WO2006136106A1 - A method and system for authenticating user terminal - Google Patents
A method and system for authenticating user terminal Download PDFInfo
- Publication number
- WO2006136106A1 WO2006136106A1 PCT/CN2006/001416 CN2006001416W WO2006136106A1 WO 2006136106 A1 WO2006136106 A1 WO 2006136106A1 CN 2006001416 W CN2006001416 W CN 2006001416W WO 2006136106 A1 WO2006136106 A1 WO 2006136106A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- binding information
- application service
- ims terminal
- service entity
- hss
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/10—Architectures or entities
- H04L65/1016—IP multimedia subsystem [IMS]
Definitions
- the present invention relates to the field of mobile communication technologies, and in particular, to a method and an authentication system for authenticating an Early IMS terminal directly accessing an application service entity. Background of the invention
- mobile communications are not limited to traditional voice communications, through data services such as presence, short messages, web browsing, location information, push services (PUSH), and file sharing.
- data services such as presence, short messages, web browsing, location information, push services (PUSH), and file sharing.
- PUSH push services
- file sharing Combined, mobile communication enables multiple media types of audio, video, picture and text to meet the diverse needs of users.
- IP-based Multimedia Subsystem IMS
- 3GPP 3rd Generation Mobile Communications Standardization Partnership Project
- 3GPP2 3rd Generation Mobile Communications Standardization Partnership Project 2
- IMS IP-based Multimedia Subsystem
- the IMS architecture is superimposed on a packet domain network (PS-Domain), and its authentication-related entities include a Call State Control Function (CSCF) entity and a Home Subscriber Server (HSS) functional entity.
- the CSCF can be further divided into three logical entities: a service CSCF (S-CSCF) proxy CSCF (P-CSCF) and a query CSCF (I-CSCF).
- S-CSCF service CSCF
- P-CSCF proxy CSCF
- I-CSCF query CSCF
- the three logical entities can be different physical devices or the same physical device. Different functional modules.
- the S-CSCF is a service control center of the IMS, which is used to perform session control, maintain session state, manage user information, and generate charging information.
- the P-CSCF is an access point for the terminal user to access the IMS, and is used to complete the user.
- I-CSCF Registration, service volume (QoS) control and security management
- I-CSCF is responsible for interworking between IMS domains, managing the allocation of S-CSCF, hiding network topology and configuration information Interest, and generate billing data, etc.
- the HSS is a very important user database that is used to support the processing of calls and sessions by various network entities.
- 3GPP proposes a transitional authentication. Rights scheme, which provides certain security functions for IMS services on 2G.
- the complete 3G-based authentication scheme is used to authenticate the access user. In this way, both the 2G user and the 3G user can apply the service in the IMS after the authentication is passed.
- the complete 3G-based authentication scheme is called Full 3GPP IMS authentication mode
- the transition authentication scheme is called Early IMS authentication mode
- the Early IMS supporting terminal is called Early IMS terminal.
- any 2G or 3G UE it can use the services provided by the IMS-based application server (AS), such as using the presence service, or some simple management of the IMS-based AS or AS agent (AP). Operations, such as managing some group list information on an AS or AP.
- AS IMS-based application server
- AP AS agent
- the UE When the UE needs to use the service provided by the IMS-based AS, it needs to access the 3GPP packet domain first, and then the IMS authentication to use the service provided by the AS. At this time, for the Early IMS UE, the IMS will use the Early IMS authentication mode for authentication; for the 3G UE, the IMS will use the Full 3GPP IMS authentication mode for authentication.
- the UE When the UE needs to perform management operations on the IMS-based AS or through the AP, it still needs to access the 3GPP packet domain first, and then the UE can directly access the AS or the AP through the Ut interface, so the IMS does not perform the UE again.
- Authentication At the same time, in the existing protocol, the UE directly accessing the AS or the AP is authenticated by using a Common Authentication Framework (GAA). To access the AS or AP.
- GAA Common Authentication Framework
- the existing authentication mechanism based on the Common Authentication Framework is for 3G user terminals, which does not support authentication of Early IMS terminals such as 2G user terminals. Therefore, there must be such a situation: Early The IMS terminal cannot access or the Early IMS terminal can directly access without authentication.
- an object of the present invention is to provide a method for authenticating a user terminal to implement authentication for an Early IMS terminal that directly accesses an application service entity.
- a method for authenticating a user terminal is applicable to an Early IMS terminal that directly accesses an application service entity, and the Early IMS terminal accesses a third-generation 3G mobile communication system to obtain an IP address, and the method further includes the following steps:
- the Early IMS terminal initiates an access request to the application service entity, where the request includes the user identity, and the application service entity obtains the IP address of the Early IMS terminal and its user identity from the home network server HSS according to the received access request. Binding information is formed, and the Early IMS terminal is authenticated according to the binding information and the access request.
