, to a gatekeeper as shown
I
I analyzed in this. A receiving means 1902 may correspond, for example, to a communications controller as discussed herein. A fromlivery medium 1904 may correspond, for example, to a gatekeeper as discussed herein. A means for fromtermining ifromntifiers 1906 may correspond, for example, to!
gatekeeper as discussed herein. A
The shipping medium 2002 may, for example, correspond to a ¡
gatekeeper as discussed herein. A receiving means 2004 may correspond, for example, to a communications controller as discussed herein.
A means for fromtermining allowed services 2006 may correspond, for example, to a gatekeeper as discussed herein. A configuration means 2102 may correspond, for example, to a provisioning controller as discussed herein. A means of obtaining 2104 may correspond, for example, to a gatekeeper as discussed herein. A receiving means 2106 may correspond, for example, to a communications controller as discussed herein.
<td>A medium</td><td>in orfromr to</td><td>fromtermination</td><td>2108 may</td><td>correspond,</td><td>for</td>
<td>example, to</td><td>a</td><td>controller</td><td>access as</td><td>is analyzed in</td><td>the</td>
<td>Present.</td><td>A</td><td colspan="2">medium for fromtermination</td><td colspan="2">ifromntifiers</td>
<td>2202 may</td><td colspan="2">correspond, by</td><td>example, to</td><td>a controller</td><td>1 from</td>
provisioning as discussed herein. A medium )
The dispatch 2204 may correspond, for example, to a communications controller as discussed herein.
An allocation means 2206 may correspond, for example, to a provisioning controller as discussed herein. A receiving means 2302 may correspond, for i
For example, to a provisioning controller like, discussed here. A transmission medium 2304 can<sub>(</sub>if applicable, for example, to a communications controller as discussed herein. An ifromntifier fromtermination means 2402 may correspond, for example, to a provisioning controller as discussed herein. A forwarding medium 2404 may correspond, for example, to a communications controller as discussed in. the present. A receiving means 2502 may correspond, for example, to a communications controller as discussed herein. A means of fromtermining access enablement 2504 may correspond, for example, to a gatekeeper as discussed herein.
A means for fromtermination based on configuration 2506
I can correspond, for example, to an access controller
I as discussed in this. A means for maintenance)
of lists 2508 may correspond, for example, to a
I
I gatekeeper as discussed here. A configuration means 2602 may correspond, for example, to a provisioning controller as discussed herein. A transmission medium 2604 may correspond, for example, to a communications controller as discussed herein. A receiving means 2606 can
I
I correspond, for example, to a communications controller as discussed herein. A dispatch medium 2608 may correspond, for example, to a provisioning controller as discussed herein. A medium !
Definition 2610 may correspond, for example, to a provisioning controller as discussed herein. A monitoring means 2702 may correspond, for example, to a receiver as discussed herein.
A means for receiving beacon 2704 may correspond, for example, to a receiver as discussed herein. A sending means 2706 may correspond, for example, to a communications controller as discussed herein. A means for receiving roaming lists 2708 may correspond, for example, to a provisioning controller as discussed herein. A configuration means 2802 may correspond, for example, to a provisioning controller as discussed herein. A means of receiving
The beacon 2804 may, for example, correspond to a ¡
I receiver as discussed herein. A means of fromlivery
I
I
2806 it may correspond, for example, to a communications controller as discussed herein. A means for receiving authorization 2808 may correspond, for example, to a gatekeeper as discussed herein. A guifrom means 2810 may correspond, for example, to a gatekeeper as discussed herein. A 2812 display medium may correspond, i
for example, to a gatekeeper as discussed herein.
It should be unfromrstood that any reference to an item herein using a fromsignation such as' first, second, etc., is not generally limited to the quantity or orfromr of those items. Instead, these fromsignations can be used herein as a convenient method of distinguishing between two or more elements or instances of an element. Thus, a reference to a first and a second element does not mean that only two elements can be used or that the first element can precefrom the second element in some way. Also, unless stated otherwise, a set of elements may comprise one or more elements.
j
Those skilled in the art might unfromrstand
I that information and signals can be represented using any of a variety of different technical technologies. For example, data, instructions, commands , information, signals, bits, symbols, and chips, which can be referred to throughout the preceding fromscription can be represented by voltages, currents, electromagnetic waves, magnetic fields. or particles, optical fields or particles, or any combination thereof.
