CN1835621B - Method and device for security user's layer mobile positioning in radio network - Google Patents

Method and device for security user's layer mobile positioning in radio network Download PDF

Info

Publication number
CN1835621B
CN1835621B CN200510024369A CN200510024369A CN1835621B CN 1835621 B CN1835621 B CN 1835621B CN 200510024369 A CN200510024369 A CN 200510024369A CN 200510024369 A CN200510024369 A CN 200510024369A CN 1835621 B CN1835621 B CN 1835621B
Authority
CN
China
Prior art keywords
running fix
home domain
visit territory
fix equipment
root certificate
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN200510024369A
Other languages
Chinese (zh)
Other versions
CN1835621A (en
Inventor
胡志远
刘菲
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Nokia Shanghai Bell Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Alcatel Lucent Shanghai Bell Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, Alcatel Lucent Shanghai Bell Co Ltd filed Critical China Mobile Communications Group Co Ltd
Priority to CN200510024369A priority Critical patent/CN1835621B/en
Publication of CN1835621A publication Critical patent/CN1835621A/en
Application granted granted Critical
Publication of CN1835621B publication Critical patent/CN1835621B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention is for use in making the secure user plane location for the target subscriber terminal roaming from the home network to the visit network and comprises: by a direct authentication from the target subscriber terminal for the mobile locating device in the visit network and a direct authentication from the home network to the mobile locating device, the target subscriber terminal at roaming state is allowed to implement the secure user plane location service. In the said authentication process, the authentication is implemented through a newly built communicational connection and without changing its own calling message of the mobile locating service.

Description

Be used for the wireless network user terminal is carried out the method and apparatus of secured user's aspect running fix
Technical field
The present invention relates to wireless communication technology, relate in particular to the technology of in cordless communication network, carrying out the running fix of secured user's aspect.
Background technology
Current, the mobile positioning technique based on portable terminal and secured user's aspect (SUPL) agreement is adopted in the running fix in wireless network more and more.In order to guarantee the confidence level of running fix, between the user terminal (SET) of supporting secured user's aspect and secured user's aspect mobile location service platform (SLP is hereinafter referred to as running fix equipment), need to authenticate mutually.
In existing secured user's aspect mobile positioning technique, generally authentication information is directly invested in the SUPL service call message, in verification process, need to change former SUPL service call message itself.Therefore, need on hardware, carry out bigger change to original moving positioning device.
In addition, in the prior art, when user terminal roams into a visit territory by home domain, when a running fix request occurring, home domain SLP (H-SLP) directly will send to this user terminal from the visit territory relevant information of visit territory SLP (V-SLP).User terminal to home domain SLP authenticate pass through after, promptly approve this visit territory relevant information, and carry out running fix by this visit territory relevant information.In whole process, user terminal does not authenticate visit territory SLP, thereby can not guarantee the confidence level of this running fix in user level.
The present invention proposes in order to solve the above-mentioned problems in the prior art just.
Summary of the invention
The purpose of this invention is to provide a kind of, be directed in the SUPL business under user terminal is in roaming condition, how SET authenticates the SLP of home domain with the visit territory, and do not need to change the solution that SUPL service call message itself realizes verification process.
According to a first aspect of the invention, a kind of method that a home domain target terminal user is carried out the running fix of secured user's aspect of being used in the home domain running fix equipment of wireless network is provided, described target terminal user belongs to the home domain at this running fix equipment place, and be in the visit territory outside the described home domain, this method may further comprise the steps: receive the visit territory relevant information from the running fix equipment in the described visit territory; Running fix equipment in the described visit territory is authenticated; If described authentication is passed through, described visit territory relevant information is sent to described target terminal user; Accept the authentication of described target terminal.
According to a second aspect of the invention, a kind of running fix equipment that is used for a user terminal is carried out the running fix of secured user's aspect in wireless network is provided, described user terminal belongs to the home domain at this running fix equipment place, and be in the visit territory outside the described home domain, comprise: a receiving system is used for receiving the visit territory relevant information from the running fix equipment that belongs to described visit territory; An authenticate device is used for coming the running fix equipment to described visit territory to authenticate; A dispensing device is used for, and when described authentication is passed through, described visit territory relevant information is sent to described target terminal user.
According to a third aspect of the invention we, a kind of method of being used to carry out the running fix of secured user's aspect in the user terminal of mobile location service supported in wireless network also is provided, described user terminal is in the visit territory outside the home domain, and this method may further comprise the steps: receive the visit territory relevant information from running fix equipment in the described home domain; Newly-built one or more communicating to connect between described user terminal and running fix equipment; Fetch by described newly-built communication link the running fix equipment in the described home domain is authenticated; If authentication is passed through, then use described visit territory relevant information to carry out running fix.
