Broker-based interworking using hierarchical certificates.
Abstract
A method for Authentication Authorization and Accounting (AAA) in an interworking between at least two networks (210 and 220). The at least two networks are capable of communicating with a broker (230) and include a first network and a second network (220) to user certificate from a user device corresponding to user of the first network (210). The first network to user certificate is signed by at a first network private key and includes a broker (230) to first network certificate and a user public key. The broker (230) to first network certificate is signed by a broker (230) private key and includes a first network (210) public key. A session key is sent from the second network (220) to the user device when the broker (230) to first network (210) certificate and the first network (210) to user certificate are determined to be authentic by the second network (220) based upon the broker (230) public key and the first network (210) public key, respectively. The session key is encrypted with the user public key. The session key is for permitting the user device to access the second network.
Term
Term ended
Expired 27 May 2023, 3.3 years ago.
- Priority
- Filed
- Expired
- Today
17 claims: 6 independent, 11 dependent
- 1REIVINDICACIONES 1. En una LAN inalámbrica (WLAN) que tiene una función de interfuncionamiento, un método para el interfuncionamiento entre la 5 WLAN y una segunda red, la WLAN y la segunda red tienen la capacidad de comunicarse con una entidad intermediaria, el método está caracterizado porque comprende los pasos de:recibir desde el intermediario una primera clave;recibir desde el dispositivo del usuario, una segunda red para 10 el certificado del usuario que incluye un Intermediario para el certificado de segunda red y una segunda clave;autenticar al Intermediario con el certificado de la segunda red con el uso de la primera clave para derivar una tercera clave;autenticar la segunda red con el certificado del usuario con el 15 uso de la tercera clave para derivar la segunda clave: generar una clave de sesión, encriptar la clave de sesión con el uso de la segunda clave y transmitir la clave de sesión encriptada al dispositivo del usuario;y comunicarse con el dispositivo del usuario con la clave de 20 sesión.
- 2El método de conformidad con la reivindicación 1, caracterizado porque la segunda red para el certificado del usuario también incluye un nivel de suscripción del usuario, el cual indica si el usuario está suscrito para un servicio de interfuncionamiento, y el paso de generación se lleva a cabo en respuesta al nivel de suscripción.
- 3El método de conformidad con la reivindicación 1, caracterizado porque la segunda red para el certificado del usuario 5 también incluye una fecha de expiración de la segunda red para el certificado del usuario, y el método también comprende el paso de revisar la fecha de expiración para determinar si la segunda red para el certificado del usuario ha expirado.
- 4El método de conformidad con la reivindicación 1, 10 caracterizado porque además incluye el paso de generar una WLAN para el certificado del usuario que está firmada con una quinta clave e incluye la clave de sesión, por lo cual el dispositivo del usuario tiene la comprende de autenticar la WLAN.
- 5En una LAN inalámbrica (WLAN) que tiene una función de 15 interfuncionamiento, un método para el interfuncionamiento entre la WLAN y una segunda red, la WLAN y la segunda red tienen la capacidad de comunicarse con una entidad intermediaria, el método está caracterizado porque comprende los pasos de:recibir desde el intermediario una clave pública del 20 intermediario;recibir desde el dispositivo del usuario, una segunda red para el certificado del usuario, que está firmada con una clave privada de la segunda red e incluye un intermediario para el certificado de segunda red y una clave pública del usuario, el intermediario para el certificado de segunda red está firmado con una clave privada del intermediario e incluye una clave pública de segunda red;autenticar al intermediario con el certificado de la segunda red con el uso de la primera clave del intermediario y derivar la clave 5 pública de segunda red;autenticar la segunda red con el certificado del usuario con el uso de la clave pública de la segunda red y derivar la clave pública del usuario: generar una clave de sesión, encriptar la clave de sesión con el 10 uso de la clave pública del usuario y transmitir la clave de sesión encriptada al dispositivo del usuario;y comunicarse con el dispositivo del usuario con la clave de sesión.
