Inter-working function for a communication system
Abstract
Inter-Working Function (IWF) for interfacing between a Wireless Local Area Network (WLAN) and a communication system. The IWF may contain sufficient information to authenticate a user access to the WLAN, or the IWF may need to request authentication from the communication system. In one embodiment, the IWF sends an access challenge to the WLAN for a user. The IWF may then pass a response to the challenge on to the communication system for authentication. The IWF allows the WLAN to use the authentication capability of the communication system for local authentication.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
13 claims: 9 independent, 4 dependent
- 1一種與一無線區域網路(WLAN)及具有一無線裝置之一蜂巢式通信網路通信之互通功能(IWF)裝置,該IWF裝置包含:一WLAN介面,以自該無線裝置接收一認證存取請求以用於存取該WLAN,該認證存取請求由該無線裝置基於一預定認證金鑰產生;及一存取控制(AC)介面,以傳輸該認證存取請求至該蜂巢式通信網路,及以接收由該蜂巢式通信網路基於該預定認證金鑰所產生之一認證存取回應,其中其決定該IWF是否持有認證該無線裝置所需之資訊以用於存取該WLAN,其中若該IWF未持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求被傳輸至該蜂巢式通信網路,及其中若其決定該IWF已經持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求不會被傳輸至該蜂巢式通信網路。
- 2如請求項1之IWF裝置,其包含:一資料庫,其與該WLAN與該等AC介面通信以儲存對應於該無線裝置之認證資訊;及一處理器,其與該資料庫、該WLAN與該等AC介面通信。
- 3如請求項1之IWF裝置,該認證資訊包含對應於該無線裝置之至少一認證能力及認證程序指令。
- 4如請求項1之IWF裝置,該認證請求包含一認證訊息。
- 5如請求項4之IWF裝置,該認證訊息包含至少一蜂巢式認證聲音加密(CAVE)訊息及認證金鑰協議(AKA)訊息。
- 6如請求項1之IWF裝置,該IWF裝置以透過一第一傳輸埠與該WLAN通信,以及透過一第二傳輸埠與該蜂巢式通信網路通信。
- 7如請求項4之IWF裝置,其中該預定認證金鑰對應至該認證訊息。
- 8一種用於藉由一蜂巢式通信網路認證一無線裝置以用於存取一無線區域網路(WLAN),該方法包含:由該無線裝置基於一預定認證金鑰產生一認證存取請求;透過與該無線裝置及該蜂巢式通信網路通信之一互通功能(IWF)裝置中該WLAN自該無線裝置接收該認證存取請求;若該IWF未持有認證該無線裝置所需之資訊以用於存取該WLAN,由該IWF傳輸已接收之該認證存取請求至該蜂巢式通信網路,其中其決定該IWF是否持有認證該無線裝置所需之資訊以用於存取該WLAN,及其中若其決定該IWF已經持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求不會被傳輸至該蜂巢式通信網路;及若該IWF未已經持有認證該無線裝置所需之資訊以用於存取該WLAN:由該蜂巢式通信網路基於該預定認證金鑰認證該認證存取請求;及接收由該蜂巢式通信網路基於該預定認證金鑰所產生之一認證存取回應。
- 9如請求項8之網路,進一步包含:若該蜂巢式通信網路認證基於該預定認證金鑰該認證存取請求,藉由該WLAN同意無線裝置存取該WLAN。
- 10如請求項8之網路,該認證存取請求透過一第一傳輸協定接收於該IWF裝置。
- 11如請求項8之網路,該認證存取請求透過一第二傳輸協定被傳輸至該蜂巢式通信網路。
- 12一種與一無線區域網路(WLAN)通信及與一無線裝置通信之一蜂巢式通信網路通信之互通功能(IWF)裝置,該IWF裝置包含:產生構件,其用於由該無線裝置基於一預定認證金鑰產生一認證存取請求;接收構件,其用於透過與該無線裝置及該蜂巢式通信網路通信之一互通功能(IWF)裝置中該WLAN自該無線裝置接收該認證存取請求;傳輸構件,用於由該IWF傳輸已接收之該認證存取請求至該蜂巢式通信網路,其中其決定該IWF是否持有認證該無線裝置所需之資訊以用於存取該WLAN,其中若該IWF未持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求被傳輸至該蜂巢式通信網路,及其中若其決定該IWF已經持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求不會被傳輸至該蜂巢式通信網路;認證構件,其用於藉由該蜂巢式通信網路基於該預定認證金鑰認證該認證存取請求;及接收回應構件,其用於接收由該蜂巢式通信網路基於該預定認證金鑰所產生之一認證存取回應。
- 13一種用於藉由一蜂巢式通信網路認證一無線裝置以用於存取一無線區域網路(WLAN)之電腦程式產品,該電腦程式產品包含具有指令於其上之一電腦可讀取儲存媒體,該等指令包含:用於由該無線裝置基於一預定認證金鑰產生一認證存取請求之程式碼;用於透過與該無線裝置及該蜂巢式通信網路通信之一互通功能(IWF)裝置中該WLAN自該無線裝置接收該認證存取請求之程式碼;用於由該IWF傳輸已接收之該認證存取請求至該蜂巢式通信網路之程式碼,其中其決定該IWF是否持有認證該無線裝置所需之資訊以用於存取該WLAN,其中若該IWF未持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求被傳輸至該蜂巢式通信網路,及其中若其決定該IWF已經持有認證該無線裝置所需之該資訊以用於存取該WLAN,該認證存取請求不會被傳輸至該蜂巢式通信網路;於藉由該蜂巢式通信網路基於該預定認證金鑰認證該認證存取請求之程式碼;及於接收由該蜂巢式通信網路基於該預定認證金鑰所產生之一認證存取回應之程式碼。
Independent claims13
71 paragraphs, as filed
Interworking function of communication system
The present invention relates to an interworking function of a communication system, and more particularly to a mechanism for mutual authentication and key exchange via an interworking function in a "Wireless Local Area Network" (WLAN).
