首页> 外国专利> methods for authenticating a subscriber of a first network and several first networks to access an application service, and system for authenticating a subscriber of a first network to access application services

methods for authenticating a subscriber of a first network and several first networks to access an application service, and system for authenticating a subscriber of a first network to access application services

机译:用于认证第一网络和多个第一网络的订户以访问应用程序服务的方法,以及用于认证第一网络的订户以访问应用程序服务的系统

摘要

METHODS FOR AUTHENTICING A FIRST NETWORK SUBSCRIBER AND FIRST NETWORKS TO ACCESS AN APPLICATION SERVICE, AND SYSTEM TO AUTHENTIC A FIRST NETWORK SUBSCRIBER TO ACCESS APPLICATION SERVICES. The present invention relates to a system and method for authenticating a subscriber of a first network, for example, a GPRS / GSM network, to access application services through a second network, where the second network is a data network by packets (PDN), for example, Intemet. The system according to preferred embodiments of the invention includes a mobile station MS (2) connected to a cellular network and capable of generating access request messages included in the data packets, said access request messages being expressed with a syntax that conforms to an application level protocol; an AAA allocation server (7) capable of allocating an address on said second network to said subscriber (subscriber address) and providing a mapping between the subscriber address and a first subscriber identifier; a connection point (6), for example a GGSN, which interfaces the first network with the second network and assigns the subscriber address to MS 2; an STI Socket Injector (10) connected to the connection point (6) and capable of intercepting data packets generated from the endpoint station and directed to the second network through the connection point (6) and capturing in data packets at least the subscriber address, and an Identity Authority IA logical entity (9) connected to the STI 10 and capable of performing the following functions: receiving the subscriber address and access request message from the first entity logic, recognizing the application level protocol of the access request message, requesting the first subscriber identifier from the allocation server, generating an authentication token according to the application level protocol, said token including a second identifier of subscriber, and associate the authentication form with the access request message.
机译:认证第一网络用户和第一网络以访问应用服务的方法,以及认证第一网络用户的网络以访问应用服务的方法。 [0001]本发明涉及一种系统和方法,该系统和方法用于认证第一网络(例如,GPRS / GSM网络)的订户通过第二网络来访问应用服务,其中第二网络是通过分组的数据网络(PDN),例如,互联网。根据本发明的优选实施例的系统包括连接到蜂窝网络并且能够生成包括在数据分组中的访问请求消息的移动台MS(2),所述访问请求消息用符合应用级别的语法来表达。协议; AAA分配服务器(7),能够将所述第二网络上的地址分配给所述用户(用户地址),并提供用户地址和第一用户标识符之间的映射;连接点(6),例如GGSN,其将第一网络与第二网络接口并将订户地址分配给MS 2; STI套接字注入器(10),其连接到连接点(6),并且能够拦截从端点站生成并通过连接点(6)定向到第二网络的数据包,并至少在数据包中捕获用户地址,与身份验证机构IA逻辑实体(9)相连,该逻辑实体(9)执行以下功能:从第一实体逻辑接收订户地址和访问请求消息,识别访问请求消息的应用层协议,请求来自分配服务器的第一用户标识符,根据应用级协议生成认证令牌,所述令牌包括用户的第二标识符,并将认证表格与访问请求消息相关联。

著录项

  • 公开/公告号BRPI0517521A

    专利类型

  • 公开/公告日2008-10-14

    原文格式PDF

  • 申请/专利权人 TELECOM ITALIA S.P.A.;

    申请/专利号BR2005PI17521

  • 申请日2005-09-30

  • 分类号H04L29/06;H04L29/12;H04W4/18;H04W8/26;H04W74;H04W88/06;H04W88/16;

  • 国家 BR

  • 入库时间 2022-08-21 20:08:45

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号