- 6El método de conformidad con la reivindicación 5, 15 caracterizado porque la segunda red para el certificado del usuario también incluye un nivel de suscripción del usuario, el cual indica si el usuario está suscrito para un servicio de interfuncionamiento, y el paso de generación se lleva a cabo en respuesta al nivel de suscripción. 20
- 7El método de conformidad con la reivindicación 5, caracterizado porque la segunda red para el certificado del usuario también incluye una fecha de expiración de la segunda red para el certificado del usuario, y el método también comprende el paso de revisar la fecha de expiración para determinar si la segunda red para 25 el certificado del usuario ha expirado.
- 8El método de conformidad con la reivindicación 5, caracterizado porque además incluye el paso de proporcionar al dispositivo del usuario la capacidad de autenticar la WLAN.
- 9El método de conformidad con la reivindicación 8, 5 caracterizado porque el paso de proporcionar comprende los pasos de:recibir un intermediarlo para el certificado WLAN firmado con la clave privada del intermediario e incluye la clave privada de la WLAN;
- 1010 generar una WLAN para el certificado del usuario que está firmada con la clave privada de la WLAN e incluye la clave de sesión de encriptado; y transmitir la WLAN para el certificado del usuario para el dispositivo del usuario. 15 10. Un método para comunicarse con una LAN inalámbrica (WLAN) con el uso de un dispositivo del usuario que tiene una suscripción a una segunda red, la segunda red tiene un contrato de interfuncionamiento con la WLAN, la WLAN y la segunda red tienen la capacidad de comunicarse con una entidad intermediaria, el 20 método está caracterizado porque comprende los pasos de:recibir, desde la segunda red, una segunda red para el certificado del dispositivo del usuario, que está formado con una clave privada de la segunda red e incluye un intermediario para el certificado de red y una clave pública del usuario;transmitir a la WLAN la segunda red para el certificado del dispositivo del usuario, en donde la WLAN tiene la capacidad de derivar una clave pública del usuario con el uso de la clave pública del intermediario recibida desde la entidad intermedia;5 recibir, desde la WLAN, una clave de sesión encriptada con el uso de la clave pública del usuario;descifrar la clave de sesión con la clave privada;y comunicar con la WLAN con el uso de la clave de sesión.
- 11El método de conformidad con la reivindicación 10, 10 caracterizado porque la segunda red para el certificado del usuario incluye también un nivel de suscripción del usuario que indica si el usuario está suscrito para un servicio de interfuncionamiento.
- 12El método de conformidad con la reivindicación 10, caracterizado porque la segunda red para el certificado del usuario 15 también incluye una fecha de expiración de la segunda red para el certificado del usuario, y el paso de transmisión se lleva a cabo cuando la fecha de expiración no se ha cumplido.
- 13El método de conformidad con la reivindicación 10. caracterizado porque el paso de recibir comprende recibir una LWAN 20 para un certificado del usuario firmado con la clave privada de intermediario e incluye la clave de sesión, y también comprende los pasos de recibir desde la segunda red, la clave pública del intermediario y autenticar la WLAN al certificado del usuario con el uso de la clave pública del intermediario y derivar la clave de sesión.
- 14Un sistema con base de b}intermediario para autenticar a los usuarios en redes que tienen relaciones de interfuncionamiento, caracterizado porque comprende:una LAN (WLAN) inalámbrica que tiene una función de 5 interfuncionamiento;una segunda red;y una entidad intermediaria que tiene la capacidad de comunicarse con la WLAN y la segunda red, el intermediario tiene un medio para transmitir una clave pública del intermediario a la WLAN, 10 y un medio para transmitir un intermediario para un certificado de segunda red, el cual está firmado con una clave privada del intermediario e incluye una clave pública de la segunda red para la segunda red;la segunda red incluye un medio para transmitir al dispositivo
- 1515 del usuario, una segunda red para el certificado del usuario firmado con una clave privada de segunda red e incluye un intermediario para el certificado de segunda red y la clave pública del usuario;la WLAN Incluye un medio para autenticar al Intermediario con un certificado de segunda red y derivar la clave pública de la
- 1620 segunda red, un medio para autenticar la segunda red para el certificado del usuario y derivar la clave pública del usuario y un medio para generar una clave de sesión y encriptar la clave de sesión con la clave pública del usuario. 15. El método de conformidad con la reivindicación 14,
- 1725 caracterizado porque la WLAN también incluye un medio para transmitir una WLAN a un certificado del usuario firmado con una clave privada de WLAN e incluye la clave de sesión encriptada.