According to a forth aspect of the invention, a kind of user terminal that is used for the running fix of secured user's aspect in wireless network also is provided, described user terminal is arranged in the visit territory outside the home domain, it is characterized in that, comprise: a receiving system is used for receiving the message from the described visit territory relevant information of described home domain running fix equipment; One connects apparatus for establishing, is used for newly-built one or more communicating to connect between described user terminal and home domain running fix equipment; An authenticate device is used for authenticating by the running fix equipment that described newly-built communication link fetches described home domain; A positioner is used for utilizing described visit territory relevant information to carry out running fix when described authentication is passed through.
According to a fifth aspect of the invention, a kind of method that is used for a target terminal user is carried out the auxiliary moving location in the visit territory running fix equipment of wireless network also is provided, described target terminal user is just roamed in the described visit territory by its home domain, wherein, the root certificate authority in described visit territory is different with the root certificate authority of described home domain, said method comprising the steps of: send visit territory relevant information to the running fix equipment in the home domain of described target terminal user; Certificate that the described home domain root certificate authority that presets signs and issues to the visit territory root certificate authority running fix equipment to described home domain is provided, authenticates by the running fix equipment of cross-certification mechanism described visit territory in order to the running fix equipment of described home domain.
According to a sixth aspect of the invention, a kind of visit territory running fix equipment that is used for a target terminal user is carried out the auxiliary moving location at wireless network also is provided, described target terminal user is just roamed in the described visit territory by its home domain, comprise: a storage device is used for preserving visit territory relevant information; A dispensing device is used to send the running fix equipment of described visit territory relevant information to described home domain; It is characterized in that, when the root certificate authority of the root certificate authority in described visit territory and described home domain not simultaneously, described storage device also prestores described home domain root certificate authority and gives the visit territory certificate that root certificate authority is signed and issued; Described dispensing device also is used for the running fix equipment of giving described home domain for the visit territory certificate that root certificate authority is signed and issued described home domain root certificate authority, authenticates by the running fix equipment of cross-certification mechanism to described visit territory in order to the running fix equipment of described home domain.
Compared with prior art, the present invention can realize the mobile location service of secured user's aspect by the indirect authentication of SET to V-SLP under SET is in roaming condition; And in the verification process and H-SLP verification process to V-SLP of SET to H-SLP, fetch the realization authentication by newly-built communication link, need not to change the message related to calls of SUPL business itself, thereby can reduce change, realize the reduction of cost existing hardware device.
Description of drawings
Describe the present invention the identical parts of wherein same or analogous Reference numeral representative with reference to the accompanying drawings.
Fig. 1 is the wireless network schematic diagram of realizing safe aspect running fix under the roaming condition that is in terminal according to the present invention;
Fig. 2 is an embodiment according to the present invention, is used for a user terminal is carried out the flow chart of the method for secured user's aspect running fix in running fix equipment;
Fig. 3 is an embodiment according to the present invention, is used for a user terminal is carried out the block diagram of the running fix equipment of secured user's aspect running fix in wireless network;
Fig. 4 is an embodiment according to the present invention, supports to be used in the user terminal of mobile location service to carry out the flow chart of the method for secured user's aspect running fix in wireless network;
Fig. 5 is an embodiment according to the present invention, is used for the block diagram of the user terminal of secured user's aspect running fix in wireless network;
Fig. 6 is an embodiment according to the present invention, is used for a target terminal user is carried out the flow chart of the method for auxiliary moving location in the visit territory running fix equipment of wireless network;
Fig. 7 is an embodiment according to the present invention, at the block diagram that is used for a target terminal user is carried out the visit territory running fix equipment of auxiliary moving location of wireless network.
Embodiment
Below with reference to accompanying drawing, and in conjunction with specific embodiments the present invention is described in detail.Should be appreciated that the present invention is not limited to specific embodiment.
Fig. 1 is for being in the wireless network schematic diagram of realizing safe aspect running fix under the roaming condition according to of the present invention in terminal, comprising 1 a, user terminal 2 of a home domain SLP (H-SLP) and a visit territory SLP (V-SLP) 3.Wherein, user terminal 2 roams into the visit territory by its home domain.