- the process of authenticating the Early IMS terminal according to the binding information and the access request includes:
- the application service entity determines whether the IP address in the binding information matches the IP address of the Early IMS terminal that initiates the access request, and if it matches, the Early IMS terminal By authentication, otherwise the Early IMS terminal cannot pass authentication.
- the process of authenticating the Early IMS terminal according to the binding information and the access request includes:
- the application service entity determines whether the acquired IP address of the Early IMS terminal and the binding information of the user identity thereof match the IP address and the user identity of the Early IMS terminal that initiates the access request. If they match, the Early The IMS terminal passes the rights of the woman, otherwise the Early IMS terminal cannot pass the authentication.
- the method further includes: saving the binding information.
- the access request initiated by the Early IMS terminal further includes an authentication mode identifier
- the application service entity When the authentication mode is identified as an early common authentication framework authentication mode, the application service entity obtains the IP address of the Early IMS terminal and the binding of the user identity thereof from the HSS by performing an entity BSF for initial authentication of the user identity. Information.
- the process for the application service entity to obtain the binding information of the IP address of the Early IMS terminal and its user identity from the HSS through the BSF includes the following steps:
- the application service entity sends a message requesting authentication information to the BSF, where the request message includes a user identity, and after receiving the request, the BSF requests the HSS for the IP address of the Early IMS terminal and its user identity according to the user identity in the request.
- the binding information is identified, and the obtained binding information is directly returned to the application service entity, and the application service entity saves the received binding information.
- the message that the BSF requests the binding information from the HSS includes an authentication scheme field, and the authentication scheme field indicates the early IMS.
- the BSF is an early Early-BSF with only query function, or supports BSF with full 3G capability and Early-BSF capability.
- the application service entity requests the binding information from the HSS through the BSF
- the application service entity and the HSS that has saved the binding information belong to the same or different home network.
- the access request initiated by the Early IMS terminal further includes an authentication mode identifier
- the application service entity When the authentication mode is identified as the direct authentication mode, the application service entity directly sends a binding information request message to the HSS, and receives and saves the binding information of the IP address of the Early IMS terminal and the user identity of the returned by the HSS. .
- the request message sent by the application service entity to the HSS is carried by the user data request UDR message, and the attribute information in the message indicates the request binding information; the response message returned by the HSS to the application service entity is answered by the user data UDA The message is carried, and the attribute information in the message indicates the request binding information.
- the application service entity directly requests the binding information from the HSS
- the application service entity and the HSS that has saved the binding information belong to the same home network.
- the access request initiated by the Early IMS terminal to the application service entity is carried by the HTTP GET-based request message HTTP GET;
- the authentication mode identifier in the request message is carried by a user agent user agent field in the HTTP GET.
- the user identity identifier in the access request is a user public identity identifier IMPU;
- the binding information of the IP address of the Early IMS terminal and the user identity of the application service entity obtained from the HSS is: a correspondence between an IMPU included in the access request and an IP address of the Early IMS terminal; or an initiation connection Correspondence between all IMPUs owned by the requested Early IMS terminal and the IP address of the Early IMS terminal.
- the application service entity further includes: determining whether the binding information corresponding to the user identity in the access request exists in the application service entity, and if yes, acquiring the binding Determining the information, and continuing to perform the authentication operation; otherwise, continuing to perform the operation of acquiring the binding information from the HSS.
- the method further comprises: establishing a transport layer secure TLS tunnel between the Early IMS terminal and the application service entity, and then performing an operation of the Early IMS terminal to initiate an access request to the application service entity.
- the authentication system of the present invention includes: an Early IMS terminal, an application service entity, and a user home network server HSS, where
- the Early IMS terminal obtains an IP address after accessing the third-generation 3G mobile communication system, and the terminal is configured to initiate an access request including the user identity to the application service entity;
- the application service entity is configured to receive an access request from the Early IMS terminal, and notify the HSS to provide the binding information formed by the IP address of the Early IMS terminal and the user identity, and the binding request and the access request are performed according to the binding information.
- the Early IMS terminal performs authentication;
- the HSS is configured to return the binding information formed by the IP address of the Early IMS terminal and the user identity to the application service entity according to the notification of the application service entity.
- the Early IMS terminal includes:
- the link establishing module is configured to initiate an access request including the user identity to the application service entity.
- the Early IMS terminal further includes:
- the service communication module is configured to receive a notification about authentication through the link establishment module, and perform service communication with the application service entity.
- the application service entity includes: receiving a request module and a security information request and Check module, where
- the receiving request module is configured to receive an access request from the Early IMS terminal, notify the security information requesting and checking module to obtain the binding information formed by the IP address of the terminal and the user identity, and receive the request from the security information request and the checking module.
- the security information requesting and checking module is configured to request and receive the binding information formed by the HSS providing the IP address of the terminal and the user identity according to the obtained IP address of the terminal and the identity of the user identity according to the notification of the receiving request module.
