Arrangement for improving security in a communication system supporting user mobility
Abstract
The present invention relates to an arrangement for improving security in a communications system, especially a telecommunications system, said system comprising distributed hardware and software components which interact in order to provide services to one or more users, and for the object of implementing this improvement this can according to the present invention be done by introducing in said system a generic access control. In a specific embodiment the invention suggests three types of access control especially related to access to the terminal in question, to the telecom system and to the requested services.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
10 claims: 5 independent, 5 dependent
- 1Patent claims 1. Arrangement for improving security in a communications system, especially a telecommunications system, said system comprising disfrib- uted hardware and software components which interact in order to provide services to one or more users, characterized by introducing in said a generic access control therein for thereby enforcing security.
- 4Arrangement as claimed in any of the preceding claims, characterized in that said generic access confrol is infroduced in any mobile distribution system, offering any type of applications, i.e. voice, data, image, video, interactive, multimedia, etc.
- 5Arrangement as claimed in any of the preceding claims, characterized in that before any user is allowed to access the services offered by the related telecom system domain, the user will be subjected to several types of access controls.
- 7Arrangement as claimed in any of the preceding claims, characterized in that the information required for carrying out said generic access confrol is contained in a Usage Resfriction component of a Term Profile object containing information about the terminal in question.
- 10Arrangement as claimed in any of claims 7- 10, characterized in that in the telecom system domain there is provided one or more timers which are restarted each time and entry is accessed the setting of the timer deciding the maintenance of said entry, and that entries not associated with a timer is regarded as permanent entries.
Independent claims5
67 paragraphs in 9 sections, as filed
0001ARRANGEMENT FOR IMPROVING SECURITY IN A COMMUNICATION SYSTEM SUPPORTING USER MOBILITY
FIELD OF THE INVENTION
0003The present invention relates to an arrangement for improving security in a communications system, especially a telecommunications system, said system comprising distributed hardware and software components which interact in order to provide services to one or more users.
0004More specifically the present invention concerns a user access control for distributed systems that support user mobility, i.e. users are allowed to move and use different terminals to access services.
BACKGROUND OF THE INVENTION
0006The Access control is the procedure used by the telecom system domain to ensure that the user accesses the telecom system domain in accordance with the restrictions specified at subscription [1]. When mobility is sup- ported, every user will have the possibility to use any terminals at any access points. The access control procedure is also intended to limit the access capability of a user for the protection and privacy of third party. The third party can be the owner of the terminal or the access point, and must have the right to block or deblock, suspend or reset the service de- livery at his terminal or access point to a user.
0007When the user is allowed to move and access to the telecommunication services anywhere and at any time, the risk of threats increases dramatically at the same time as the mechanisms necessary to enforce security become more difficult to realise. In systems supporting general mobility, fraudulent use of anyone's subscription can be attempted from any terminal and at any network access point. In this way the user may be exposed to various forms of fraud as, for example, fraudulent use of the user "s resources by unauthorised parties who manage to take up the identity of the user, eavesdropping, unauthorised tapping or modification of information exchanged during communication, and disclosure of the user's physical location [4]. Another security problem arises because the user is allowed to use any terminal and at any network access point. Such a tem- porary usage may conflict with the use of the terminal by the terminal owners, also referred to as third parties [6]. In principle, third parties should not suffer in terms of loss of privacy or freedom of actions as a result of activities by the mobile user.
STATE OF THE ART
0009With mobility, users may make use of any existing and available terminals and network access points. However, this does not mean that the terminal owner (the third party) has to accept such actions on his termi- nal. He must have the rights to restrict the usage of the terminal, e.g. only allowing certain users while others are prohibited from using the terminal.
0010This may be done in many ways, e.g. by keeping the terminal in a se- cured place, use local password, etc., but such measures are cumbersome for the owner and often not secure enough. This is commonly referred as the protection of third parties. The UPT (Universal Personal Telecommunication) [4] system comprises some sort of access control mechanisms but they are limited to telephony services and to voice terminals or telephone.
0011Consequently, there is a need for an improved user access control for distributed systems supporting user mobility.