A wireless local area network (WLAN) allows users virtually unlimited access to "Internet Protocol" (IP) services and data networks. The use of WLAN is not limited to laptops and other computer devices, but is rapidly expanding to include mobile phones, personal digital assistants (PDAs), and other small wireless devices supported by an external network or carrier. For example, a wireless device communicating via a mobile communication carrier roams to a WLAN in a computerized setting or workspace. In this case, the wireless device has access to the mobile communication system, but wants to access the WLAN. WLAN access requires authentication. Since the wireless device has gained access to the mobile communication system, the need for further authentication is redundant. Therefore, there is a need for an interworking function that allows a common authentication for accessing a mobile communication system and accessing a WLAN.
The present invention relates to an interworking function (IWF) that interfaces a wireless local area network (WLAN) and a communication system. The IWF may contain sufficient information to authenticate a user to access the WLAN, or the IWF may need to request authentication from the communication system. According to an example, the IWF can send an access query to a user's WLAN. The IWF then passes a response query to the communication system for authentication. IWF allows WLAN to use the authentication capability of the communication system for local authentication.
The word "typical example" is used in this article to mean "can be used as an example, example, or legend." Any embodiment described herein as a "typical example" is not necessarily constructed to be better or more advantageous than other examples.
An HDR telephone subscriber station, in this context, refers to an access terminal (AT), which can be mobile or fixed, and can communicate with one or more HDR base stations, in this context refers to a modem pool transceiver ( MPTs). An access terminal can transmit and receive data packets to an HDR base station controller via one or more modem pool transceivers, which is referred to herein as a modem pool controller (MPC). The modem pool transceiver and the modem pool controller are called components of a network in an access network. An access network can transmit data packets among multiple access terminals. The access network is further connected to an additional network outside the access network, such as a common intranet or the Internet, and can transmit data between each access terminal and this external network Packet. An access terminal that has established an active telecommunication channel connection with one or more modem pool transceivers is called an active connection terminal, and it means that it is in a communication state. Access to the terminal during the process of establishing an active communication channel connection with one or more modem pool transceivers indicates that it is in a connection setting state. An access terminal can be any data device that can communicate via a wireless channel or via a connection channel, such as using fiber optics or coaxial cable communication. An access terminal can be any of many types of devices including but not limited to PC cards, CF memory cards, external or internal modems, or wireless or wired phones. The communication link through which the access terminal can send signals to the modem pool transceiver is called a reverse link. Sending a signal to an access terminal via a modem pool transceiver is called a forward link.
Figure 1 illustrates a wireless local area network (WLAN) 100 having one of multiple access points (APs) 106, 108, 110. An AP system can provide a star topology on the wireless side of the WLAN 100 to control a hub or bridge, and access the connection network.