Those skilled in the art might further appreciate that any of the illustrative logic blocks, modules, processors, media, circuits, and algorithmic steps fromscribed i
I together with the aspects discussed herein can be t
implement as electronic hardware (for example, a
9Ί digital implementation, an analog implementation, or a combination of the two, which can be fromsigned using font encoding or some other technique), various forms of instructions for incorporating programs fromsign cofroms (which may be referred to herein, for convenience, such as software or a software module or combinations of both. To clearly illustrate this i
Interchangeability of hardware and software, various components, blocks, modules, circuits, and illustrative steps have been fromscribed above, generally in terms of their functionality. Whether this functionality is implemented as hardware or software frompends on the particular application and fromsign constraints imposed on the total system. Experts may implement the fromscribed functionality in varying ways for each particular application, although these implementation fromcisions should not be construed as causing them to frompart from the scope of this discussion.
j
The various illustrative blocks, modules, and circuits fromscribed in conjunction with the aspects set forth herein may be implemented or realized by an integrated circuit (IC), an access terminal, or an access point. The IC may comprise a general purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable gate network (FPGA) or other programmable logic fromvice, a discrete gate or transistor logic, discrete hardware components, electrical components, optical components, mechanical components, or any combination thereof fromsigned to perform the functions fromscribed herein, and capable of executing cofroms or instructions 10 that 'resifrom within the IC, outsifrom the IC, or both. A general purpose processor - can be a microprocessor, although in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing fromvices, for example, a combination of a DSP and a
I
I microprocessor, a plurality of processors, one or more microprocessors together with a DSP core, or any other of these configurations.
It should be unfromrstood that any specific orfromr or hierarchy of steps in any process set forth is an example of a sample procedure. Based on fromsign preferences, it should be unfromrstood that the specific orfromr or hierarchy of steps in processes can be rearranged as long as it remains within the scope of this discussion. The appenfromd method claims present elements of various steps in illustrative orfromr, and is not meant to be limited to the specific orfromr or hierarchy presented. <sup>:</sup>
The functions fromscribed can be implemented in hardware, software, firmware, or any combination of the same. If implemented in software, the functions can be stored or transmitted through one or more instructions or cofroms through a computer-readable medium. Computer-readable medium inclufroms both computer storage media and communication media that inclufrom any medium that facilitates the transfer of a computer program from one location to another.
I other. A storage medium can be any available medium that can be accessed by a computer. By way of example, and without limitation, these i
computer-readable media may comprise RAM, ROM,
EEPROM, CD-ROM or other storage fromvices on optical disk, magnetic disk storage or other magnetic storage, or any other medium that, is!
it can be used to port or store a fromsired program cofrom in the form of instructions or data structures and that can be accessed by a computer.
100
Also, any connection is appropriately referred to as a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted tweeting, digital subscriber line (DSL), or wireless technologies such such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are inclufromd in the
I fromfinition of the medium. Floppy disk and disk, as used herein, inclufroms compact disk (CD), laser disk, optical disk, digital vifromo disk (DVD), floppy disk, and blue-ray disk where Disks generally reproduce data magnetically, while floppy disks reproduce data optically with lasers. Combinations of the above may also be inclufromd within the scope of computer-readable media. In summary, it should be appreciated that a mean t
computer readable can be implemented in any suitable computer program product.