When needs carry out running fix to user terminal 2, need the relevant information in its residing visit territory (such as address information etc.) be sent to user terminal 2 by the SLP 1 of home domain, user terminal 2 utilizes described visit territory relevant information to obtain positional information in the visit territory then.In order to guarantee that whole running fix process is believable in user level, user terminal 2 need authenticate V-SLP 3.For this purpose, can directly authenticate, directly authenticate by 2 couples of H-SLP 1 of user terminal again, thereby can realize the indirect authentication of 2 couples of V-SLP 3 of user terminal by 1 couple of V-SLP 3 of H-SLP.
Fig. 2 is an embodiment according to the present invention, is used for a user terminal is carried out the flow chart of the method for secured user's aspect running fix in home domain SLP (H-SLP is also referred to as running fix equipment) 1.Be in running fix roaming condition under because the present invention only relates to user terminal, suppose that therefore this user terminal is in one and visits in the territory.
In step S101, H-SLP receives a running fix request to user terminal in its home domain, and this running fix request can be initiated by this user terminal or other user terminals, is also initiated by network side.Enter step S102 subsequently.
In step S102, H-SLP receive from the SLP (V-SLP) in this user terminal visit of living in territory with the relevant information in visit territory.The described information relevant with the visit territory can be the address information in visit territory, or target terminal user is used in other information that running fix is carried out in the visit territory.At this moment, H-SLP can not determine whether this visit territory relevant information is credible, therefore need authenticate it.
In step S103, preferably, in order not change the call information of secured user's aspect mobile location service itself, H-SLP need be communicating to connect between verification process other newly-built one or more and the V-SLP.Should be appreciated that the present invention can newly-builtly communicate to connect, and by authentication information is invested in the running fix message related to calls to come V-SLP is authenticated.
Subsequently, in step S104, H-SLP fetches by newly-built communication link visit territory mobile device is authenticated.
In a preferred embodiment, if the root certificate at visit domain authentication center is identical with the root certificate of home domain authentication center, then H-SLP can utilize the root certificate that presets home domain authentication center that V-SLP 3 is authenticated.Otherwise V-SLP 3 need preset the root certificate authority in territory (home domain) under the H-SLP 1 and give the certificate that the root certificate authority in territories (visit territory) is signed and issued under the V-SLP 3.This certificate that H-SLP 1 utilizes V-SLP 3 to send over authenticates V-SLP 3 by cross-certification mechanism.
In step S105, judge whether authentication is passed through, also promptly whether credible from the information of V-SLP? if authentication is passed through, then enter step S106, otherwise whole running fix process finishes.
In step S106, H-SLP will send to described user terminal by the described visit territory relevant information of authentication, be used for running fix.
Fig. 3 is an embodiment according to the present invention, is used for a user terminal is carried out the block diagram of the home domain SLP (H-SLP is also referred to as running fix equipment) 1 of secured user's aspect running fix in wireless network.
H-SLP described here is defined as the SLP in the affiliated territory (home domain) of target terminal user, also promptly is used for the user terminal of its home domain is carried out the SLP of running fix.
Be in running fix roaming condition under because the present invention only relates to user terminal, suppose that therefore this user terminal is in one and visits in the territory.
As shown in FIG., H-SLP 1 comprises a receiving system 11, authenticate device 13, a dispensing device 14.
Receiving system 11 is used to receive a running fix request to described user terminal, and this running fix request can be initiated by this user terminal or other user terminals, is also initiated by network side.Subsequently, this receiving system 11 also be used for receiving from the SLP (V-SLP) in this user terminal visit of living in territory with the relevant information in visit territory.The described information relevant with the visit territory can be the address information in visit territory, or target terminal user is used in other information that running fix is carried out in the visit territory.At this moment, H-SLP can not determine whether this visit territory relevant information is credible, therefore need authenticate it.
Authenticate device 13 is used for V-SLP is authenticated, and wherein authentication information can be attached in the mobile location service message related to calls and transmit.
Preferably, H-SLP 1 also can comprise a storage device 15, wherein prestore the root certificate of the authentication center of home domain, with, if the root certificate at the root certificate of described home domain authentication center and visit domain authentication center is not simultaneously, V-SLP 3 prestores the root certificate authority in territory (home domain) under the H-SLP 1 and gives the certificate that the root certificate authority in territories (visit territory) is signed and issued under the V-SLP 3;
If the root certificate at visit domain authentication center is identical with the root certificate of home domain authentication center, then described authenticate device 13 can utilize the root certificate of the home domain authentication center that prestores in the storage device 15 that V-SLP is authenticated.Otherwise the home domain root certificate authority that authenticate device 13 can need to utilize V-SLP 3 to send over is given the visit territory certificate that root certificate authority is signed and issued, and utilizes this certificate by cross-certification mechanism V-SLP to be authenticated.
