WO2004034717A1

Verifying check-in authentication by using an access authentication token

Abstract

A simple and efficient ability to verify check-in authentication is made possible by the method and device for verifying check-in authentication before the start of the re-registration process on the basis of a check-in request made by a mobile radio terminal (5) to at least one access device (6) for an intra-domain handover in a mobile communications network. The invention is characterized in that an authentication token, which was sent by an access device (4) to a mobile radio terminal (5) and which was stored in at least one confidence table (7) of at least one access device (1, 4, 6), is received by at least one additional access device (6) during a check-in request made by a mobile radio terminal (5) and is compared to authentication tokens, which are stored in at least one confidence table (7), before the start of the check-in in order to verify check-in authentication, and the check-in is initiated only when an authentication exists.

WO2004034717A1, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

24 claims: 23 independent, 1 dependent

  1. 1
    Claims 1. 1. A method for checking the log-in authorization prior to the start of the re-registration process due to a log-on request of a mobile radio terminal (5) to at least one access device (6) for an intra-domain handover in a mobile communication network, characterized in that et an authorization mark, which has been sent by an access device (4) to a mobile radio terminal (5) and has been stored in at least one trust table (7) by at least one access device (4), at least one further access device (1, 4, 6) is received in a log-on request of a Mobilfunkendgerates (5) and compared with at least one trust table (7) stored authorization marks before the start of the booking for Einbuchungsberechtigungsprüfung and only if there is an authorization the log-on is started.
  2. 3
    Third Method according to one of the preceding claims, characterized in that the verification of the entry authorization is made before the beginning of the re-registration processes.
  3. 4
    4th Method according to one of the preceding claims, characterized in that the connection update process is used for the re-registration process.
  4. 5
    5th Method according to one of the preceding claims, characterized in that the authentication and authorization process is used for the re-registration process.
  5. 6
    6th Method according to one of the preceding claims, characterized in that for the re-registration process the authentication and authorization process and the connection update process are used simultaneously.
  6. 7
    7th Method according to one of the preceding claims, characterized in that an access device (4) is an access router
  7. 8
    8th. Method according to one of the preceding claims, characterized in that after successful verification of the authorization of the access device (6) the renewal of the connection process is started.
  8. 9
    9th Method according to one of the preceding claims, characterized in that after successful verification of the authorization of the access device (6) the renewal of the authorization and authentication process is started.
  9. 10
    10th Method according to one of the preceding claims, characterized in that the authorization mark is sent with the message for renewing the connection between access device (6) and mobile radio terminal (5),
  10. 11
    11th Method according to one of the preceding claims, characterized in that an access device (4) sends the authorization mark received by a mobile radio terminal (5) to a neighboring access device (1, 6). ± 1
  11. 12
    12th Method according to one of the preceding claims, characterized in that an access device (4) sends the authorization mark received by a mobile radio terminal (5) to a neighboring access device (1, 6) which is stored in a trusted list.
  12. 13
    13th Method according to one of the preceding claims, characterized in that an access device (4) stores authorization marks received from neighboring access devices (1, 6) in at least one trust table (7).
  13. 14
    14th Method according to one of the preceding claims, characterized in that used authorization marks are stored in a dedicated trust table.
  14. 15
    15th Method according to one of the preceding claims, characterized in that a Mobilfunkendgerat (5) in an intra-domain handover the entitlement mark to another access device (6) sends.
  15. 16
    16th Method according to one of the preceding claims, characterized in that a further access device (6) checks the authorization mark after the validity period of the authorization mark.
  16. 17
    17th Method according to one of the preceding claims, characterized in that a further access device (6) checks the authorization mark after the creation of the authorization mark.
  17. 18
    18th Method according to one of the preceding claims, characterized in that an addition of the authorization mark representing a key is compared with a calculated key of the access device (6).
  18. 19
    19th Method according to one of the preceding claims, characterized geke nzeichnet that an authorization mark contains the identity of the Mobilfunkendgerat (5).
  19. 20
    20th Method according to one of the preceding claims, characterized in that an authorization mark contains the identity of the creating access device (4).
  20. 21
    21st Method according to one of the preceding claims, characterized in that an authorization mark contains the creation time.
  21. 22
    22nd Method according to one of the preceding claims, characterized gekennzeic net, that an authorization mark contains a random number.
  22. 23
    23rd Method according to one of the preceding claims, characterized in that an authorization mark contains an addition representing a key.
  23. 24
    24th Device for checking the access authorization when starting authentication and authorization processes due to a log-on request of a mobile radio terminal (5) to at least one access device (4) for an intra-domain handover in a mobile communication network, a receiving unit (10) for receiving an authorization mark and a request for authorization for access of a mobile radio terminal, with a processing unit (11) for creating authorization marks and checking for received authorization marks, with at least one trust table (7) for storing created and at least one access device (6) received authorization marks and with a transmitting unit (12) for sending created authorization marks to a Mobilfunkendgerat (5) and at least one further access device (6) and for forwarding the access authorization to other network units.
Independent claims23