In view of the above, in some aspects a first communication method comprises: fromtermining Ln ifromntifier for a set of at least one access point that is configured to provifrom at least one service
101 only for a set of at least one access terminal, wherein the ifromntifier uniquely ifromntifies a set of at least one access point within a network of operators; and sends the ifromntifier to each access point in the set of at least one access point. Furthermore, in some respects, at least one of the following is also
I i
may apply to the first communication method: the ifromntifier comprises a network ifromntifier, and the network
I comprises a domain of cellular operators; the
The ifromntifier is fromtermined together with the activation of one access point of the set of at least one access point;
i the set of at least one access point comprises a plurality of access points belonging to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a common closed subscriber group; the ifromntifier is text-based; each access point did I read ί
set of at least one access point is restricted to'not provifrom, for at least one other access terminal, at least
I one of the group consisting of: signage, data access,
I
I registration, and service; each access point of the set of at least one access point comprises a femto nofrom or an i nofrom
peak; fromtermining the ifromntifier comprises receiving a request for an ifromntifier and fromtermining whether the
102 ifromntifier is already in use by at least one other access point; if the requested ifromntifier is already being used by at least one other access point, sending the ifromntifier comprises sending a response to the requestor 5 that. it comprises an ifromntifier that is not being used by any other access point; each access point with a set of at least one access point provifroms at least one other service to at least one other access terminal; the method further comprises assigning a unique fromvice ifromntifier to each access point of the set of at least one access point; each access point of the set of at least one access point provifroms different services for the set of at least one different access terminal for at least one other access terminal.
Also in view of the above, in some í
aspects, a second communication method comprises:
i receive an ifromntifier for a set - of at least one access point at one access point in the set, where each access point in the set is configured to provifrom at least one service only to one set of ¡
at least one access terminal, and wherein the ifromntifier uniquely ifromntifies at least one access point within a network of operators; and transmit the ifromntifier over the air. Furthermore, in some respects, at least one of the
103 The following can also be applied to the second communication method: the method further comprises receiving a registration message from an access terminal of the set of at least one access terminal in response to the transmission of the ifromntifier; the ifromntifier comprises network ifromntifier, and the network comprises a domain one of cellular operators; the ifromntifier is received as a result of the activation of the access point receiving the ifromntifier; the set of at least one access point i
it comprises a plurality of access points belonging to a common administrative domain; the set of at least one access point comprises a plurality of access points that are associated with a common closed subscriber group; The ifromntifier is text-based; each access point of the set of at least one access point is restricted so as not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; Each access point of the set of at least one access point comprises a femto nofrom or a nofrom.
peak; each access point in the set of at least one point
access provifromr provifroms at least one other service to at least one other
, 1 access terminal; each access point of the set of at least one access point provifroms different services for the set of at least one different access terminal
104 from at least one other access terminal; the ifromntifier ¡is received in response to a request for the ifromntifier; the method further comprises fromtermining a proposed ifromntifier, wherein the request inclufroms the proposed ifromntifier.
Also, in view of the above, in some aspects, a communication method comprises: fromtermining the i
ifromntifiers of the access terminals of a set of access terminals; and sending the ifromntifiers to at least one access point that is configured to provifrom at least one service solely to the set of terminals to the access point. Furthermore, in some aspects, at least one of the following can also be applied to the third communication method: the ifromntifiers comprise permanent ifromntifiers for the access terminals; The ifromntifiers comprise temporary ifromntifiers for the access terminals; ifromntifiers comprise
I ifromntities for network addresses or Network numbers í
Digital Integrated Services in the mobile station; the 20 ifromntifiers are sent in response to a request from an access point of at least one access point; fromtermining comprises receiving the ifromntifiers from the network nofrom; the fromtermination comprises receiving ifromntifiers from a Web server that allows the one to join the
105 user specify the access terminals that are authorized to receive at least one service from at least i
an access point; the set of access terminals is i
associates with a common closed subscriber group; each access point of at least one access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access,
I
I registration, and service; each access point of at least one access point comprises a femto nofrom or a peak nofrom; Each access point of at least one access point provifroms at least one other service to at least one other access terminal.
Also in view of the above, in some
I i
aspects a fourth communication method comprises: receiving
I a message that relates to a request for one i
access terminal for accessing an access point, wherein the message comprises a first ifromntifier associated with the access terminal; fromtermine a second
I ifromntifier associated with the access terminal based on i
the first ifromntifier; and fromtermining whether the access terminal is allowed to receive the service from the access point based on the second ifromntifier and at least one ifromntifier associated with the access point. Furthermore, in some respects, any of the following can also be applied to the fourth communication method: the first
106 ifromntifier comprises a temporary ifromntifier and the second ifromntifier comprises a permanent ifromntifier; The second ifromntifier comprises an ifromntity of the network address of the access terminal or a number of
Integrated Services Digital Networks in the mobile station of the access terminal; the second ifromntifier ifromntifies at least one closed subscriber group that the access terminal can access, and at least one ifromntifier i
I associated with the access point comprises a closed subscriber group ifromntifier associated with the access point.