OBJECTS OF THE INVENTION
0013The present invention has for an objective to address any mobile distributed system, any types of applications, i.e. voice, data, image, video, interactive, multimedia, etc., for in such mobile distributed systems to introduce an improved access control.
0014A further object of the present invention is to introduce a generic access control in such distributed systems.
0015Still another object of the present invention is to introduce such a generic access control for distributed systems supporting user mobility which can be used in mobile distributed systems comprising public or private, local- area or wide-area, wireline or wireless networks.
BRIEF DISCLOSURE OF THE INVENTION
0017The above objects are achieved in an arrangement as stated in the preamble, which primarily is characterised by introducing in said system a user access control, for thereby enforcing security in communications systems. In other words, the invention also suggests that this type of generic access control is related to personal mobility.
0018Further features and advantages of the present invention will appear from the following description taken in conjunction with the enclosed drawings, as well as from the appending patent claims.
BRIEF DISCLOSURE OF THE DRAWINGS
0020Fig. 1 is a schematic diagram illustrating the main subject matter to which the present invention is related, namely by illustrating a user's access to the services in question.
0021Fig. 2 is a schematic diagram illustrating an embodiment of the present invention for carrying out access control, especially in relation to a information object Term_Profιle.
0022Fig. 3 is a schematic diagram illustrating an embodiment of a Termi- nal_Data object.
0023Fig. 4 illustrates a computational model of the access control of a user for use of a terminal.
0024Fig. 5 is a schematic diagram illustrating a user_registration object con- taining a list of allowed services.
0025Fig. 6 is a schematic diagram illustrating the relation between user domain, terminal domain and telecom system domain as well as an embodiment of access control on the access to the telecom system. Fig. 7 is a block diagram illustrating the relation between user domain, terminal domain and telecom system domain, as well as an embodiment of access control on the axis to the telecom system.
DETAILED DESCRIPTION OF EMBODIMENT
0027As stated previously, the present invention relates to user access control for distributed systems that support user mobility which means that the users are allowed to move and use different terminals to access services available to them.
0028In Fig. 1 there is illustrated a user which has access to a terminal which in turn is communicating with a telecom system which in turn is offering a plurality of services.
0029Before allowing the user to access the services offered by the telecom system domain, he is subject to three types of access control
0030• access control concerning the use of the current terminal (protection of third party)
0031• access control concerning the access to the telecom system
0032• access control concerning the use of the service requested
0033SOLUTION We shall successively describe the three mentioned access controls.
0034Access control for use of the current terminal
0035With mobility, users may make use of any existing and available termi- nals and network access points. However, this does not mean that the terminal owner (the third party) has to accept such actions on his terminal. He must have the rights to restrict the usage of the terminal, e.g. only allowing certain users while other are prohibited from using the terminal. Of course, there are many ways to do this locally, e.g. keep the terminal in a secure place, use local password, etc. but they are cumbersome for the owner and often not secure enough. This is commonly referred as the protection of third parties [2].
0036Let us suppose that the mobile distributed system uses agent techniques to support mobility and has the following objects:
0037PD_UA (ProviderDomain_UserAgent) representing a user in the telecom system domain.
0038TA (TerminalAgenf) representing a terminal in the telecom system do main SPA (ServiceProvider Agent) representing the telecom system in the terminal domain
0039NAP representing a Network Access Point
0040TAP representing a Terminal Access Point
0041The information required for to carrying out the access control is contained in the Usage_Restriction component of the object Term_Profιle (see Figure 2) which contains information about the terminal. The attribute All_Barring is used to specify that only the terminal owner can use the terminal. The terminal owner may also prevent a particular user or group of users from using his terminal by specifying the attribute Bar- ring_List or to allow only certain user by specifying an Allowance_List. Modification of the Usage_restriction may be provided as an application where only the owner has the right to make access. The details of such an application and the specific layout of the Usage_Resfriction is a matter of implementation and will not be carried further here.
0042In order to support selective access control of the terminal, the object Terminal_Data which contains information required for the support ter- minal mobility such as state, NAPid, etc. may be equipped with a table of controlled and cleared users, called ClearedUserTable, as shown in Figure 3. The ClearedUserTable contains the references or CIIs (Computational Interface Identifier) of the PD_UAs whose access have been controlled.