Each AP 106, 108, 110, and other APs not shown, can support connection to a data service, such as the Internet, and a workstation 102, such as a laptop computer, or other digital computing device, can be connected via the air The interface communicates with an AP, so the term is wireless LAN. This AP then communicates with an authentication server (AS) or authentication center (AC). This AC is a component for devices requesting to enter a network to perform authentication services. Implementation includes "remote authentication phone dial-in user service" (RADIUS), which is one of the Internet user authentication described in RFC 2138, and the "remote authentication phone" invented by C. Rigney et al was published in April 1997 Dial-in User Service (RADIUS)", and other authentication, approval and description (AAA) service providers.
Wireless networks are emerging as an important aspect of the Internet. According to the facts: the only area of a wireless network is the strength of the radio signal. No connection to define a membership in a network. There is no substantial way to restrict a system within the radio range to be a member of a wireless network. Wireless networks that exceed any other network technology require an authentication and access control mechanism. Various groups are currently working on the development of a standard verification agency. The currently accepted standard is IEEE 802.11.
The nature of an RF-based network is that any radio within the transmitter's range allows it to intercept packets at will. Interception may occur due to the use of high-gain antennas far beyond the user's "work" range. With rapidly available tools, eavesdroppers are not limited to only collecting packets for later disassembly, but can essentially understand the interactive aggregation like an information web page viewed by an effective wireless user. An eavesdropper can also hear weak authentication exchanges, like some information websites record input. The eavesdropper can then copy and record the connection and gain access.
Once an intruder has obtained the knowledge of how to control a WLAN, he can gain access to his own network or steal the access of a valid user. If the attacker can imitate the MAC address of a valid user and use its designated IP address, it is simple to steal a user's access. The attacker can wait until the effective system stops using the network, and then take over the location within the network. This allows an attacker to directly access all devices in a network, or use the network to gain access to a wider Internet, and there will always be a valid user of the attacked network. Therefore, authentication and decryption become the most important concern in implementing a WLAN.
Authentication is a process that proves the identity of a person or is applied within a communication. This authentication allows the service provider to determine that the entity is a valid user and also determine the user requesting a particular service. Authentication and approval have a very specific meaning in essence, although these two terms are often used interchangeably, and in fact they are often not clearly distinguished.
Authentication is the process by which a user establishes a right to an identity-in essence, the right to use a name. There are many technologies that can be used to authenticate a user-passwords, biometrics, smart cards, credentials.
A name or identity has characteristics associated with it. The feature is closely affected by a name (for example, in a voucher payload) or can be stored in a name address book or other database with a key corresponding to the name. The characteristics will change over time.
Permission is a process that determines whether an identity (plus a set of characteristics associated with the identity) is allowed to perform certain actions, such as accessing a resource. Note that allowing an action to be performed does not guarantee that the action can be performed. Note that different entities can complete authentication and permission at different points.
In a mobile communication network, the authentication feature is a network capability that allows the mobile communication network to confirm the identity of the wireless device, thereby reducing unauthorized use of the mobile communication network. This procedure is transparent to phone users. When a customer makes a call, he does not need to take any action to verify the identity of his phone.
Authentication typically includes an encryption mechanism, in which service providers and users have some shared information and some private information. The shared information is typically referred to as a "shared secret".
<b>A-Key</b>
The authentication key (A-key) is a secret value that is unique to each person's mobile phone. It is temporarily stored and stored in the telephone and authentication center (AC) with the cellular service provider. This A-key is programmed in the phone by the manufacturer. It can also be entered manually by the user from within the wireless device directory function, or entered by a special terminal at the point of sale.
The wireless device and the AC must have the same A-key to generate the same calculation. The main function of A-key is to be used as a parameter to calculate shared secret data (SSD).
<b>Shared secret data (SSD)</b>
The SSD is used as an input for authentication calculation in the wireless device and the AC, and is stored in two locations. Unlike the A-key, SSD can be modified via the Internet. AC and wireless devices can share three elements for SSD calculations: 1) Electronic Serial Number (ESN); 2) Authentication Key (A-Key); and 3) One of "Shared Secret Data" Calculation (RANDSSD) RANDom number.
ESN and RANDSSD can be transmitted through the network and through the air interface. When a device accesses its first system, the SSD can be updated, and it will be updated regularly thereafter. When calculating SSD, the result is two separate values, SSD-A and SSD-B. Use SSD-A for authentication. Use SSD-B for encryption and voice secret.