Independent claims17
76 paragraphs in 8 sections, as filed
(54) Title: INTERMEDIATE INTERFUNCTIONING WITH THE USE OF HIERARCHICAL CERTIFICATES.
(54) Title: BROKER-BASED INTERWORKING USING HIERARCHICAL CERTIFICATES.
(57) Summary
A method for Authentication, Authorization and Account (AAA) in an interworking between at least two networks (210, 220). The at least two networks have the ability to communicate with a broker (230) and include a first network and a second network (220) for the user's certificate from a user device corresponding to the user of the first network (210). The first network for the user's certificate is signed by a private key from the first network and a public key by the user. The broker (230) for the first network certificate is signed by a private key from the broker (230) and includes a public key from the first network (210). A session key is sent from the second network (220) to the user device when the broker (230) for the certificate of the first network (210) and the first network (210) for the certificate of the first network (210) and the first network (210) for the user's certificate are determined to be authentic by the second network (220) based on the broker's public key (230) and the public key of the first network (210), respectively. The session key is encrypted with the user's public key. The session key is to allow the user's device to access the second network.
(57) Abstract
A method for Authentication Authorization and Accounting (AAA) in an interworking between at least two networks (210 and 220). The at least two networks are capable of communicating with a broker (230) and inelude a first network and a second network (220) to user certify from a user device corresponding to user of the first network (210). The first network to user certify yourself signed by at a first network private key and neludes a broker (230) to first network certify yourself and a user public key. The broker (230) to first network certify s signed by a broker (230) private key and neludes a first network (210) public key. A session key is sent from the second network (220) to the user device when the broker (230) to first network (210) certify and the first network (210) to user certify are determined to be authentic by the second network (220 ) based upon the broker (230) public key and the first network (210) public key, respectively. The session key is encrypted with the user public key. The session key¡s for permitting the user device to access the second network.
<img file="MXPA04012157A_D0001.tif" />
<img file="MXPA04012157A_D0002.tif" />
(12) INTERNATIONAL APPLICATION PUBLISHED UNDER THE PATENT COOPERAT1ON TREATY (PCT) (19) World Intellectual Property Organization International Bureau (43) International Publication Date
December 2003 (12/18/2003)
<img file="MXPA04012157A_D0003.tif" />
IIIIIMIIIH
PCT (10) International Publication Number
WO 03/105049 Al
WO 03/105049 Al lllllllllllllllllllllllllllillffl «lllllllIHIHIIIIIIIIIN (51) International Patent Classification<sup>7</sup>: G06F 17/60,
H04L 9/00 (21) International Application Number: PCT / US03 / 16546 (22) International Filing Date: May 27, 2003 (May 27, 2003) (25) Filing Language: English (26) Publication Language: English (30) Priority Data :
60 / 386,603 6 June 2002 (06.06.2002) US (71) Applicant (for all designated States except US) ·. THOMSON LICENSING SA [FR / FR]; 46, Quai A. Le Gallo, F-92648 Boulogne (FR).
(72) Inventor; and (75) Inventor / Applicant (for US only): ZHANG, Junbiao [CN / US]; 1003 Snnny Slope Road, Bridgewater, NJ 08807 (US).
(74) Agents: TRIPOLI, Joseph, S et al .; c / o Thomson Licensing, Inc., Two Independence Way, Princeton, NJ 08540 (US).
(81) Designated States (national): AE, AG, AL, AM, AT, AU, AZ, BA, BB, BG, BR, BY, BZ, CA, CH, CN, CO, CR, CU, CZ, DE , DK, DM, DZ, EC, EE, ES, FI, GB, GD, GE, GH, GM, HR, HU, ID, IL, IN, IS, JP, KE, KG, KP, KR, KZ, LC , LK, LR, LS, LT, LU, LV, MA, MD, MG, MK, MN, MW, MX, MZ, NI, NO, NZ, OM, PH, PL, PT, RO, RU, SC, SD , SE, SG, SK, SL, TJ, TM, TN, TR, TT, TZ, UA, UG, US, UZ, VC, VN, YU, ZA, ZM, ZW.