- the information is matched with the IP address and the user identity of the Early IMS terminal that initiated the access request, the terminal is authenticated, and the authentication result is sent to the receiving request module.
- the security information requesting and checking module is further configured to save the binding information formed by the IP address and the user identity of the terminal provided by the HSS, and after receiving the access request from the Early IMS terminal, Determining whether there is binding information corresponding to the user identity in the access request, and directly performing authentication in the presence of the binding information; and requesting and receiving the HSS in the absence of the binding information Bind information.
- the service application entity further includes:
- the service communication module is configured to receive an authentication result from the receiving request module, and perform service communication with the Early IMS terminal when the terminal passes the authentication.
- the HSS includes: a security binding information storage module, configured to hold binding information composed of an IP address of the Early IMS terminal and its user identity, and find Early in itself according to the notification from the application service entity. Binding information corresponding to the IMS, and returning the found binding information to the application service entity.
- a security binding information storage module configured to hold binding information composed of an IP address of the Early IMS terminal and its user identity, and find Early in itself according to the notification from the application service entity. Binding information corresponding to the IMS, and returning the found binding information to the application service entity.
- the system further comprises:
- the BSF with the Early-BSF function is configured to receive a notification from the application service entity regarding the binding information of the IP address and the user identity requesting to provide the Early IMS terminal, forward the notification to the HSS, and receive the HSS from the HSS. IP of the Early IMS terminal The binding information formed by the address and the user identity is forwarded to the application service entity.
- the application service entity is an application server AS or an application server proxy AP.
- the key point of the present invention is: after receiving the access request containing the user identity from the Early IMS terminal, the application service entity obtains the IP address of the Early IMS terminal from the HSS according to the user identity in the access request and Binding information of the user identity; Afterwards, the application service entity authenticates the Early IMS terminal according to the binding information of the obtained Early IMS terminal's IP address and its user identity and the access request.
- the Early IMS terminal directly accessing the application service entity is authenticated, which ensures that the legitimate user can access and ensures the security of the network. Especially for early application of IMS-based services, it can be deployed and run normally.
- Embodiment 1 is a schematic flow chart showing Embodiment 1 of the present invention.
- FIG. 2 is a schematic flow chart of a second embodiment to which the present invention is applied;
- FIG. 3 is a schematic structural diagram of an authentication system to which an embodiment of the present invention is applied.
- FIG. 4 is a schematic structural diagram of an authentication system to which another embodiment of the present invention is applied. Mode for carrying out the invention
- the method for authenticating a user terminal is applicable to an Early IMS terminal that directly accesses an application service entity, and the Early IMS terminal obtains after accessing the 3GPP network. IP address, the method includes the following steps:
- the Early IMS terminal initiates an access request to the application service entity, where the request includes a user identity, and the application service entity obtains, from the HSS, the binding of the IP address of the Early IMS terminal and its user identity according to the received access request. Determining information, and authenticating the Early IMS terminal according to the binding information and the access request.
- the method of the present invention will be described in detail below by taking the Early IMS terminal as a 2G user terminal as an example.
- FIG. 1 is a schematic flow chart showing a first embodiment of the present invention.
- the UE of the 2G has accessed the 3GPP packet domain, and obtains the IP address assigned by the packet network gateway node (GGSN) of the packet network, and the GGSN uses the telephone number (MSISDN) of the user of the UE,
- MSISDN packet network gateway node
- IMSI International Mobile Subscriber Identity
- the information about the International Mobile Subscriber Identity (IMSI) and the IP address of the packet domain is sent to the HSS.
- the HSS finds the user identity IMPI of the user in the IMS system through the MSISDN or IMSI of the user, and the IMPI of the UE, the IMPI.
- the corresponding user's public identity (IMPU), MSISD, and the IP address of the UE are bound and saved.
- This embodiment uses a 2G UE to access the AS as an example for description.
- Step 101 The UE of the 2G initiates an access request to the AS, where the request includes the user identity of the UE, such as an IMPU; the request message further includes an authentication mode identifier supported by the UE, and the existing Http-based protocol is used.
- the Ut interface can use the user agent field in the Http GET message to carry the authentication mode identifier.
- the authentication mode supported by the 2G UE is the Ut interface authentication mode used in the early application of the GAA.
- the identifier of the authentication mode is recorded as an early universal authentication framework authentication method (Early-GAA-Ut), then the authentication mode identifies the user that Early-GAA-Ut will be added in the Http message. In the agent field.
- the AS determines, according to the received access request, that the authentication mode identifier in the request message is Early-GAA-Ut, and determines whether there is binding information corresponding to the user identity in the access request, and if yes, The binding information is obtained by itself, and the process proceeds to step 106; otherwise, in step 102, the AS sends a message requesting authentication information to the entity (BSF) that performs the initial authentication of the user identity, where the message includes the user identity.