Depending on the capabilities of the service system, SSDs can be shared or not shared between the AC and the Service Mobile Switching Center (MSC). If the secret information is shared, it means that the AC will send the secret information to the serving MSC, and the serving MSC must be able to perform cellular authentication and voice translation (CAVE). If the secret information is not shared, the AC will keep this information and perform authentication.
The type of sharing can affect how an authentication query is made. An authentication query is to send a message to query the identity of the wireless device. Basically, an authentication query can send some information, typically random number data, for the user to process. The user then processes this information and sends a response. Analyze this response for user verification. Use the shared secret information to process an inquiry at the serving MSC. By sharing secret information, this system can minimize the amount of communication sent and make inquiries happen more quickly at the service switch.
<b>Authentication procedure</b>
In a known system, a local location register (HLR) can control the authentication process by acting as an intermediary between the MSC and AC. Setting the serving MSC means using the mobile HLR to support authentication, and vice versa.
If it can be authenticated, the device can start the procedure by notifying the serving MSC, that is, adding a permission field in the signal message chain by setting. In response, the serving MSC can start the temporary storage/authentication process with an "authentication request".
By sending the "authentication request", the serving MSC informs the HLR/AC whether it can perform CAVE calculations. The AC can control which of the capabilities of the serving MSC and the device capabilities are used from the existing capabilities. When the serving MSC does not have the CAVE capability, it is impossible to share the SSD between the AC and the MSC and therefore all authentication procedures can be performed in the AC.
The purpose of "Authentication Request" (AUTHREQ) is to authenticate the phone and request the SSD. AUTHREQ includes two parameters for authentication, AUTHR and RAND parameters. When AC obtains AUTHREQ, it uses RAND and the last learned SSD to calculate AUTHR. If it can match the AUTHR sent in AUTHREQ, then the authentication is successful. If it can be shared, the result returned to AUTHREQ includes SSD.
<b>ask</b>
The authentication process consists of an inquiry and response dialogue. If the SSD is shared, the dialogue is carried out between the MSC and the device. If the SSD is not shared, the dialogue is between the HLR/AC and the device. The MSC system can make a unique inquiry, a global inquiry, or both depending on the switch type. Some MSCs are currently not capable of making global enquiries. The unique query is only one of the queries that occurs during the call attempt, because it uses the voice channel. The unique query presents an authentication of a separate device between the start of the call and the transmission of the call. The global inquiry is in the temporary storage, the start of the call, and one of the inquiries that occur during the transmission of the call. The global inquiry shows an authentication inquiry to all MSs using a special radio control channel. It is called a global inquiry because it is broadcast on a radio control channel, and the inquiry is used by all phones accessing the control channel.
In an inquiry, the device can respond to a random number provided by the MSC or AC. The device can use random numbers and shared secret data stored in the device to calculate a response to the MSC. MSC can also use random numbers and shared secret data to calculate the response of the slave device. These calculations can be completed by the CAVE algorithm. If the responses are not the same, the service is denied. The interrogation process did not increase the amount of time it took to connect to the phone. In fact, the call can be made under certain circumstances, and the line will be disconnected only when the authentication fails.
Wireless local area networks (WLANs) have become very popular as a device that provides users with open access to IP data networks. The third-generation (3G) wireless network is also designed to provide high-speed data access; although the supported data rate is typically lower than that of WLAN, 3G network can provide data coverage through a very wide area. Even if it is regarded as a network competitor, WLAN and 3G networks can complement each other: WLAN can provide high-capacity "high-spot" coverage in public areas such as airport reception rooms and hotel waiting rooms, and 3G networks can provide users with Although it is in progress, the data service is almost ubiquitous. Therefore, the same carrier can provide both 3G and WLAN access services according to a single user subscription. This means that the MS can use the same authentication method and secret for two types of access authentication.
According to 3G access authentication, this authentication center (AC) can authenticate MS. AC and MS have a shared secret. On the network side, the common secret is firmly stored in the AC and has not been assigned to any other network entity. On the MS side, the shared secret is firmly stored in the stable memory and is not distributed outside of it. AC and MS can use "Cellular Authentication Phonetic Encryption" (CAVE) or Authentication Key Agreement (AKA) as the authentication algorithm. The authentication parameters are transmitted between MS and AC via 3G through the air sending signal message and the network sending signal message (such as IS-41).