(84) Designated States (regional): ARIPO patent (GH, GM, KE, LS, MW, MZ, SD, SL, SZ, TZ, UG, ZM, ZW), Eurasian patent (AM, AZ, BY, KG, KZ, MD, RU, TJ, TM), European patent (AT, BE, BG, CH, CY, CZ, DE, DK, EE, ES, FI, FR, GB, GR, HU, ΙΕ, ΓΓ, LU, MC, NL, PT, RO, SE, SI, SK, TR), OAPI patent (BF, BJ, CF, CG, Cl, CM, GA, GN, GQ, GW, ML, MR, NE, SN, TD, TG).
Published:
- with. International search report [Continued on next page] (54) Title: BROKER-BASED INTERWORKING USING HIERARCHICAL CERTIFICALES
<img file="MXPA04012157A_D0004.tif" />
(57) Abstract: A method for Authentication Authorization and Accounting (AAA) in an interworking between at least two networks (210 and 220). The at least two networks are capable of communicating with a broker (230) and inelude a fírst network and a second network (220) to user certify from a user device corresponding to user of the fírst network (210). The fírst network to user certify yourself is signed by at a fírst network private key and ineludes a broker (230) to fírst network certify yourself and a user public key. The broker (230) to fírst network certify is signed by a broker (230) private key and ineludes a fírst network (210) public key. A session key is sent from the second network (220) to the user device when the broker (230) to fírst network (210) certify and the fírst network (210) to user certificate are determined to be authentic by the second network (220 ) based upon the broker (230) public key and the fírst network (210) public key, respectively. The session key is enciypted with the user public key. The session key is for permitting the user device to access the second network.
INTERMEDIATE INTERMEDIATE BASE WITH
THE USE OF HIERARCHICAL CERTIFICATES
FIELD OF THE INVENTION
The present invention generally relates to networks, and more particularly to Authentication, Authorization and Account (AAA) in broker-based interworking with the use of hierarchical certificates.
BACKGROUND OF THE INVENTION
Typically, Authentication, Authorization and Account (AAA) is required to gain access and use networks such as cellular networks and wireless local area networks (WLANs). In an environment where a mobile terminal has multiple network access mechanisms, providing AAA interworking between these networks is of great importance. However, it is generally the case that one or more networks involved do not belong to the same administrative domain and do not share the same AAA schemes. Furthermore, it is difficult for the cellular operator to establish a contract relationship with each of the wireless LAN operators and vice versa. Furthermore, the mobile user who has signed up for interworking should not be aware of any third party involved in the interworking, that is, they only need to maintain a single account, that is, their own cellular account.
There are two main types of interworking between cellular networks and WLAN, firm coupling and loose coupling. In a loose coupling scenario, the WLAN and the cellular network have separate data paths, but the AAA for WLAN users is supported by the AAA functions of the cellular network. However, cellular network AAA protocols (MAP / SS7) are incompatible with Internet Protocol (IP) based protocols used by WLAN users.
To solve these problems of networks that do not belong to the same administrative domain and that do not share the same AAA schemes, special interworking gateways or functions are proposed to form a bridge between the cellular network and the AAA schemes of the WLAN. Some of these special features require the Home Location Register (HLR) cellular network to be adapted; however, this is not desirable for many reasons, particularly from the point of view of cellular operators.
Conventional broker models addressing the problem of establishing contracts between each of the WLANs and cellular network operators is that they all require the broker to deploy AAA engines that are involved in real-time user authentication, this is easily created at a single point of failure. Some of these broker models also require the mobile user to create a separate account with the Broker, this is inconvenient for the user.
Accordingly, it is desirable and highly advantageous to have an Interworking AAA scheme that solves the aforementioned problems of prior art Interworking AAA schemes.
BRIEF DESCRIPTION OF THE INVENTION
The aforementioned problems, as well as other problems related to the prior art, are solved with the present invention, with an Authentication, Authorization and Account Interworking (AAA) on the basis of intermediating it with the use of hierarchical certificates.