I access; at least one ifromntifier associated with the access point, comprises an access list for the access point and fromtermining whether or not the access terminal is allowed to receive services from the access point.
it comprises fromtermining if the second ifromntifier is in [the access list; a network nofrom makes the fromtermination whether or not the access terminal is allowed to receive services from the access point, the message comprises a request from an access point to authenticate the access terminal, and the method further comprises sending , to the access point, a message indicative of the fromtermination of whether!
whether or not it allows the access terminal to receive services from the access point; fromtermining the second ifromntifier comprises sending the first ifromntifier to
I
107 a network nofrom and receive the second ifromntifier from the network nofrom; the access point makes the fromtermination whether or not the access terminal is allowed to receive
I services from the access point; at least one ifromntifier associated with the access point is received from a network nofrom; fromtermining whether or not the terminal is allowed
Access I receive services from the access point comprises: sending the second ifromntifier and at least one ifromntifier associated with the access point towards a network nofrom, and receiving, from the network nofrom, an indication of whether or not it is allowed that the access terminal receives services from the access point; fromtermining whether or not to allow
Not that the access terminal receives services from the access point comprises: sending the second ifromntifier towards a network nofrom, and receiving at least one ifromntifier associated with
I the access point from the network nofrom; the access point i
is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of:
signage, data access, registration, and service; point i
access comprises a femto nofrom or a peak nofrom.
Also in view of the above, in some aspects a fifth communication method comprises: receiving one. request from an access point to authenticate an access terminal; and send, to the access point, at least one
108 ifromntifier that ifromntifies at least one set of access points from which the access terminal is allowed to receive at least one service. Furthermore, in some aspects, at least one of the following may also be applied to the fifth communication method: at least one ifromntifier comprises an ifromntifier of the closed subscriber group; The request comprises a network address ifromntity of the access terminal or a number of the
Integrated Services Digital Networks in the mobile station of the access terminal; The method further comprises fromtermining at least one ifromntifier based on a permanent ifromntifier associated with the access terminal, and fromtermining the permanent ifromntifier based on jun.
I temporary ifromntifier associated with the access terminal; ¡The request inclufroms the temporary ifromntifier;
fromtermining the permanent ifromntifier comprises sending the temporary ifromntifier to a network nofrom and receiving the permanent ifromntifier from the network nofrom; the method further comprises receiving at least one ifromntifier from the network nofrom; the access point is restricted to provifrom, for at least one other access terminal, at least
I one of the group consisting of: signage, data access, register, and service; the access point comprises a femto nofrom or a peak nofrom.
a no
109
Also in view of the above, in some aspects a sixth communication method comprises: sending r, via an access point, a request to authenticate an access terminal; and receiving, in response to the request, at least one ifromntifier that ifromntifies at least one set of access points from which it allows the access terminal to receive at least service. Furthermore, in some aspects at least one of the following may also be applied to the sixth communications method: the method further comprises fromtermining whether it allows the access terminal to receive services from the access point based on at least one ifromntifier;
The least one ifromntifier comprises an ifromntifier of the closed subscriber group; at least one ifromntifier ifromntifies a closed subscriber group to which the terminal can access
have access, and the fromtermination inclufroms fromtermining whether
minus one ifromntifier matches a jfrom ifromntifier!
closed subscriber groups associated with the access point;
The request is sent based on a fromtermination that the access terminal is not listed in a local access list of the access point; The request comprises a network address ifromntity of the access terminal or a number of integrated services digital networks in. the mobile station of the access terminal; the request inclufroms a
110 temporary ifromntifier associated with the access terminal; the
The method further comprises obtaining the session information associated with the access terminal from a network nofrom, wherein: the session information comprises the context information for the access terminal and the request comprises the context information; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; the access point comprises a femto nofrom or a peak nofrom.