According to WLAN access authentication, it is expected that the same AC can authenticate the MS using the same common secret and authentication algorithm (AKA or CAVE). However, different mechanisms can be used to transmit authentication parameters within the WLAN. Specifically, the authentication parameters can be transmitted via the Extensive Authentication Protocol (EAP) and an AAA protocol (RADIUS or Diameter). The inquiry is to make the transmitter between 3G and WLAN form a network so that authentication parameters can be transmitted between the MS and AC used for WLAN access authentication.
As mentioned above in this article, the CAVE algorithm is commonly used in cellular communication and therefore, it is properly used and distributed. Alternative algorithms for authentication can also be used. It is clear that there are complex and application changes in various algorithms in data communication. To coordinate these institutions, the Extensive Authentication Agreement (EAP) has been developed into a universal agreement framework that can support multiple authentication and key distribution institutions. Published in March 1998, RFC 2284, "PPP Extensive Authentication Protocol (EAP)" written by L. Blunk et al describes EAP.
It was published as an Internet draft in February 2002 and was defined by J. Arkko et al in "EAP AKA Authentication" as one of the institutions supported by EAP is the AKA algorithm. Therefore, it needs to be expanded to include the cellular algorithm CAVE. This is expected to provide compatibility between the new system and the network backup.
<b>EAP</b>
The Extensive Authentication Protocol (EAP) is a universal protocol that can support the authentication of multiple authentication institutions. EAP does not select a specific authentication agency during the chain setting and control period, but can delay this agency until the authentication process starts. This allows the certifier to request more information before deciding on a specific certification body. This authenticator is defined as the terminal that requires authentication chain. The authenticator can specify the authentication protocol used during the chain establishment period.
<b>Interworking Function (IWF)</b>
According to one example, a new network implementation is implemented and is referred to as the Interworking Function (IWF) or more specifically, the AAA/IS-41 Interworking Function (IWF). IWF can communicate with wireless networks, such as 3G, and the transmission mechanism of authentication parameters (such as CAVE, AKA) and WLAN networks. In FIG. 2, it is illustrated that an IWF 204 is a part of a communication system 200. The system 200 includes a WLAN 202, an IWF 204, and an AC 206. As shown in the figure, a mobile station 208 is currently within the communication range of the WLAN 202. The IWF 204 can provide an interface between the AC 206 and the WLAN 202, allowing the use of a common authentication for the MS 208 to gain access to the network. Note that MS 208 is a wireless workstation, a remote control user, or other wireless device that can communicate via a network other than WLAN 202. In this case, the network is a part of its AC 206 network.
The IWF 204 is a one-way interworking function, that is, the authentication request starts from the WLAN 202. Note that according to the current example and diagram, AAA is the transmission mechanism that transmits authentication parameters between WLAN 202 and IWF 204. Moreover, IS-41 is a transport mechanism between IWF 204 and AC 206. This example makes it clear that RADIUS can be used as the AAA protocol.
Figure 3 illustrates the authentication process. Initially, the IWF 204 receives a RADIUS access-request message that contains the identity of the MS 208 (or wireless workstation) required to perform authentication to access the WLAN 202. The IWF 204 is configured with a database 210 storing authentication capabilities associated with the MS 208, and other MS 208 currently temporarily stored via the AC 206. The database 210 is designated by the identity of each MS 208. Therefore, the IWF 204 can determine the authentication capabilities of the MS 208 (for example, AKA and/or CAVE).
If the MS 208 only supports CAVE, the IWF 204 can perform the following procedures consistent with FIG. 3. The IWF can send a RADIUS access query message including an EAP request message containing a CAVE query. As discussed above, the query includes a random number used by MS 208 to calculate an authentication response. The IWF 204 can receive a RADIUS access request message containing an EAP response message (including a CAVE query response). The CAVE response includes the MS 208 authentication response, that is, the calculation result using random numbers, and other parameters specific to the MS 208.