- the BSF in this step can be an Early-BSF with only the query function, or a BSF with Full 3G function and Earl y-BSF function.
- the AS Since the AS requests the authentication information from the BSF during the execution of the 3G GAA, the AS needs to carry the BSF-assigned user session identifier (B-TID), and in the Early-GAA-Ut authentication mode, there is no BSF-assigned B. -TID, so for a BSF that supports the full 3G function and has the Early-BSF function, after receiving the message requesting authentication information from the AS, it can determine whether the message carries the B-TID or the user identity. The distinction is whether the normal 3G GAA authentication method or the Early-GAA-Ut authentication authentication method.
- B-TID BSF-assigned user session identifier
- Step 103 After receiving the message requesting the authentication information of the AS, and determining that the request carries the user identity, the BSF requests the HSS to bind the IP address of the UE and the binding identifier of the user identity.
- the request information also includes the user identity of the UE, and the message requesting the binding information to the HSS includes an authentication scheme field, and the authentication scheme field indicates the early IMS.
- Step 104 The HSS queries the binding information required by the BSF according to the user identity identifier in the received request information, and returns the binding information to the BSF.
- the process of the HSS querying the binding information is: the HSS searches for the IMPI corresponding to the IMPU and the IP address corresponding to the IMPI through the received IMPU.
- the returned binding information refers to the correspondence between the IMPU and the IP address of the UE.
- the binding information returned by the HSS is the binding information of the IMPI and the IP address or the binding information of the IMSI and the IP address, or returns the required IMPI and/or IMPU and the IP address of the user terminal according to the needs of the network system to which the application is applied.
- Binding information That is to say, the binding information returned by the HSS is the correspondence information between the user identity of the UE that initiated the request and the IP address currently owned by the UE.
- Step 105 After receiving the binding information, the BSF does not save but directly forwards the binding information to the AS.
- the advantage of the BSF is that when the AS requests the binding information from the BSF again, the BSF needs to go to the HSS to query. This ensures that the information returned by the BSF to the AS is always up to date.
- Step 106 The AS authenticates the 2G terminal according to the obtained binding information and the access request.
- the method for authenticating here may be: the AS determines whether the binding information of the IP address of the UE and its user identity saved by the AS matches the IP address and the user identity of the UE that initiated the access request, that is, whether they are identical. If the match is met, the 2G UE passes the authentication, otherwise the 2G UE cannot pass the authentication.
- the authentication method may also be: the AS determines whether the IP address in the binding information matches the IP address of the 2G UE that initiates the access request, and if yes, the 2G UE passes the authentication, otherwise the 2G UE Cannot pass authentication.
- the GGSN will notify the HSS to update the binding information or delete the binding information.
- the HSS does not need to notify the BSF, because usually after the IP address changes or logs off, the connection-based application layer protocol will be disconnected and the connection will be re-established later, and the AS disconnects.
- the saved binding information will be deleted.
- the AS will re-request the binding information to the BSF.
- the AS that receives the access request and the HSS that has saved the binding information may belong to the same home network, or may belong to different home networks.
- FIG. 2 is a schematic flow chart showing the application of the second embodiment of the present invention.
- the UE has accessed the 3GPP packet domain and obtained the IP address assigned by the GGSN.
- the GGSN sends the MSISDN, IMSI and IP address of the UE to the HSS.
- the HSS finds the user in the IMS through the MSISDN or IMSI of the user.
- the user identity in the system identifies the IMPI, and binds and stores the IMPI of the UE, the public identity (IMU) of the user corresponding to the IMPI, the MSISDN, and the IP address of the UE.
- IMU public identity
- Step 201 The UE of the 2G initiates an access request to the AS, where the request includes the user identity of the UE itself, such as an IMPU.
- the message of the request further includes an authentication mode identifier supported by the UE.
- the Ut interface can use the user agent field in the Http GET message to carry the authentication mode identifier.
- the authentication mode supported by the 2G UE is a direct reference of the Sh interface between the application AS and the HSS.
- Right mode, here, the identifier of the authentication mode is recorded as a direct authentication mode (Ut-Sh-Authentication), then the authentication mode identifier Ut-Sh-Authentication will be added in the user agent field in the Http message. .
- the AS determines, according to the received access request, that the authentication mode identifier in the request message is Ut-Sh-Authentication, it determines whether there is binding information corresponding to the user identity in the access request, and if yes, The binding information is obtained by itself, and the process proceeds to step 204. Otherwise, in step 202, the AS sends a message requesting the IP address of the UE and its user identity binding information to the HSS through the Sh interface.
- the request message sent by the AS to the HSS also contains the user identity information.
- the request message sent by the AS to the HSS through the Sh interface is carried by a User Data Request (UDR) message, and the attribute information Avp ( Attribute-Value Pair ) in the request message is used to describe the requesting user. What kind of data.
- the address binding information is requested through the Sh interface by adding an Avp attribute that requires binding of the address information.