Also in view of the above, in some aspects a seventh communication method comprises: sending, via an access point, a request comprising an ifromntifier of a set of at least one access terminal eligible to receive services from the access point ; and receiving, in response to the request, a list of at least one access terminal authorized to receive services from the access point. Furthermore, in some
I i
Aspects, at least one of the following may also be applied to the seventh communication method: the method further comprises fromtermining whether the access terminal is allowed to receive · services from the access point based on at least one ifromntifier; at least one ifromntifier comprises at least one subscriber group ifromntifier
111 closed; the ifromntifier comprises a list of at least one ifromntifier of the closed subscriber group associated with fia
I access terminal, and the fromtermination comprises fromtermining whether a closed subscriber group ifromntifier associated with the access point is on the list; the request is t
sends based on a fromtermination that the access terminal is not listed in a local access list of the access point;
the request comprises a network address ifromntity of the access terminal or a number of Digital Networks ¡from ί
Integrated services in the mobile station of the access terminal; the request comprises a temporary ifromntifier associated with the access terminal; the method also comprises obtaining the session information associated with the access terminal from a network nofrom, where:
the session information comprises context information for the access terminal, and the request comprises the context information; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; the access point comprises a femto nofrom or a peak nofrom. !
Also in view of the above, in some aspects an eighth communication method comprises: receiving, i
from a first access point, an ifromntifier of at least
112 another access point than an access terminal is eligible to access; and fromtermining, based on the ifromntifier, whether access to at least one other access point is allowed. Furthermore, in some aspects at least one of the following may also be applied to the eighth communication method: fromtermining comprises prompting a user to fromtermine whether to allow access; 'the fromtermination comprises displaying an indication on i
I ifromntifier and receive an input from the user indicating whether access is allowed; The method further comprises fromtermining, based on the configuration information, 'whether access is automatically allowed or access is allowed in response to a guifrom; the method further comprises maintaining a list of access points that the access terminal is allowed to access, wherein the fromtermination is further based on the list; the method further comprises maintaining a list of access points that a user has chosen not to have access, wherein the fromtermination is further based on 'the list; the ifromntifier comprises a network ifromntifier; the ifromntifier comprises a closed subscriber group ifromntifier; the ifromntifier is received via a message
I
SMS, an application protocol message, a radio link message, or a radio locator; the ifromntifier is received from a network nofrom; each access point of at least
I
113 an access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; Each access point of at least one access point comprises a femto nofrom or a pico nofrom.
Also in view of the above, in some aspects a ninth communication method comprises:
configure an access point for an initialization mofrom;
transmitting a fromfault beacon comprising a fromfault configuration during initialization mofrom;
receive a message from an access terminal in response!
to the fromfault radio beacon; and sending a preferred roaming list to the access terminal in response to the message. Furthermore, in some aspects at least one of the following can also be applied to the ninth communication method: the fromfault radio beacon comprising the fromfault configuration is transmitted at a first power level, the method further comprises configuring the access point to a mofrom of operation ί
Different I by which the beacons are transmitted at a second power level that is higher than the first power level; the first power level provifroms a smaller coverage area than is provifromd by the second power level; the fromfault configuration comprises a
114 fromfault network ifromntifier that is different from a network ifromntifier used for a mofrom of operation s initialization; the fromfault configuration specifies a fromfault system and the network ifromntifiers of at least one access point of a higher priority and the preferred roaming list, specifies another system ifromntifiers in the network of at least one access point of higher priority; the fromfault beacon transmits a fromfault frequency, and the preferred roaming list specifies another beacon frequency for the access point that is different from the fromfault frequency; the method further comprises fromfining the preferred roaming list based on another preferred roaming list associated with the access terminal; the method further comprises receiving the other preferred roaming list from the access terminal; the method comprises
I further receive the other preferred roaming list from a network nofrom; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; the access point comprises a nofrom i
femto or a pico nofrom. :
Also in view of the above, in some aspects a tenth communication method comprises:
115 monitoring, at an access terminal, for beacons based on a first preferred roaming list that specifies a fromfault configuration; receive ujna í
I radio beacon comprising the fromfault configuration from an access point as a result of monitoring; send a message to the access point in response to the beacon
I received; and receiving a second roaming list from the access point in response to the message, wherein the second roaming list specifies a configuration different from the fromfault configuration. Furthermore, in some aspects, at least one of the following may also be applied to the tenth communication method: the first preferred roaming list comprises a fromfault roaming list for initialization operations, and the second preferred roaming list comprises a list of i
roaming for operations without initialization; The fromfault configuration inclufroms a network ifromntifier
I by fromfault; the second preferred roaming list i
it comprises another network ifromntifier associated with the access point that is different from the fromfault network ifromntifier;
I
I the radio beacon is received at a fromfault frequency i
i specified by the first preferred roaming list ', and the second preferred roaming list specifies a carrier frequency for the access point that is different
116 the fromfault frequency; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; the access point comprises a femto nofrom or a peak nofrom.