If the IWF 204 is unable to authenticate the EAP response message, or explicitly unable to authenticate the CAVE response to the CAVE query, the IWF 204 sends an AUTHREQ message which is an IS-41 message to the AC 206. In this case, IWF 204 does not have the information necessary to confirm the response to the inquiry. The AUTHREQ message includes the IMSI assigned to the MS 208, a random number (ie, inquiry), and the authentication response generated by the MS 208. AC 206, which has knowledge of the shared secret specific to MS 208, then determines MS 208's query response. The AC 206 can reply the AUTHREQ message as an IS-41 message to the IWF. The AUTHREQ message contains the authentication result. If successful, the AUTHREQ message also contains a key called "Cellular Message Encryption Algorithm" (CMEA), which is used to protect the MS 208 communication in the WLAN 202. If the IWF 204 cannot receive the AUTHREQ message from the AC 206 after a predetermined number of retries, the IWF 204 sends a RADIUS access rejection message with EAP failure to the WLAN 202. Failure to receive an AUTHREQ message indicates a network problem between IWF 204 and AC 206.
If the IWF 204 can authenticate the query response from the MS 208, and this authentication is successful, the IWF 204 generates the CMEA key. If the MS 208 is successfully authenticated, the IWF 204 sends a RADIUS access-accept message to the WLAN 202. Such messages include an EAP-success message and CMEA key. If the MS 208 fails to authenticate, the IWF 204 sends a RADIUS access-rejection message with an EAP-failure message to the WLAN 202.
FIG. 4 illustrates an authentication procedure 400 according to an example, in which the MS 208 can support the CAVE protocol. When the MS 208 and the WLAN 202 start the authentication negotiation at step 402, the procedure starts. Also at this step, the WLAN 202 sends a RADIUS access request message containing the MS 208 identity. As shown above, the identity can be provided by IMSI or other unique identification code of MS 208. This procedure includes MS 208 seeking to access WLAN 202 and in response, WLAN 202 requests authentication from MS 208 at step 402. At this point, the IWF 204 can send a RADIUS access query to the WLAN 202, including the CAVE query at step 404. In response to this query, MS 208 can calculate a response and provide a response to WLAN 202 (not shown). The response is then sent to the IWF 204 in a RADIUS access response message in step 406. If the IWF 204 does not have the shared secret knowledge for the MS 208 at the decision step 408, the process continues to step 410 where the IWF 204 can send an AUTHREQ message to the AC 206. AUTHREQ message can request MS Identification of 208. If an AUTHREQ message is obtained at decision step 412, the processing continues to decision step 414 to determine whether the AUTHREQ message indicates successful authentication, that is, the result of the authentication is to grant access to the WLAN. If the AUTHREQ message is not received at decision step 412, the processing continues to step 416, where the IWF can send a RADIUS access denial message.
Continuing from the decision step 408, if the IWF 204 has knowledge of the shared secret information of the MS 208, the IWF 204 can determine whether the authentication at the decision step 418 is successful. Successful authentication proceeds to step 420 to calculate the CMEA key. Then, at step 424, a RADIUS access accept message is sent. Note that the successful authentication at step 414 (for authentication by AC 206) can also proceed to step 420. From the decision step 418, if the authentication is not successful, the IWF sends a RADIUS access rejection message at step 422.
In an alternative example, IWF 204 may use the AKA protocol for sending a query. As shown in FIG. 5, if the MS 208 can support AKA, the IWF 204 will execute the AKA query, and the sequence of authentication processing can be changed. According to this situation, an authentication vector (AV) can provide enough information to authenticate a user, such as MS 208. Note that the AC 206 can send the shared secret (SS) information in the AV to the IWF 204. According to this example, AV includes SS, challenge and a cryptographic key (CK). Use CK to communicate with secret MS.
If the IWF 204 does not have an authentication vector (AV) to authenticate the MS 208, the IWF 204 sends an AUTHREQ message to request the AV from the AC 206. The AUTHREQ message includes the identity of the MS 208, such as IMSI, and AV request. AC 206 answers with the AUTHREQ message containing AV. AV is composed of a random number (RAND), an expected response (XRES), a cryptographic key (CK), and an authentication mark (AUTN). The AC can provide multiple AVs in the AUTHREQ message, so the IWF does not need to request subsequent authentication from the AC 206.
If the IWF 204 cannot receive the AUTHREQ message from the AC 206 (which is after some predetermined number of retries), the IWF 204 can send a RADIUS access denial message containing an EAP-failure message to the WLAN 202, such as when in the IWF This is the case when there is a network problem between 204 and AC 206.
If the received AUTHREQ does not include AV, the IWF 204 sends a RADIUS access rejection message with an EAP-failure message to the WLAN 202. For example, this situation appears when MS 208 has an expired subscription.