The present invention is particularly useful, but not limited to a loose coupling scenario in a cellular data network and WLAN interworking. When deploying an intermediary, cellular operators do not have to establish a contract relationship with each of the Wireless LAN operators for Interworking. This is a much more scalable measurement than previous measurements. Furthermore, with the use of hierarchical certificates, the intermediary does not have to maintain the information of the mobile user. Mobile users can only use their cellular account to obtain LAN access that they have contracts with their cellular operators.
In accordance with an aspect of the present invention, a method for Authentication, Authorization and Account (AAA) is provided in an interworking between at least two networks. The at least two networks have the ability to communicate with a broker and include a first network and a second network. The second network receives a public key from the broker from the broker and a first network for the user's certificate from the user's device that corresponds to the user from the first network. The first network for the user's certificate is signed by a first network private key and includes a broker for the first network certificate and a user's public key. The broker for the first network certificate is signed by a broker's private key and includes a first network public key. A session key is sent from the second network to the user's device when the broker for the first network certificate and the first network for the user's certificate are determined to be authenticated by the second network based on the broker's public key and the public key of the first network, respectively. The session key is encrypted with the user's public key. The session key is used to allow the user's device to access the second network.
These and other aspects, features and advantages of the present invention will become apparent from the following detailed description of the preferred embodiments, which should be read in conjunction with the accompanying drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied, in accordance with an illustrative embodiment of the present invention.
Figure 2 is a block diagram illustrating a communication structure in which the present invention can be applied, in accordance with an illustrative embodiment of the present invention.
Figure 3 is a flowchart illustrating a broker-based method for Authentication, Authorization and Account (AAA) of a mobile user in loose coupling interworking between access networks, in accordance with an illustrative embodiment of the present invention.
Figure 4 is a flowchart illustrating a certificate-based method for Authentication, Authorization and Account (AAA) of a mobile user in loose coupling interworking between access networks, in accordance with another illustrative embodiment of the present invention.
DETAILED DESCRIPTION OF THE INVENTION
The present invention is directed to broker-based interworking Authentication, Authorization and Account (AAA) with the use of hierarchical certificates. It should be appreciated that the present invention can be applied in any combination of access networks. However, the present invention can be applied in particular to the interworking of a cellular network and a wireless local area network (WLAN).
It should be understood that the present invention can be implemented in various forms of special purpose hardware, software, firmware, processors, or a combination thereof. Preferably, the present invention is implemented in a combination of hardware and software. Also preferably, the software is implemented as a tangible embedded application program in a program storage device. The application program can be loaded and run by a machine that comprises an appropriate architecture. Preferably, the machine is implemented on a computer platform that has hardware such as one or more central processing units (CPUs), a random access memory (RAM), and an input / output interface (l / O). The computer platform also includes an operating system and a micro-instruction code. The different processes and functions described here may be part of the micro-instruction code as part of the application program (or a combination thereof), which is executed by the operating system. Furthermore, various peripheral devices can be connected to the computer platform such as an additional data storage device and a printing device.
It should also be understood that due to the components that make up the system and the steps illustrated in the accompanying Figures, preferably implemented in the software, the actual connections between the components of the system (or the steps of the process) may differ depending on how the present invention is programmed. Given these teachings, those skilled in the art will have the ability to contemplate these and other similar implementations or configurations of the present invention.
FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied, in accordance with an illustrative embodiment of the present invention. The computer system 100 can be implemented for example in a mobile device used for access to a wireless LAN or a cellular network or an access point to implement a wireless LAN, by including the necessary communication interface elements and the elements processing as known in the art. In the case of a mobile user device, the computer system 100 may include, for example, the radio interfaces necessary to communicate with the required radio access networks, as well as the processing elements to encode and decode the compliance messages. with the applicable standards. The computer processing system 100 includes at least one processor (CPU) 102 operatively coupled with other components through a busbar 104 of the system. A read-only memory (ROM) 106, a random access memory (RAM) 108, a deployment adapter 110, an I / O adapter 112, a user interface adapter 114, a sound adapter 199, and an adapter 198, are operatively coupled with the busbar 104 of the system.