- Step 203 The HSS queries the binding information required by the AS according to the user identity identifier in the received request information, and returns the binding information directly to the AS.
- the HSS uses a User Data Answer (UDA, User-Data-Answer) message in the Sh interface as a response message to the UDR message.
- UDA User Data Answer
- the Avp attribute information added in step 202 is also used in the UDA message.
- the process of the HSS querying the binding information is: the HSS searches for the IMPI corresponding to the IMPU and the IP address corresponding to the IMPI through the received IMPU.
- the returned binding information refers to the correspondence between the IMPU and the IP address of the UE.
- the binding information returned by the HSS is the binding information of the IMPI and the IP address or the binding information of the IMSI and the IP address, or according to the applied
- the network system needs to return information about the required IMPI and/or the binding of the IMPU to the IP address of the user terminal. That is to say, the binding information returned by the HSS is the correspondence information of the user identity of the UE that initiated the request and the IP address currently owned by the UE.
- Step 204 The AS authenticates the 2G terminal according to the obtained binding information and the access request.
- the authentication method may be: the AS determines whether the acquired IP address of the UE and the binding information of the user identity match the IP address and the user identity of the UE that initiated the access request, that is, whether they are identical. If the match is met, the 2G UE passes the authentication, otherwise the 2G UE cannot pass the authentication.
- the AS may perform authentication only according to whether the IP address in the binding information is the same as the IP address of the UE that initiates the access request.
- the GGSN will notify the HSS to update the binding information or delete the binding information.
- the HSS does not need to notify the AS, because usually after the IP address changes or logs off, the connection-based application layer protocol will be disconnected and the connection will be re-established later.
- the AS will delete the saved binding information after the connection is disconnected.
- the UE re-establishes the connection, the AS will re-request the binding information to the HSS.
- the AS that receives the access request and the HSS that has saved the binding information must belong to the same home network.
- the correspondence between the user's public identity IMPU and the private identity IMPI is a many-to-one relationship. Therefore, for the above two embodiments, when the HSS returns the binding information, the IMPI may also be returned. Binding information of all IMPUs to the IP address of the UE. The advantage of this is that after the UE connects to the AS, the subsequent messages may change to use other IMPUs, so the AS can save the correspondence between all IMPUs of the UE and the IP address.
- Such a process is particularly useful when the AS in the above embodiment is replaced by an AP, because the AP can have multiple ASs behind it, and the AP performs the authentication function for the ASs, and the UE uses the request when sending requests to different ASs.
- the IMPU is likely to be different.
- the application service entity can also perform the authentication operation directly after receiving the binding information from the HSS without saving.
- the UE and the AS may first establish a transport layer security (TLS Transport Layer Security) tunnel based on transport layer protection. Since TLS is a transport layer protection protocol, after the tunnel is established, it is executed.
- TLS Transport Layer Security
- the application layer-based authentication process can ensure sufficient security protection for application layer communication between the UE and the AS.
- the above embodiments all allow the network side to adapt to the UE, that is, enable the network side to authenticate the 2G UE.
- the UE can also be adapted to the network side, that is, the 2G user can load a software module, so that the 2G UE can fully support the 3G function, that is, the 2G UE can support the 3G authentication mode.
- the network side can still authenticate the UE by using a standard 3G authentication mode.
- the software module can be downloaded from the Internet or directly from the operator.
- the authentication mode in the foregoing embodiments may be applied when the UE of the 2G UE directly accesses the AS, or may be applied to the message sent by the UE that is accessed by the UE.
- the present invention also provides an authentication system capable of authenticating an Early IMS terminal that directly accesses an application service entity.
- Figure 3 illustrates an embodiment of an authentication system.
- the authentication system includes: an Early IMS terminal, an application service entity, and an HSS.
- the Early IMS terminal obtains an IP address after accessing the 3G mobile communication system, the terminal is configured to initiate an access request including the user identity to the application service entity, and the application service entity is configured to receive the access request from the Early IMS terminal.
- the HSS notifying the HSS to provide the binding information formed by the IP address of the Early IMS terminal and the user identity, and authenticating the Early IMS terminal according to the binding information and the access request; the HSS is used according to the application service entity.
- the notification returns the binding information formed by the IP address of the Early IMS terminal and the user identity to the application service entity.
- the Early IMS terminal in FIG. 3 includes a link establishment module for initiating an access request including a user identity to an application service entity. Further, the terminal further includes a service communication module, configured to receive, by the link establishment module, a notification about the authentication by the application service entity, and perform service communication with the application service entity.
- the application service entity includes a receiving request module and a security information request and checking module. among them
- the receiving request module is configured to receive an access request from the Early IMS terminal, notify the security information requesting and checking module to obtain the binding information formed by the IP address and the user identity of the terminal, and receive the information from the security information request and the checking module.