If the IWF 204 has an AV, the IWF 204 sends a RADIUS access query message containing an EAP-request message with an AKA query to the WLAN 202. AKA inquiry includes AUTN and RAND. AUTN can transmit AC 206 certificate and is authenticated by MS 208. RAND is to query MS 208 used to calculate an authentication response (RES). MS 208 can provide RES to WLAN 202.
The IWF 204 can receive a RADIUS access request message containing an EAP-response including a CAVE query from the WLAN 202. The CAVE query includes the MS 208 authentication response (RES) received via the WLAN 202. IWF 204 can compare RES with XRES. Regarding a match, the MS 208 is successfully authenticated, and the IWF 204 can send a RADIUS access-accept message to the WLAN 202. This type of message includes an EAP-success message and a CK. CK is used to protect MS 208 communication in WLAN 202. If the MS 208 fails to authenticate, the IWF 204 sends a RADIUS access-rejection message including an EAP-failure message to the WLAN 202.
FIG. 6 illustrates the authentication procedure 500 using one of the AVs. If the IWF 204 has sufficient AV to identify the MS 208 at the decision step 502, the procedure continues to step 506, otherwise the process continues to step 504. In step 506, the IWF 204 may send a RADIUS access query message to the WLAN 202 of the MS 208. The query is then forwarded to the MS 208 for processing, and a response is provided back to the WLAN 202 (not shown). The IWF 204 can receive the RADIUS access request message at step 510, and determine whether the MS authentication is successful at decision step 512. For a successful authentication, the IWF 204 may send a RADIUS access accept message at step 514, otherwise the IWF 204 may send a RADIUS access reject message at step 516.
Returning to the decision step 502, if the IWF 204 does not have AV, the IWF 204 sends an AUTHREQ message to the AC 206 at step 504. During AV reception, the IWF 204 continues processing to step 506, otherwise the processing can continue to step 516.
Figure 7 illustrates that an IWF 600 is suitable for forming an interface between a WLAN (not shown), and therefore can perform communication, authentication, key exchange, and other procedures necessary for secure communication with it, and an AC (not shown) It can perform communication, authentication, key exchange, and other procedures necessary for secure communication with it. The IWF 600 includes a WLAN interface unit 602, which can prepare, transmit, receive, and/or communicate with a WLAN. Similarly, IWF 600 includes an AC interface unit 604, which can prepare, transmit, receive, and/or communicate with an AC. The IWF 600 further includes a CAVE programmer 608, an EAP programmer 610, and a RADIUS programmer 612. The IWF 600 may include any number of such programmers (not shown) required for interworking functions in a known system. All programmers, such as CAVE programmer 608, EAP programmer 610 and RADIUS programmer 612, can be executed in software, hardware, firmware, or a combination thereof. Different modules within the IWF 600 can communicate via the communication bus 614.
Skilled personnel will understand that information and signals can be represented by using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips throughout the above description can be referred to by voltage, current, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof. Of.
Those skilled in the art know better: different descriptive logic blocks, modules, circuits, and the algorithm steps related to the examples disclosed in this article can be implemented as electronic hardware, computer software, or a combination of the two. In order to clearly illustrate this interchangeability of hardware and software, different description elements, blocks, modules, circuits and steps are generally described above in terms of their functionality. Whether this functionality is executable, such as hardware or software, depends on the special application and design constraints imposed on the entire system. Skilled technicians can perform the described functionality in different ways for each special application, but such implementation final accounts are not construed as causing a departure from the scope of the present invention.
Different explanation logic blocks, modules, and circuits described in the examples disclosed in this article can all be used with a general processing unit, a digital signal processing unit (DSP), a dedicated integrated circuit (ASIC), and a programmable gate FPGA or other programmable logic devices, separate gate or transistor logic, separate hardware components, or implement or execute any combination of functions designed to perform the functions described in this article. A general-purpose processing unit can be a micro-processing unit, but in another alternative, the processing unit can be any conventional processing unit, controller, microcontroller, or state machine. A processing unit can also be implemented as a combination of computing devices, such as a combination of a DSP and a micro processing unit, multiple micro processing units, one or more micro processing units connected to the same DSP magnetic coil, or any other such configuration.