0043The TA assumes the Access control Enforcement Function (AEF). The Access control Decision Function is allocated to an object called ADF. The access control Procedure for use of the terminal is shown in Figure 4.
00441. Every time an operation OpX arrives at the TA, the TA will check whether the identifier of the originating or addressed PD_UA is on the ClearedUserTable or not. If it is, TA will do the transfer of OpX If it is not, TA will initiate the access control Procedure.
00452. TA invokes Get(Usage_Resfriction) on Term_Profile to acquire the access control Decision Information (ADI).
00463. The TA invokes the operation Decision_Request on the ADF object. The arguments of this operation are the ADI obtained from the TermJProftle. The ADF makes the decision and returns the Ac- cess_Result to TA. The Access_result may be granted or not_granted.If the Access_Result is not_granted, TA returns an error message to the originator of the operation.
00474. If the Access_Result is granted, TA invokes the operation Up- date(CleareduserTable,PD_UARef) on Terminal_Data to register the PD_UA of the newly cleared user.
0048One way of removing entries from ClearedUserTable, i.e the identifier (reference) of a PD UA, is to restart a timer each time that entry is accessed. If the timer times out, the entry is removed. Some entries may be permanent, i.e. they are not associated with a timer.
0049This type of access confrol is only intended to other users than the terminal owner himself. In fact, the terminal owner should never be prevented to use his terminal. The access to the telecom system domain and the access to the services are different types of access controls which are applicable to all the users including the terminal owner.
0050In the object Usage_Resfriction it is therefore necessary to define an additional attribute called NoRestr_List containing the PD_UA identifiers of the users who are by default allowed to use the terminal. The identifier of the terminal owner's PD_UA is one of them. This list must not be ac- cessible to anyone but the telecom system domain operator itself, i.e. even not to the terminal owner. However, it may be possible to define an "emergency user", i.e. every call to an emergency number will be effectual without being checked by the access control service. Access control for access to the telecom system domain If the user is allowed to use the terminal, it does not necessarily mean that he is allowed to access the telecom system domain. He may be located outside the roaming area; his credit with the operator may have run out; the authentication mechanism used to authenticate him may also be too weak and he is allowed to access a limited set of services. The list of allowed services for a user at a terminal is hence equal to or smaller than the list of subscribed services. This list is a column in the User Registration object in Figure 5.
0051The initiator of the access confrol service is User<sub>a</sub>. The target is the telecom system domain. The AEF is assumed by the PD_UA<sub>a</sub>. The ADF is assumed by the object ADF. The access of the user to the telecom system domain may be limited by some parameters such as Roam- ing_Resfriction, Credit_Limit, Time_Restriction, etc. which are contained in the Service_Resfriction attribute of the User_Profιle object. The Service_Restriction attribute contains also a list of subscribed services. The use of the services in this list may be conditioned by the strength of the method used to authenticate the user, the location of the terminal, the call destination, etc. The Service_Restriction attribute may thus be quite complex.
0052A computational model of the access control service for access to the telecom system domain is shown in Figure 6. The access control procedure is as follows:
00531. The PD_UAa object invokes a Get(Service_Restriction) on the User_Profιle to acquire the access control Decision Information (ADI). 2. The PD_UAa object invokes a Get(SecurityData) on the User_Regisfration object to acquire the contextual information (result from the authentication service).
00543. The PD_UA<sub>a</sub> object invokes the operation Decision_Request on the ADF object. The arguments of this operation are the ADI obtained from User_Profιle and the contextual information obtained from User_Registration.
0055The ADF may use the access control services offered by the platform or a security system to obtain further contextual information such as time, system status, etc. and the access control policy rules. The ADF makes the decision and returns the Access_Result to PD_UAa together with Se- curityData and AllowedServices.
0056The Access_result may be granted, not_granted or suspended. If the Ac- cess_Result is Suspended, depending on the access confrol Policy the terminal will be, temporarily or permanently no longer allowed to access the telecom system domain.