- the security information request and check module is configured to request and receive the binding information formed by the HSS providing the IP address of the terminal and the user identity according to the notification of the receiving request module, according to the obtained IP address of the terminal and the user thereof.
- the binding information of the identity and the access request are used to authenticate the terminal, and the authentication result is sent to the receiving request module.
- the security information requesting and checking module can also save the binding information formed by the IP address and the user identity of the terminal provided by the HSS in itself, and determine the self after receiving the access request from the Early IMS terminal. Whether the binding information corresponding to the user identity in the access request exists, and if the binding information exists, the authentication is directly performed; if the binding information does not exist, the binding provided by the HSS is requested and received. information.
- the service application entity further includes a service communication module, configured to receive an authentication result from the receiving request module, and perform service communication with the Early IMS terminal when the terminal passes the authentication.
- the HSS includes a security binding information storage module, configured to store the binding information formed by the IP address of the Early IMS terminal and its user identity, and find the binding information corresponding to the Early IMS according to the notification from the application service entity. And return the found binding information to the application business entity.
- Fig. 4 shows still another embodiment of the authentication system of the present invention.
- the authentication system in this embodiment differs from FIG. 3 in that a BSF having an Early-BSF function is added.
- the BSF is configured to receive a notification from the application service entity regarding the binding information of the IP address and the user identity requesting to provide the Early IMS terminal, forward the notification to the HSS, and receive the IP of the Early IMS terminal from the HSS.
- the binding information formed by the address and the user identity is forwarded to the application service entity.
- the above-mentioned Early IMS terminal and the application service entity may not include the service communication module.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Power Engineering (AREA)
- Mobile Radio Communication Systems (AREA)
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNA2006800123062A CN101160920A (zh) | 2005-06-21 | 2006-06-21 | 对用户终端进行鉴权的方法及鉴权系统 |
| EP06742203A EP1816825A4 (en) | 2005-06-21 | 2006-06-21 | METHOD AND SYSTEM FOR AUTHENTICATING USER TERMINAL |
| US11/735,541 US20070249342A1 (en) | 2005-06-21 | 2007-04-16 | Method, system and application service entity for authenticating user equipment |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN200510077476.6 | 2005-06-21 | ||
| CNB2005100774766A CN100379315C (zh) | 2005-06-21 | 2005-06-21 | 对用户终端进行鉴权的方法 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US11/735,541 Continuation US20070249342A1 (en) | 2005-06-21 | 2007-04-16 | Method, system and application service entity for authenticating user equipment |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2006136106A1 true WO2006136106A1 (en) | 2006-12-28 |
Family
ID=36811707
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2006/001416 Ceased WO2006136106A1 (en) | 2005-06-21 | 2006-06-21 | A method and system for authenticating user terminal |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20070249342A1 (zh) |
| EP (1) | EP1816825A4 (zh) |
| CN (2) | CN100379315C (zh) |
| WO (1) | WO2006136106A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101945102A (zh) * | 2010-07-26 | 2011-01-12 | 中兴通讯股份有限公司 | 基于ims的iptv用户合法性认证的方法、服务器及系统 |
| US11409851B2 (en) | 2016-11-08 | 2022-08-09 | Huawei Technologies Co., Ltd. | Authentication method and electronic device |
Families Citing this family (32)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101030853B (zh) * | 2006-03-02 | 2010-04-14 | 华为技术有限公司 | 一种用户终端的鉴权方法 |
| CN101102186B (zh) * | 2006-07-04 | 2012-01-04 | 华为技术有限公司 | 通用鉴权框架推送业务实现方法 |
| CN101072326B (zh) * | 2007-06-20 | 2011-12-21 | 华为技术有限公司 | 访问非归属签约iptv业务提供者业务的方法、系统和设备 |