The steps of a method or algorithm described in the examples disclosed herein can be directly included in the hardware, in a software module executed by the processing unit, or in a combination of the two. A software module exists in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, scratchpad, hard disc, a removable disc, a CD-ROM, or those well known in the art Any other form of storage media. A typical storage medium is coupled to the processing unit so that the processing unit can read information from the storage medium and write information to the storage medium. Or, the storage medium is necessary for the processing unit. The processing unit and storage medium are located in the ASIC. The ASIC exists in a user terminal. Alternatively, the processing unit and the storage medium are separate components that exist in a user terminal.
The foregoing descriptions of the disclosed examples are provided to enable those skilled in the art to complete or use the present invention. Different modifications of these examples are obvious to those skilled in the art, and the general principles defined in this text can be applied to other examples without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to limit the examples shown in this article, but it conforms to the widest scope consistent with the principles and features disclosed in this article.
<p>100,202. . . Wireless local area network</p><p>102. . . workstation</p><p>106,108,111,208. . . Access point</p><p>204. . . Interworking function</p><p>602. . . WLAN interface</p><p>604. . . AC interface</p><p>606. . . Central processing unit</p><p>608. . . CAVE program</p><p>610. . . EAP procedure</p><p>612. . . RADIUS program</p>
Figure 1 includes a wireless local area network (WLAN) communication system.
Figure 2 is a communication system with an interworking function (IWF) device.
Figure 3 is a sequence diagram of an authentication procedure in a communication system.
Figure 4 is a flow chart of the authentication process.
Figure 5 is a sequence diagram of an authentication procedure in a communication system.
Figure 6 is a flow chart of an authentication procedure at an IWF in a communication system.
Figure 7 is a flow chart of the authentication process at a mobile station.
33 members in 14 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10176562 | United States of America | – | |
| 17656202 | United States of America | A | |
| 17656202 | United States of America | A | |
| 20020176562 | – | – | – |
| US20020176562 | – | – | – |
Members33
| Document | Office | Kind | |
|---|---|---|---|
| US2003236982A1 | United States of America | A1 | |
| WO2004002073A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003243676A1 | Australia | A1 | |
| TW200405734A | Taiwan Province of China | A | |
| WO2004002073A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1514384A2 | European Patent Office (EPO) | A2 | |
| CN1672368A | China | A | |
| JP2005530459A | Japan | A | |
| BR0311913A | Brazil | A | |
| CN101018178A | China | A | |
| EP2144399A1 | European Patent Office (EPO) | A1 | |
| EP1514384B1 | European Patent Office (EPO) | B1 | |
| AT456237T | Austria | T | |
| ATE456237T1 | Austria | T1 | |
| DE60331064D1 | Germany | D1 | |
| ES2336665T3 | Spain | T3 | |
| KR20100085185A | Republic of Korea | A | |
| EP2257095A1 | European Patent Office (EPO) | A1 | |
| JP4624785B2 | Japan | B2 | |
| TW201123772AThis record | Taiwan Province of China | A | |
| KR101068424B1 | Republic of Korea | B1 | |
| TWI351194B | Taiwan Province of China | B | |
| CN1672368B | China | B | |
| EP2144399B1 | European Patent Office (EPO) | B1 | |
| ES2387599T3 | Spain | T3 | |
| TWI375438B | Taiwan Province of China | B | |
| CN101018178B | China | B | |
| US8630414B2 | United States of America | B2 | |
| EP2257095B1 | European Patent Office (EPO) | B1 | |
| PT2257095E | Portugal | E | |
| DK2257095T3 | Denmark | T3 | |
| ES2524294T3 | Spain | T3 | |
| BRPI0311913B1 | Brazil | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 201123772
- Publication, DOCDB
- 201123772
- Publication, EPODOC
- TW201123772
- Application
- 100103772
- Application, DOCDB
- 100103772
- Application, EPODOC
- TW20110103772
Titles4
- Chinese
- 通信系統之互通功能
- English
- INTER-WORKING FUNCTION FOR A COMMUNICATION SYSTEM
- Unlabeled
- 通信系統之互通功能
- Unlabeled
- Interworking function of communication system
Classification
- CPC, 7
- H04L12/46
- H04W12/06
- H04L63/08
- H04W92/02
- H04W12/0431
- H04L63/0892
- H04W12/08
- IPC, 6
- H04L12 28
- H04W12 00
- H04L12 66
- H04L29 06
- H04W12 06
- H04W92 02