摘要:
Authentication method for authenticating a mobile node to a packet data network, in which a shared secret for both the mobile node and the packet data network is arranged by using a shared secret of the mobile node and a telecommunications network authentication centre. In the method, the mobile node sends its subscriber identity to the packet data network together with a replay attack protector. The packet data network obtains authentication triplets, forms a session key using them, and sends back to the mobile node challenges and a cryptographic authenticator made by using the session key. The mobile node can then form the rest of the authentication triplets using the challenges and then form the session key. With the session key, the mobile node can check the validity of the cryptographic authenticator. If the authenticator is correct, the mobile node sends a cryptographic response formed using the session key to the packet data network for authenticating itself to the packet data network.
摘要:
The invention allows utilizing Generic Authentication Architecture for Mobile Internet Protocol key distribution. A Generic Authentication Architecture bootstrapping is performed between a mobile terminal device and a Bootstrapping Server Function. In an embodiment a resulting Bootstrapping Transaction Identifier is sent to a Home Agent which uses it to obtain a Home Agent specific key to be used in authenticating a Mobile Internet Protocol Registration Request.
摘要:
Authentication method for authenticating a mobile node to a packet data network, in which a shared secret for both the mobile node and the packet data network is arranged by using a shared secret of the mobile node and a telecommunications network authentication center. In the method, the mobile node sends its subscriber identity to the packet data network together with a replay attack protector. The packet data network obtains authentication triplets, forms a session key using them, and sends back to the mobile node challenges and a cryptographic authenticator made by using the session key. The mobile node can then form the rest of the authentication triplets using the challenges and then form the session key. With the session key, the mobile node can check the validity of the cryptographic authenticator. If the authenticator is correct, the mobile node sends a cryptographic response formed using the session key to the packet data network for authenticating itself to the packet data network.
摘要:
The invention relates to a method for distinguishing clients in a communication system comprising at least one wireless access network and at least one wired access network. The wireless access network comprise means for connecting wireless clients in communication to the wireless access network. Wired access network comprise means for connecting wired clients in communication to the wired access network. Communication system comprise means for communicating between the access network and the wired access network. In the method a resolution request message is transmitted to the communication system indicating a client to be examined, the message is received in at least one other node. A decision whether a resolution reply message is to be transmitted to the communication system is performed on the basis of a resolution reply message.
摘要:
A method, program product and system of selecting a wireless local area network (WLAN) using split user equipment. The method comprising the following steps: a first user equipment obtains relevant network selection parameters from a second user equipment and obtains an undecorated root network access identifier from the second user equipment, the first user equipment performs network discovery and selection, and, upon initiation of final EAP authentication, the first user equipment decorates said network access identifier and transmits it to the WLAN.
摘要:
The present invention relates to a method and system for providing access from a first network (30) to a service of a second network, wherein an authentication signaling is used to transfer a service selection information to the second network (70). Based on the service selection information, a connection can be established to access the desired service. Thereby, cellular packet-switched services can be accessed over networks which do not provide a context activation procedure or corresponding control plane signaling function.
摘要:
The invention relates to a method and system for authenticating a user of a data transfer device (such as a terminal in a wireless local area network, i.e. WLAN). The method comprises: setting up a data transfer connection from the data transfer device to a service access point. Next, identification data of the mobile subscriber (for example an MSISDN) are inputted to the service access point. This is followed by checking from the mobile communications system whether the mobile subscriber identification data contains an access right to the service access point. If a valid access right exists, a password is generated, then transmitted to a subscriber terminal (for example a GSM mobile phone) corresponding to the mobile subscriber identification data, and login from the data transfer device to the service access point takes place with the password transmitted to the subscriber terminal.
摘要:
The invention relates to a terminal (A), which comprises at least one network interface card (NIC1, NIC2, NIC3) for setting up a data transmission connection to a communication network (NW1, NW2, NW3, MNW) for packet switched data transmission, and means (PD) for forming packets of the information to be transmitted and for unpacking information from the received packets. The terminal (A) is allocated at least one first address identifying the terminal (A), and at least one data network-specific second address. The means (PD) for forming packets comprise means for connecting the first address to the packets, and the terminal (A) also comprises a network interface selection driver (NISD), which contains means for selecting the communication network (NW1, NW2, NW3, MNW) used in data transmission at a given time, means for transmitting packets between the means (PD) for forming packets and the network interface card (NIC1, NIC2, NIC3) corresponding to the data transmission network (NW1, NW2, NW3, MNW) used at a given time, and means for modifying the first address to the second address according to the data transmission network used in the packets at a given time.
摘要:
A re-registration authorization is attached to a registration request or data packet sent from a mobile node roaming on a foreign network. The mobile node requests registration with its home network in order to maintain communication with the Internet and maintain identification of the mobile node by its individual home address. Such registration has a limited lifetime, and the re-registration authorization attached to the registration request or other data packet authorizes an intermediate communication entity in the foreign network to re-register the mobile node, on behalf of the mobile node, with the mobile node's home network, if the communication traffic of the mobile node indicates that the mobile node is still roaming on the foreign network. The rate of error is reduced by significantly reducing the amount of transmissions sent from the mobile node, and power consumption of the typically battery-powered mobile unit is reduced, as well.