A deployment device 116 is operatively coupled to the system busbar 104 by the deployment adapter 110. A disk storage device (eg, an optical or magnetic disk storage device) 118 is operatively coupled to the busbar
104 the system using the 112 l / O adapter.
A mouse 120 and a keyboard 122 are operatively coupled to the system busbar 104 via the user interface adapter 114. Mouse 120 and keyboard 122 are used to input and output information to and from system 100.
At least one horn (hereinafter "horn") 197 is operatively coupled to the system busbar 104 by the sound adapter 199.
A modem 196 (digital and / or analog) is operatively coupled to the busbar 104 of the system by the network adapter 198.
The present invention provides a scheme for AAA where an intermediary is employed. The broker serves as a certificate authority rather than a real-time authentication engine. In this way, the broker is no longer the only point of failure. The Intermediary issues certificates for the wireless networks, which in turn issue their own certificates to the individual mobile users subscribed to the interworking service.
Figure 2 is a block diagram illustrating a communication structure in which the present invention can be applied, in accordance with an illustrative embodiment of the present invention. In the illustrative embodiment of Figure 2, the communication structure includes a cellular network 210, a wireless local area network (WLAN) 220, an intermediary 230, and a user
240 mobile. The present invention provides a certificate-based scheme for providing AAA services to WLAN users. As mentioned before, the present invention can be applied in any combination of networks, including different numbers and different types of networks.
Figure 3 is a flowchart illustrating a broker-based method for Authentication, Authorization and Account (AAA) of a mobile user in loose coupling interworking between access networks, in accordance with an illustrative embodiment of the present invention. Access networks include a cellular network and a wireless local area network (WLAN). The cellular network is associated with at least one mobile user. It should be noted that while the illustrative mode of Figure 3 (as well as the illustrative mode of Figure 4, below) is described with respect to a cellular network and a WLAN, any combination of networks, including the above and other types of networks as well as different numbers of networks (eg one cellular network and three WLANs, two cellular networks and two WLANs, and so on), can be easily employed in accordance with the present invention, as long as they remain within the spirit and scope of the invention. It should also be appreciated that in the preferred embodiments of the present invention, there may be a single cellular network with which the mobile user has contracted for its service, and a plurality of WLANs that have an interworking contract with a single cellular network. The interworking agreement can be implemented with various known communication methods between the WLAN and the cellular network.
A public key K<sub>pub</sub>_b of the broker is sent from the broker to the WLAN, the latter has an interworking contract with the cellular network (step 305). In the event that the cellular network has an interworking contract with more than one WLAN, then the broker can send the public key K<sub>pub</sub>_b to all WLANs. Preferably, but not required, the public key K<sub>pub</sub>The broker's _b is sent over a secure channel so that the WLAN can be sure that the public key
K<sub>pu</sub>b_b is certainly the broker's public key.
A broker for a cellular network certificate is issued to the cellular network by the broker (step 310). The broker for cellular network certificate includes, but is not limited to the following, a public key K<sub>pub</sub>_<sub>C</sub>n, from the cellular network, and an ID from the cellular network. The broker for the cellular network certificate is signed with a private key K<sub>pri</sub>_<sub>b</sub> of the intermediary.
After the mobile user signs with the cellular network for the interworking service with the WLAN, the cellular network for the mobile user's certificate is issued by the mobile user over the cellular network (step 315). The cellular network for the mobile user's certificate includes, but is not limited to the following: the broker for the cellular network certificate, a public key K<sub>pub</sub>_<sub>m</sub> mobile user, a subscription level of the mobile user (whether the mobile user is subscribed to the interworking service
WLAN), a cellular network expiration date for the mobile user certificate. The cellular network for the mobile user certificate is signed with a private key K<sub>pr¡ cn</sub> of the cellular network.