| CN101946455B (zh) * | 2008-02-21 | 2012-09-05 | 上海贝尔股份有限公司 | 用于异构网络的一次通过认证机制和系统 |
| US8359031B2 (en) * | 2008-09-19 | 2013-01-22 | Clear Channel Management Services, Inc. | Computer based method and system for logging in a user mobile device at a server computer system |
| CN102917342B (zh) * | 2008-09-28 | 2015-11-25 | 华为技术有限公司 | 用户设备活动信息通知方法、系统及网元设备、服务器 |
| CN101715173B (zh) * | 2008-10-06 | 2013-06-05 | 华为技术有限公司 | 用户设备活动信息通知方法、系统及网元设备、服务器 |
| CN101729578B (zh) * | 2008-10-27 | 2013-01-23 | 华为技术有限公司 | 应用业务接入鉴权方法及接入鉴权代理 |
| CN101478755B (zh) * | 2009-01-21 | 2011-05-11 | 中兴通讯股份有限公司 | 一种网络安全的http协商的方法及其相关装置 |
| KR101094577B1 (ko) | 2009-02-27 | 2011-12-19 | 주식회사 케이티 | 인터페이스 서버의 사용자 단말 인증 방법과 그 인터페이스 서버 및 사용자 단말 |
| CN102238211A (zh) * | 2010-04-23 | 2011-11-09 | 上海博泰悦臻电子设备制造有限公司 | 车载通信服务提供、获取方法和装置及系统 |
| EP2418815B1 (en) | 2010-08-12 | 2019-01-02 | Deutsche Telekom AG | Managing Session Initiation Protocol communications towards a user entity in a communication network |
| EP2418817B1 (en) | 2010-08-12 | 2018-12-12 | Deutsche Telekom AG | Application server for managing communications towards a set of user entities |
| EP2418818B1 (en) * | 2010-08-12 | 2018-02-14 | Deutsche Telekom AG | Network entity for managing communications towards a user entity over a communication network |
| CN102469448B (zh) * | 2010-11-08 | 2016-12-28 | 中兴通讯股份有限公司 | 一种机器类通信接入控制的方法、系统及装置 |
| CA2853867A1 (en) * | 2011-10-31 | 2013-05-10 | Nokia Technologies Oy | Security mechanism for external code |
| EP2805450B1 (en) * | 2012-01-19 | 2019-05-15 | Nokia Solutions and Networks Oy | Detection of non-entitlement of a subscriber to a service in communication networks |
| US20130212653A1 (en) * | 2012-02-09 | 2013-08-15 | Indigo Identityware | Systems and methods for password-free authentication |
| CN103888415B (zh) * | 2012-12-20 | 2017-09-15 | 中国移动通信集团公司 | Ims用户的游牧控制方法及装置 |
| CN104468464B (zh) * | 2013-09-12 | 2018-07-06 | 深圳市腾讯计算机系统有限公司 | 验证方法、装置和系统 |
| CN104753872B (zh) * | 2013-12-30 | 2018-10-12 | 中国移动通信集团公司 | 认证方法、认证平台、业务平台、网元及系统 |
| US10791496B2 (en) * | 2016-06-30 | 2020-09-29 | T-Mobile Usa, Inc. | Restoration of serving call session control and application server function |
| CN108024248B (zh) * | 2016-10-31 | 2022-11-08 | 中兴通讯股份有限公司 | 一种物联网平台的鉴权方法和装置 |
| CN106599622A (zh) * | 2016-12-06 | 2017-04-26 | 福建中金在线信息科技有限公司 | 一种应用软件接口程序过滤的方法及装置 |
| CN109756450B (zh) | 2017-11-03 | 2021-06-15 | 华为技术有限公司 | 一种物联网通信的方法、装置、系统和存储介质 |
| CN109962878B (zh) | 2017-12-14 | 2021-04-16 | 大唐移动通信设备有限公司 | 一种ims用户的注册方法及装置 |
| US10721621B2 (en) * | 2018-05-23 | 2020-07-21 | Cisco Technology, Inc. | Updating policy for a video flow during transitions |
| CN112422479B (zh) * | 2019-08-22 | 2024-05-14 | 北京奇虎科技有限公司 | 一种设备绑定方法及装置、系统 |
| WO2021093997A1 (en) * | 2019-11-15 | 2021-05-20 | Telefonaktiebolaget Lm Ericsson (Publ) | A method for supporting authentication of a user equipment |
| CN114125836B (zh) * | 2020-08-10 | 2024-08-09 | 中国移动通信有限公司研究院 | 鉴权方法、装置、设备及存储介质 |
| US11638134B2 (en) * | 2021-07-02 | 2023-04-25 | Oracle International Corporation | Methods, systems, and computer readable media for resource cleanup in communications networks |
| US11709725B1 (en) | 2022-01-19 | 2023-07-25 | Oracle International Corporation | Methods, systems, and computer readable media for health checking involving common application programming interface framework |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030159067A1 (en) * | 2002-02-21 | 2003-08-21 | Nokia Corporation | Method and apparatus for granting access by a portable phone to multimedia services |
| US20040122934A1 (en) * | 2001-04-03 | 2004-06-24 | Ilkka Westman | Registering a user in a communication network |
| US20040230697A1 (en) * | 2003-05-13 | 2004-11-18 | Nokia Corporation | Registrations in a communication system |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| ATE405123T1 (de) * | 2004-05-12 | 2008-08-15 | Ericsson Telefon Ab L M | Authentifizierungssystem |
| GB0414421D0 (en) * | 2004-06-28 | 2004-07-28 | Nokia Corp | Authenticating users |
| US20060020791A1 (en) * | 2004-07-22 | 2006-01-26 | Pekka Laitinen | Entity for use in a generic authentication architecture |
| US7715822B2 (en) * | 2005-02-04 | 2010-05-11 | Qualcomm Incorporated | Secure bootstrapping for wireless communications |