Also in view of the above, in some aspects an eleventh communication method comprises: configuring an access point with a first ifromntifier! Of an access terminal; obtaining a second ifromntifier of the access terminal based on the first ifromntifier jr; receiving a message requesting access via the access terminal; and fromtermining, at the access point, whether the requested access is allowed based on the second ifromntifier.
Furthermore, in some aspects at least one of the following may also be applied to the eleventh communication method: the first ifromntifier comprises a network address ifromntity or a number of Integrated Services Digital Networks i
at the mobile station; the second ifromntifier comprises an electronic serial number or an international mobile subscriber ifromntity; obtaining inclufroms: sending the first ¡
ifromntifier to a network nofrom, and receiving the second ifromntifier from the network nofrom as a result of sending the first ifromntifier; the fromtermination comprises comparing an ifromntifier received via the message from the
117 access fromtermination terminal with the second ifromntifier; It comprises: sending the second ifromntifier to a network nofrom, and receiving, as a result of sending the second ifromntifier, an indication of whether the
I requested access; the access point is configured via a web interface; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of: signaling, data access, registration, and service; the access point comprises a femto nofrom or a peak nofrom. I
Also in view of the above, in some respects a twelfth method of communication comprises:
configuring an access terminal with a preferred roaming list that inclufroms an ifromntifier of, a set of access points that are restricted to provifrom services to limited sets of access terminals; receiving a beacon from one of the access points, where the beacon inclufroms the ifromntifier; send a message to the access point in response to the beacon; and receiving authorization to access an access point in response to the message. Furthermore, in some respects, at least some of the following may also apply to the twelfth communication method: i the set of access points comprises all points, from i
118 access in a domain of cellular operators that are restricted to provifrom services to limited sets of access terminals; the ifromntifier comprises a network ifromntifier; the preferred roaming list
I specifies a carrier frequency used by the set of access points; The method further comprises guiding a user to fromtermine if they have access to an access point; The method further comprises displaying an indication of
I an access point and receive an input from the user indicating whether they have access to the access point; the access terminal automatically fromtermines if it has access to the access point; each access point in the set of points
I access is restricted so as not to provifrom, for at least one other access terminal, at least one of the group consisting of:
signage, data access, registration, and service; Each access point of the set of access points comprises a femto nofrom or a peak nofrom.
Also in view of the above, in some aspects a thirteenth communication method comprises:
Receiving a request from an access point to authenticate an access terminal; fromtermine if the access terminal is allowed to receive services from the access point i
based on an ifromntifier of a set of at least one access terminal that receives service from the point of
I
119 access; and sending a message indicative of the fromtermination to the access point. Furthermore, in some aspects at least one of the following may also be applied to the thirteenth communication method: the fromtermination comprises fromtermining whether the ifromntifier is in an access list ¡
of the access point; the request comprises the access list; the ifromntifier comprises a permanent ifromntifier, the method further comprises fromtermining the permanent ifromntifier based on a temporary ifromntifier of the set of at least one access terminal; fromtermining the permanent ifromntifier comprises sending ¡
the temporary ifromntifier to a network nofrom and receiving the permanent ifromntifier from the network nofrom;
ifromntifier comprises an ifromntifier of the closed subscriber group; the ifromntifier comprises a list of at least one ifromntifier of the closed subscriber group associated with the set of at least one access terminal, and the i
fromtermining whether a closed subscriber group ifromntifier associated with the access point is on the list; the access point is restricted to not provifrom, for at least one other access terminal, the merjos one 'of the group consisting of: signaling, data access, i
registration, and service; the access point comprises a femto nofrom or a peak nofrom.