After the mobile user moves within the coverage area of the WLAN, the mobile user sends their certificate (i.e. the cellular network for the mobile user certificate) to the WLAN (for example, an access point (AP) ) or other WLAN entity) (step 320). The broker for the cellular network certificate is determined to be authentic by the WLAN (included in the cellular network for the mobile user certificate), using the public key K<sub>pub b </sub>from the broker (sent to the WLAN in step 305) (step 325). In case the broker for the cellular network certificate is not authentic, then the method is terminated. However, when the broker for the cellular network certificate is authentic, then the WLAN extracts the public key K<sub>cn pub</sub> from the cellular network (from the broker for the cellular network certificate included in the cellular network to the mobile user's certificate) (step 330). With the use of the public key K<sub>pu</sub>b_cn of the cellular network, it is determined by the WLAN whether the cellular network for the mobile user's certificate is authentic (step 335).
When the cellular network for the mobile user's certificate is not authentic, then the method is terminated. However, when the cellular network for the mobile user's certificate is authentic, then the WLAN extracts the public key K<sub>pub m</sub> of the mobile user from the cellular network for the certificate of the mobile user and issues the session key for the mobile user that is encrypted with the public key K<sub>pub</sub>M of the mobile user (step 340). The session key can be, but is not limited to one equivalent privacy key (WEP) per user.
The encrypted session key is decrypted by the mobile user with the use of his private key K<sub>first m</sub> (step 345). The mobile user and the WLAN communicate with the use of the session key (ie all subsequent communication between the mobile user and the WLAN is encrypted with the session key) (step 350). The mobile user is authenticated by the WLAN since only the specific mobile user has the private key K<sub>pri</sub>_<sub>m</sub> to decrypt the session key.
Figure 4 is a flowchart illustrating a certificate-based method for Authentication, Authorization and Account (AAA) of a mobile user in loose coupling interworking between access networks, in accordance with another illustrative embodiment of the present invention. Access networks Include a cellular network and a Wireless local area network (WLAN). The cellular network is associated with at least one mobile user. The method of Figure 4 allows mutual authentication between the mobile user and the WLAN, so that the mobile user can also verify that he is talking to a legitimate WLAN (to avoid eg violated messages).
A public key K<sub>pub</sub>_<sub>b</sub> From the broker and a broker for a WLAN certificate are sent from the broker to the WLAN, the latter has an interworking contract with the cellular network (step 405). The broker for the WLAN certificate includes, but is not limited to the following: a public key K<sub>pu</sub>b_w of the WLAN, and a WLAN ID. The intermediary for the certificate
WLAN is signed with a private key K<sub>pri</sub>_<sub>b</sub> of the intermediary.
In case the cellular network has an interworking contract with more than one WLAN, then the broker will send the public key K<sub>pub b</sub> to all WLANs. Preferably, but not necessarily, public key K<sub>pub</sub>_<sub>b</sub> the broker is sent over a secure channel so that the WLAN can be sure that the public key K<sub>pub b</sub> it is certainly the public key of the Intermediary.
An Intermediary for the cellular network certificate is issued over the cellular network by the Intermediary (step 410). The broker for the cellular network certificate Includes, but is not limited to the following:
a public key K<sub>pu</sub>b_<sub>C</sub>n of the cellular network; an ID of the cellular network; and a public key K<sub>pub</sub>_b of the Intermediary. The Broker for the cellular network certificate is signed with a private key K<sub>pr</sub>¡_<sub>b</sub> of the intermediary.
After the mobile user is signed with the cellular network for the WLAN service, the cellular network for the mobile user certificate is issued by the mobile user over the cellular network (step 415). The cellular network for the mobile user's certificate includes, but is not limited to the following: Intermediate for the cellular network certificate, a public key K<sub>pu</sub>b_<sub>m</sub> mobile user, a mobile user subscription level (whether the mobile user is subscribed to the WLAN interworking service), a cellular network expiration date for the mobile user certificate. The cellular network for the mobile user certificate is signed with a private key
Kpr¡_cn of the cellular network. The public key K<sub>pub b</sub> the intermediary is also sent to a mobile user (step 417).