| MX2007009705A (es) * | 2005-02-11 | 2007-10-04 | Nokia Corp | Metodo y aparato para proporcionar procedimientos de carga inicial en una red de comunicacion. |
| GB0504865D0 (en) * | 2005-03-09 | 2005-04-13 | Nokia Corp | User authentication in a communications system |
-
2005
- 2005-06-21 CN CNB2005100774766A patent/CN100379315C/zh not_active Expired - Fee Related
-
2006
- 2006-06-21 WO PCT/CN2006/001416 patent/WO2006136106A1/zh not_active Ceased
- 2006-06-21 CN CNA2006800123062A patent/CN101160920A/zh active Pending
- 2006-06-21 EP EP06742203A patent/EP1816825A4/en not_active Withdrawn
-
2007
- 2007-04-16 US US11/735,541 patent/US20070249342A1/en not_active Abandoned
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040122934A1 (en) * | 2001-04-03 | 2004-06-24 | Ilkka Westman | Registering a user in a communication network |
| US20030159067A1 (en) * | 2002-02-21 | 2003-08-21 | Nokia Corporation | Method and apparatus for granting access by a portable phone to multimedia services |
| US20040230697A1 (en) * | 2003-05-13 | 2004-11-18 | Nokia Corporation | Registrations in a communication system |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP1816825A4 * |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101945102A (zh) * | 2010-07-26 | 2011-01-12 | 中兴通讯股份有限公司 | 基于ims的iptv用户合法性认证的方法、服务器及系统 |
| CN101945102B (zh) * | 2010-07-26 | 2014-07-16 | 中兴通讯股份有限公司 | 基于ims的iptv用户合法性认证的方法、服务器及系统 |
| US11409851B2 (en) | 2016-11-08 | 2022-08-09 | Huawei Technologies Co., Ltd. | Authentication method and electronic device |
| US11860986B2 (en) | 2016-11-08 | 2024-01-02 | Huawei Technologies Co., Ltd. | Authentication method and electronic device |
Also Published As
| Publication number | Publication date |
|---|---|
| CN101160920A (zh) | 2008-04-09 |
| US20070249342A1 (en) | 2007-10-25 |
| EP1816825A1 (en) | 2007-08-08 |
| EP1816825A4 (en) | 2008-03-05 |
| CN100379315C (zh) | 2008-04-02 |
| CN1802016A (zh) | 2006-07-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN100379315C (zh) | 对用户终端进行鉴权的方法 | |
| JP5529889B2 (ja) | 加入者装置のグローバルに一意的な識別子の生成 | |
| CN101002446B (zh) | 在混合电信网络中用于提供相关通信会话信息的方法和系统 | |
| WO2006047925A1 (en) | A method for selecting the authentication manner at the network side | |
| WO2006010312A1 (en) | A method of informing the capability change of the terminal to the network | |
| WO2006102830A1 (en) | A method for terminal identifying capability interaction route control while ims and cs are coinstantaneous | |
| WO2006136097A1 (en) | A method for processing the register abnormality during the user register procedure | |
| US8661097B2 (en) | Service node, control method thereof, user node, and control method thereof | |
| WO2006099815A1 (en) | A method for implementing the user registering in the ip multimedia subsystem and the system thereof | |
| CN1610441B (zh) | 通信系统中消息的验证 | |
| WO2008000192A1 (en) | Network access method of terminals, network access system and gateway equipment | |
| CN100493227C (zh) | 一种网络侧对更新ip地址的用户的处理方法 | |
| US20110173687A1 (en) | Methods and Arrangements for an Internet Multimedia Subsystem (IMS) | |
| WO2019184717A1 (zh) | 一种通信方法、及相关产品 | |
| CN101573934A (zh) | 在通信网络中的鉴别 | |
| CN114667751A (zh) | 一种支持对用户设备认证的方法 | |
| US20070055874A1 (en) | Bundled subscriber authentication in next generation communication networks | |
| CN101401476B (zh) | 通信网络中的接入控制 | |
| WO2014114088A1 (zh) | 一种ngn下实现宽带业务功能的方法及业务平台 | |
| CN101800945A (zh) | 区分共享同一公共用户标识的多个用户设备的方法及装置 | |
| WO2015192559A1 (zh) | Ims、ims中的业务开通方法及装置 | |
| WO2007090348A1 (en) | A method, apparatus and system for checking the validity for globally routable user agent uri | |
| JP2006521717A5 (zh) | ||
| US9692835B2 (en) | Method and apparatuses for the provision of network services offered through a set of servers in an IMS network | |
| CN101521930B (zh) | 一种策略控制方法及系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| WWE | Wipo information: entry into national phase |
Ref document number: 11735541 Country of ref document: US |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2006742203 Country of ref document: EP |
|
| WWP | Wipo information: published in national office |
Ref document number: 2006742203 Country of ref document: EP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 200680012306.2 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 11735541 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWW | Wipo information: withdrawn in national office |
Country of ref document: DE |