0057If the Access_Result is not_granted, the SecurityData returned to the PD_UA<sub>a</sub> from the ADF will contain a NoOfRefries field increased by one. The NoOfRefries field indicates the number of unsuccessful access attempts and is used as contextual information for the next access confrol service. The PD_UA<sub>a</sub> will invoke the operation Set(SecurityData) on the User Registration object to save the updated SecurityData. Depending on the operation which initiated the access confrol procedure, the PD_UA<sub>a</sub> will return the appropriate response containing a not_granted status. When the Access_Result is granted, the AllowedServices containing an updated list of allowed services is returned to the PD_UA<sub>a</sub>. The PD_UAa will invoke the operation Set(AllowedServices) on the User_Regisfration object to save the updated AllowedServices. Depending on the operation which initiated the access control procedure, the PD_UA<sub>a</sub> will return the appropriate response containing a granted status.
0058The user can now request the wanted service and is hence subject to the access confrol for the requested service.
0059Access control for the requested service
0060There are two types of services, outgoing and incoming. Outgoing services are initiated by the user himself while incoming services are delivered to him by other users or applications.
0061For outgoing services, the initiator of the access confrol service is Usera. For incoming services the initiator is some other user or application. The target is the requested service. The AEF is assumed by the PD_UA<sub>a</sub>. The ADF is assumed by the object ADF. The access of the user to the re- quested service is limited by the information contained in the Allowed- Service list of the User_Registration object. Another resfriction originates from the Usage_Restriction contained in the object Terminal_Data and set by the terminal owner. The terminal owner may allow only one or both of the two service types to be performed on his terminal The attrib- utes OutBarring and InBarring of the Usage_Restriction is used to specify, respectively, the users who are not allowed to use outgoing services and incoming services on the terminal (or who are allowed).
0062The access confrol procedure is as follows: 1. The PD_UA<sub>a</sub> object receives a ServiceReq(ServId) from either the user or an application.
00633. The PD_UAaobject invokes a Get(Usage_Resfriction) on the TA.
00643. The PD_UA<sub>a</sub> object invokes a Get(AllowedService) on the User_Regisfration.
00652. The PD_UA<sub>a</sub> object invokes the operation Decision_Request on the ADF object. The arguments of this operation are the ADI obtained from the User_Registration object and the TA.
0066The ADF makes the decision and returns the Access_Result to PD_UA<sub>a</sub>. The Access result may be granted or not_granted. Depending on the operation which initiated the access control procedure, the PD_UA<sub>a</sub> will return the appropriate response to the requester. The access control on the requested service is shown in Figure 7.
MERITS OF THE INVENTION
0068This invention has high level of flexibility in the sense that it can be used in different mobile distributed systems, public or private, local-area or wide-area, wireline or wireless.
0069It is a complete access control in the sense that it contains all the three types of access control.
0070Important features of the invention may be listed as follows: 1 : A user access control is introduced for distributed systems that supports personal mobility.
00712: Such a user access confrol consists of access confrol for the use of the terminal, access confrol to the telecom system and access confrol to the requested services.
REFERENCES
00731. ISO/IEC. Information technology - Open System INterconnection security frameworks in Open Systems: Part 1 : Access Confrol, Jun 93
00742. ETSI. NA:UPT: Service Requirements on protection of third parties. Version 1.0.0
00753. ITU-TS Draft recommendation F.851. Universal Personal Telecommunication (UPT) - Service Description. International Telecommunication Union-Telecommunication Stan- dardization Sector, (Version 10) Jan 94.