After the mobile user moves within the coverage area of the WLAN, the mobile user sends his certificate (i.e. the cellular network for the mobile user certificate) to the WLAN (for example, an access point ( AP) or other WLAN entity) (step 420). The WLAN determines if the Broker for the cellular network certificate (Included in the cellular network for the mobile user's certificate) is authentic, using the public key K<sub>pub</sub>_<sub>b</sub> Intermediate (sent to the WLAN step 405) (step 425). When the broker for the cellular network certificate is not authentic, then the method is terminated. However, when the broker for the cellular network certificate is authentic, then the WLAN extracts the public key K<sub>pt</sub>,<sub>b</sub>_<sub>C</sub>cellular network n (from the broker for the cellular network certificate included in the cellular network for the mobile user certificate) (step 430). With the use of the public key K<sub>pub</sub>_<sub>cn</sub> From the cellular network, the WLAN determines whether the cellular network for the mobile user's certificate is authentic (step 435).
When the cellular network for the mobile user certificate is not authentic, then the method is terminated. However, when the cellular network for the mobile user certificate is authentic, the WLAN extracts the public key K<sub>pub m</sub> of the mobile user and issues a session key to the mobile user that is encrypted with public key K<sub>P</sub>ub_m of the mobile user and is signed by a private key K<sub>pri w</sub> of the
WLAN and also sends the mobile user the intermediary for the WLAN certificate that is signed by the private key K<sub>pr</sub>¡_B of the Intermediary (step 440). The broker for the WLAN certificate includes a public key K<sub>pub w</sub> from the WLAN. The session key can be but is not limited to one wired equivalent privacy key (WEP) per user.
The mobile user determines if the broker for the WLAN certificate is authentic, using the public key K<sub>pub b </sub>from the broker (step 442). When the broker for the WLAN certificate is not authentic, then the method is terminated.
However, when the broker for the WLAN certificate is authentic, then the public key K<sub>pub</sub>_<sub>w</sub> WLAN is obtained by the mobile user from the broker for the WLAN certificate (step 443). The mobile user determines if the session key is authentic, using the public key K<sub>pu</sub>b_w of the WLAN (step
444). When the session key is not authentic, then the method is terminated.
However, when the session key is authentic, then the encrypted session key is decrypted by the mobile user with the use of his private key K<sub>pr¡ m</sub> (step 445). The mobile user and the
WLANs communicate with the use of the session key (that is, the subsequent communication between the mobile user and the WLAN is encrypted with the session key (step 450).
Although the Illustrative embodiments have been described herein with reference to the accompanying drawings, it should be understood that the present invention is not limited to these embodiments, and that persons skilled in the art may make changes and modifications without departing from the spirit and scope of the Invention. For example, it is clear that the Invention can be applied with any combination of mobile or wireless communication networks that include but are not limited to basic IEEE 802.1 1, Hiperlan 2, etc. All of these changes and modifications are intended to be included within the scope of the invention as defined by the appended claims.
Contents8
14 members in 9 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 38660302 | United States of America | P | |
| 0316546 | United States of America | W |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO03105049A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003237252A1 | Australia | A1 | |
| BR0305019A | Brazil | A | |
| KR20050010859A | Republic of Korea | A | |
| EP1514208A1 | European Patent Office (EPO) | A1 | |
| MXPA04012157AThis record | Mexico | A | |
| CN1659558A | China | A | |
| JP2005529525A | Japan | A | |
| US2005240760A1 | United States of America | A1 | |
| CN1659558B | China | B | |
| EP1514208A4 | European Patent Office (EPO) | A4 | |
| KR101002471B1 | Republic of Korea | B1 | |
| JP4792221B2 | Japan | B2 | |
| US8468354B2 | United States of America | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Application
- 4012157
Titles2
- English
- BROKER-BASED INTERWORKING USING HIERARCHICAL CERTIFICATES.
- Spanish
- INTERFUNCIONAMIENTO CON BASE DE INTERMEDIARIO CON EL USO DE CERTIFICADOS JERARQUICOS.
Classification
- CPC, 12
- H04W12/06
- H04L9/0825
- H04L9/3263
- H04L63/062
- H04L63/0823
- H04L63/0892
- H04L2209/56
- H04L2209/80
- H04W84/12
- H04W88/06
- H04W92/02
- H04W12/0431
- IPC, 8
- H04W12 06
- G06F21 35
- H04L9 00
- H04L9 08
- H04L9 30
- H04L9 32
- H04L29 06
- H04L29 08