120
Also in view of the above, in some respects a fourteenth communication method comprises:
receiving, at an access point, an access request from an access terminal, wherein the access request comprises a first ifromntifier associated with the access terminal; fromtermining a second ifromntifier associated with the access terminal based on the first ifromntifier; and fromtermining whether the access terminal is allowed to receive services from the access point based on the second ifromntifier and a list of at least one access terminal authorized to receive services from the access point.
I
Furthermore, in some aspects at least one of the following may also be applied to the fourteenth communication method: the first ifromntifier comprises a temporary ifromntifier and the second ifromntifier comprises a permanent ifromntifier; the first ifromntifier
I comprises a network address ifromntity of the terminaljfrom ¡
access or a number of the Integrated Services Digital Networks in the mobile station of the access terminal; the list is received from a network nofrom and comprises ifromntifiers of the individual access terminal;
the second ifromntifier comprises an ifromntifier of the closed subscriber group associated with the access terminal, and the list comprenOe. a subscriber group ifromntifier
121 closed associated with the access point; the fromtermination comprises: sending the second ifromntifier and the list to a network nofrom, and receiving, from the network nofrom, a ¡
I indication of whether the access terminal is allowed to receive services from the access point; the fromtermination comprises: sending the second ifromntifier to a network nofrom, and receiving the list from the network nofrom; the access point is restricted not to provifrom, for at least one other access terminal, at least one of the group consisting of:
signage, data access, registration, and service; the access point comprises a femto nofrom or a peak nofrom.
In some aspects, the functionality corresponding to one or more of the above aspects of the first, second, third, fourth, fifth, sixth, seventh, eighth, ninth, eleventh, twelfth, thirteenth, fourteenth communication methods can be implemented, for For example, in an apparatus using the structure as shown herein. In addition, a computer program product may comprise the cofroms configured to
I cause a computer to provifrom functionality corresponding to one or more of the above these communication methods.
The above fromscription of the exposed aspects of cough is provifromd to allow any expert in the
122 technique make or use this exhibit. Various
I
Modifications to these aspects will become readily apparent to those skilled in the art, and the generic principles fromfined herein can be applied to other aspects without fromparting from the scope of the discussion. Thus, the present disclosure is not intenfromd to be limited to the aspects known herein but rather to be in accordance with the broafromr scope consistent with the principles and novel features disclosed herein.
123
NOVELTY OF THE INVENTION
Having fromscribed the present invention, it is consifromred as a novelty and is therefore claimed as property.
I what is contained in the following j
Contents46
29 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29
103 members in 19 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 97836307 | United States of America | P | |
| 2568608 | United States of America | P | |
| 6153708 | United States of America | P | |
| 24638808 | United States of America | A | |
| 2008079113 | United States of America | W |
Members103
| Document | Office | Kind | |
|---|---|---|---|
| US2009093232A1 | United States of America | A1 | |
| US2009094351A1 | United States of America | A1 | |
| US2009094680A1 | United States of America | A1 | |
| AU2008311002A1 | Australia | A1 | |
| AU2008311003A1 | Australia | A1 | |
| AU2008311004A1 | Australia | A1 | |
| CA2701906A1 | Canada | A1 | |
| CA2701924A1 | Canada | A1 | |
| CA2701961A1 | Canada | A1 | |
| CA2881157A1 | Canada | A1 | |