In a preferred embodiment, in order not change the mobile location service message related to calls, can set up one or more new traffic separately for verification process and connect, therefore, SLP 1 comprises that also one connects apparatus for establishing 12, is used for newly-built one or more communicating to connect between H-SLP and V-SLP.Then, authenticate device 13 is used for fetching by described newly-built communication link V-SLP is authenticated.
If the authentication of 13 couples of V-SLP of authenticate device is passed through, confirm promptly that also the information from V-SLP is credible, then notify dispensing device 14.Dispensing device 14 is used for described visit territory relevant information is sent to described target terminal.
Fig. 4 is an embodiment according to the present invention, supports to be used in the user terminal of mobile location service to carry out the flow chart of the method for secured user's aspect running fix in wireless network.Be in running fix roaming condition under because the present invention only relates to user terminal, suppose that therefore this user terminal is in one and visits in the territory.
In step S201, user terminal 2 receive the SLP (H-SLP is also referred to as home domain running fix equipment) that comes from its home domain with its relevant information in visit of living in territory.The described information relevant with the visit territory can be the address information in visit territory, or target terminal user is used in other information that running fix is carried out in the visit territory.But user terminal 2 can not determine whether this H-SLP 1 is credible, therefore need authenticate it.
In the prior art, when 1 couple of H-SLP of user terminal authenticates, be that authentication information is attached in the mobile location service message related to calls, this will change message related to calls itself, thereby bring the bigger change of hardware.Therefore, in the present invention, user terminal 1 will be specially for verification process set up one or more and H-SLP between new communicating to connect, also promptly enter step S202.
In step S202, user terminal 2 newly-built one or more communicating to connect between described user terminal and H-SLP.Enter step S203 subsequently.
In step S203, user terminal 2 fetches by described newly-built communication link described H-SLP is authenticated.
In a preferred embodiment, user terminal 2 can utilize the root certificate of the home domain authentication center of wherein presetting, and comes to come H-SLP is authenticated by Transport Layer Security (TLS) agreement.
In step S204, judge whether authentication is passed through, also be whether described H-SLP credible? if authentication is passed through, then enter step S205, otherwise the running fix process finishes.
In step S205, user terminal 2 utilizes by the described visit territory relevant information of authentication and carries out further running fix.
Fig. 5 is an embodiment according to the present invention, is used for the block diagram of the user terminal of secured user's aspect running fix in wireless network.Be in running fix roaming condition under because the present invention only relates to user terminal, suppose that therefore this user terminal is in one and visits in the territory.
As shown in FIG., user terminal 2 comprises that a receiving system 21, one connect apparatus for establishing 22, one second authenticate device 23, a positioner 24.
Described receiving system 21 be used to receive from H-SLP with its relevant information in visit of living in territory.The described information relevant with the visit territory can be the address information in visit territory, or target terminal user is used in other information that running fix is carried out in the visit territory.At this moment, but user terminal 2 can not determine whether this H-SLP 1 is credible, therefore need authenticate it.
Unlike the prior art, in order not change mobile location service message related to calls itself, need communicate to connect for verification process newly-built one or more.
Described connection apparatus for establishing 22 is used for newly-built one or more communicating to connect between described user terminal 2 and H-SLP 1.
Described authenticate device 23 is used for authenticating by the running fix equipment that described newly-built communication link fetches described home domain.
In a preferred embodiment, user terminal 2 also comprises a storage device 25, is used to prestore the root certificate of its home domain authentication center.Described authenticate device 23 is used to utilize the root certificate of described home domain authentication center, comes by Transport Layer Security (TLS) agreement the running fix equipment in the described home domain to be authenticated.
If the authentication of 23 couples of H-SLP of authenticate device is passed through, confirm promptly that also the information from H-SLP is believable, then notify positioner 24.Positioner 24 will utilize described visit territory relevant information to carry out further running fix.
Fig. 6 is embodiment according to the present invention, at the visit territory of wireless network SLP (V-SLP, hereinafter to be referred as running fix equipment) be used for a target terminal user 2 is carried out the flow chart of the method for auxiliary moving location in 3. because only relating to user terminal 2, the present invention is in running fix under the roaming condition, therefore suppose that this user terminal 2 is just roamed in the visit territory by its home domain. and suppose that the root certificate authority in described visit territory is different with the root certificate authority of described home domain, give the visit territory certificate that root certificate authority is signed and issued and preset described home domain root certificate authority in the running fix equipment in visit territory.