00764. ETSI. NA:UPT: Service Requirements on protection of thirdparties. Version 1.0.
Contents9
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0119050A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7079499B1 | Cited by | United States of America | Applicant |
| US7079499B1 | Cited by | United States of America | Applicant |
| US6769000B1 | Cited by | United States of America | Applicant |
| CN100428710C | Cited by | China | Search report |
| WO0119050A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO9625012A1 | Cites | World Intellectual Property Organization (WIPO) | International search |
49 members in 7 offices
Members49
| Document | Office | Kind | |
|---|---|---|---|
| NO971605D0 | Norway | D0 | |
| NO971605L | Norway | L | |
| WO9845982A2This record | World Intellectual Property Organization (WIPO) | A2 | |
| WO9845985A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9845986A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9845987A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9845988A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9845989A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9846036A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU6857098A | Australia | A | |
| AU6857198A | Australia | A | |
| AU6857298A | Australia | A | |
| AU6857398A | Australia | A | |
| AU6857498A | Australia | A | |
| AU6857598A | Australia | A | |
| AU6857698A | Australia | A | |
| WO9845982A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9845988A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9845989A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9845986A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9845987A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0974214A1 | European Patent Office (EPO) | A1 | |
| EP0974233A2 | European Patent Office (EPO) | A2 | |
| EP0974235A2 | European Patent Office (EPO) | A2 | |
| EP0976222A2 | European Patent Office (EPO) | A2 | |
| EP0980629A2 | European Patent Office (EPO) | A2 | |
| EP0981876A2 | European Patent Office (EPO) | A2 | |
| EP0981921A1 | European Patent Office (EPO) | A1 | |
| US6233446B1 | United States of America | B1 | |
| US6275709B1 | United States of America | B1 | |
| JP2001519062A | Japan | A | |
| JP2001521686A | Japan | A | |
| JP2001521687A | Japan | A | |
| JP2001521688A | Japan | A | |
| JP2001521689A | Japan | A | |
| JP2001521690A | Japan | A | |
| US6332081B1 | United States of America | B1 | |
| US6336130B1 | United States of America | B1 | |
| JP2002510440A | Japan | A | |
| US6389037B1 | United States of America | B1 | |
| US6490613B1 | United States of America | B1 | |
| US6964050B1 | United States of America | B1 | |
| EP0974233B1 | European Patent Office (EPO) | B1 | |
| DE69837040D1 | Germany | D1 | |
| DE69837040T2 | Germany | T2 | |
| JP4234210B2 | Japan | B2 | |
| JP4267708B2 | Japan | B2 | |
| EP0981921B1 | European Patent Office (EPO) | B1 | |
| DE69841308D1 | Germany | D1 |
13 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: grant in national officeWWG | WWG | WO | |
| Non-entry into the national phaseNENP | NENP | CA | |
| Procedure relating to pct application: ceased to have effect for deCeased8642 | 8642 | DE | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Entry into the national phaseENP | ENP | JP | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)DFPE | DFPE | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 98/45982
- Application
- 9800109
Titles2
- English
- ARRANGEMENT FOR IMPROVING SECURITY IN A COMMUNICATION SYSTEM SUPPORTING USER MOBILITY
- French
- AGENCEMENT DESTINE A AMELIORER LA SECURITE DANS UN SYSTEME DE COMMUNICATION SUPPORTANT UNE MOBILITE UTILISATEUR
Classification
- CPC, 17
- H04W8/18
- H04L63/10
- H04Q3/005
- H04Q3/0095
- H04W80/04
- H04L67/303
- H04L67/306
- H04L67/04
- H04L67/10
- H04L69/03
- H04L69/329
- H04W12/084
- H04L67/51
- H04L67/52
- H04L69/32
- H04L9/40
- H04L67/01
- IPC, 16
- G01C21 00
- G06F9 46
- G06F12 14
- G06F15 00
- G06F15 16
- G08G1 123
- H04B7 26
- H04L9 32
- H04L12 56
- H04L29 06
- H04L29 08
- H04M3 46
- H04Q3 00
- H04W8 18
- H04W12 00
- H04W80 04
Designated states94
- Regional, 50
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Sudan
- Eswatini
- Uganda
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
- Tajikistan
- Turkmenistan
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
and 26 moreShow fewer
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 44
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Bulgaria
- Brazil
- Canada
- China
- Cuba
- Czechia
- Estonia
- Georgia
- Guinea-Bissau
- Hungary
- Indonesia
- Israel
- Iceland
- Japan
- Democratic People’s Republic of Korea
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Lithuania
and 20 moreShow fewer
- Latvia
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Norway
- New Zealand
- Poland
- Romania
- Singapore
- Slovenia
- Slovakia
- Sierra Leone
- Türkiye
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)