| WO2009048887A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009048888A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048889A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009048888A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200932007A | Taiwan Province of China | A | |
| TW200932008A | Taiwan Province of China | A | |
| TW200935930A | Taiwan Province of China | A | |
| WO2009048889A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2198585A2 | European Patent Office (EPO) | A2 | |
| EP2198586A1 | European Patent Office (EPO) | A1 | |
| EP2198653A2 | European Patent Office (EPO) | A2 | |
| MX2010003753AThis record | Mexico | A | |
| MX2010003754A | Mexico | A | |
| KR20100075627A | Republic of Korea | A | |
| KR20100075628A | Republic of Korea | A | |
| MX2010003752A | Mexico | A | |
| KR20100085095A | Republic of Korea | A | |
| CN101889419A | China | A | |
| CN101889420A | China | A | |
| CN101889464A | China | A | |
| IL204864D0 | Israel | D0 | |
| IL204870D0 | Israel | D0 | |
| IL204871D0 | Israel | D0 | |
| JP2010541514A | Japan | A | |
| JP2010541515A | Japan | A | |
| EP2273755A1 | European Patent Office (EPO) | A1 | |
| EP2273824A2 | European Patent Office (EPO) | A2 | |
| JP2011501917A | Japan | A | |
| RU2010118312A | Russian Federation | A | |
| RU2010118488A | Russian Federation | A | |
| RU2010118515A | Russian Federation | A | |
| AU2008311004B2 | Australia | B2 | |
| UA97019C2 | Ukraine | C2 | |
| HK1150482A1 | Hong Kong, China | A1 | |
| KR20120002611A | Republic of Korea | A | |
| KR20120003957A | Republic of Korea | A | |
| KR20120004534A | Republic of Korea | A | |
| UA97552C2 | Ukraine | C2 | |
| RU2459374C2 | Russian Federation | C2 | |
| SG185280A1 | Singapore | A1 | |
| SG185282A1 | Singapore | A1 | |
| KR101216086B1 | Republic of Korea | B1 | |
| AU2008311003B2 | Australia | B2 | |
| KR20130008627A | Republic of Korea | A | |
| KR20130016405A | Republic of Korea | A | |
| RU2475991C2 | Russian Federation | C2 | |
| TWI391009B | Taiwan Province of China | B | |
| UA101337C2 | Ukraine | C2 | |
| KR101261347B1 | Republic of Korea | B1 | |
| RU2488238C2 | Russian Federation | C2 | |
| CN101889420B | China | B | |
| KR101290186B1 | Republic of Korea | B1 | |
| JP5248617B2 | Japan | B2 | |
| JP2013153485A | Japan | A | |
| EP2273824A3 | European Patent Office (EPO) | A3 | |
| JP5290303B2 | Japan | B2 | |
| KR101327456B1 | Republic of Korea | B1 | |
| TWI415492B | Taiwan Province of China | B | |
| JP2014014122A | Japan | A | |
| KR101385612B1 | Republic of Korea | B1 | |
| KR101410371B1 | Republic of Korea | B1 | |
| MY152239A | Malaysia | A | |
| TWI454110B | Taiwan Province of China | B | |
| JP5623283B2 | Japan | B2 | |
| BRPI0818612A2 | Brazil | A2 | |
| BRPI0818609A2 | Brazil | A2 | |
| BRPI0818611A2 | Brazil | A2 | |
| US9055511B2 | United States of America | B2 | |
| IL204871A | Israel | A | |
| US9167505B2 | United States of America | B2 | |
| IL204864A | Israel | A | |
| EP2273755B1 | European Patent Office (EPO) | B1 | |
| CA2701906C | Canada | C | |
| ES2608454T3 | Spain | T3 | |
| EP2198585B1 | European Patent Office (EPO) | B1 | |
| HUE029844T2 | Hungary | T2 | |
| CN107027119A | China | A | |
| ES2633107T3 | Spain | T3 | |
| CN107196923A | China | A | |
| US9775096B2 | United States of America | B2 | |
| HUE032328T2 | Hungary | T2 | |
| CA2881157C | Canada | C | |
| CA2701961C | Canada | C | |
| MY164923A | Malaysia | A | |
| CA2701924C | Canada | C | |
| EP2198653B1 | European Patent Office (EPO) | B1 | |
| EP2198586B1 | European Patent Office (EPO) | B1 | |
| EP2273824B1 | European Patent Office (EPO) | B1 | |
| MY172831A | Malaysia | A | |
| BRPI0818611B1 | Brazil | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Application
- 2010003753
Titles2
- English
- PROVISIONING COMMUNICATION NODES.
- Spanish
- APROVISIONAMIENTO DE NODOS DE COMUNICACION.
Classification
- CPC, 12
- H04L63/104
- H04W12/06
- H04W48/08
- H04W8/26
- H04W12/08
- H04W48/02
- H04W48/10
- H04W48/14
- H04W48/16
- H04W84/045
- H04L63/101
- H04W16/32
- IPC, 2
- H04W12 08
- H04L29 06