In step S301, V-SLP 3 will visit the territory relevant information and give H-SLP;
Subsequently, in step 302, V-SLP 3 sends to H-SLP 1 for the visit territory certificate that root certificate authority is signed and issued the described home domain root certificate authority that presets.H-SLP 1 will utilize the described home domain root certificate authority that is sended over by V-SLP 3 to give the root certificate of the home domain authentication center that visit territory certificate that root certificate authority is signed and issued and H-SLP 1 preset, and come by cross-certification mechanism described V-SLP to be authenticated.
Fig. 7 is an embodiment according to the present invention, at the block diagram that is used for a target terminal user is carried out the visit territory SLP (V-SLP is hereinafter to be referred as running fix equipment) 3 of auxiliary moving location of wireless network.Be in running fix roaming condition under because the present invention only relates to user terminal 2, suppose therefore that this user terminal 2 is just being roamed into by its home domain to visit in the territory.
As shown in FIG., V-SLP 3 comprises a storage device 31 and a dispensing device 32.
Described storage device 31 is used for preserving visit territory relevant information, also needs to preset the home domain root certificate authority and gives the visit territory certificate that root certificate authority is signed and issued.
Described dispensing device 32 is used to send described visit territory relevant information to H-SLP 1.
Further the root certificate authority in the described visit of supposition territory is different with the root certificate authority of described home domain, so also prestores the certificate that the root certificate authority in territory (home domain) signs and issues for the root certificate authority in V-SLP 3 affiliated territories (visit territory) under the H-SLP 1 in the storage device 31.
And described dispensing device 32 also is used for giving H-SLP 1 for the visit territory certificate that root certificate authority is signed and issued described home domain root certificate authority.H-SLP 1 will utilize described home domain root certificate authority give the visit territory certificate that root certificate authority is signed and issued with and the root certificate of the home domain authentication center of presetting, come described V-SLP to be authenticated by cross-certification mechanism.
After user terminal 2 successfully authenticates H-SLP 1, H-SLP will set up one or more and communicate to connect authenticated user terminal 2.Authentication mechanism can be PSK-TLS, also can be other modes, and this paper does not do discussion.So just can satisfy the safety requirements of user level positioning service, promptly in target terminal user 2 and (V/H) carry out two-way authentication between the SLP.
More than specific embodiments of the invention are described.Need to understand being, the present invention is not limited to above-mentioned specific for execution mode, and those skilled in the art can make various distortion or modification within the scope of the appended claims.

Claims (14)

1. one kind is used for method that a home domain target terminal user is carried out the running fix of secured user's aspect in the home domain running fix equipment of wireless network, described target terminal user belongs to the home domain at this running fix equipment place, and be in the visit territory outside the described home domain, this method may further comprise the steps:
Reception is from the visit territory relevant information of the running fix equipment in the described visit territory;
Running fix equipment in the described visit territory is authenticated;
If described authentication is passed through, described visit territory relevant information is sent to described target terminal user;
Accept the authentication of described target terminal.
2. method according to claim 1 is characterized in that, the described step that running fix equipment in the described visit territory is authenticated comprises:
The root certificate of the home domain authentication center that utilization is preset comes by Transport Layer Security the running fix equipment in the described visit territory to be authenticated.
3. method according to claim 1 is characterized in that, the described step that running fix equipment in the described visit territory is authenticated comprises:
If the root certificate of described home domain authentication center is different with the root certificate at visit domain authentication center, the home domain authentication center that then utilizes the root certificate of described home domain authentication center and preset in the running fix equipment in described visit territory gives the visit domain authentication certificate that sign and issue at the center, comes to authenticate by the running fix equipment of cross-certification mechanism to described visit territory.
4. according to each described method among the claim 1-3, it is characterized in that,
The described step that running fix equipment in the described visit territory is authenticated comprises:
Setting up one or more is connected with new traffic between the visit territory running fix equipment at home domain running fix equipment;
Connect to come by described new traffic described visit territory running fix equipment is authenticated.
5. running fix equipment that in wireless network, is used for a user terminal is carried out the running fix of secured user's aspect, described user terminal belongs to the home domain at this running fix equipment place, and be in the visit territory outside the described home domain, comprise:
A receiving system is used for receiving the visit territory relevant information from the running fix equipment that belongs to described visit territory;
An authenticate device is used for coming the running fix equipment to described visit territory to authenticate;
A dispensing device is used for, and when described authentication is passed through, described visit territory relevant information is sent to described target terminal user.
6. running fix equipment according to claim 5 is characterized in that, also comprises
A storage device wherein prestores the root certificate of the authentication center of home domain,
Wherein, described authenticate device is used to utilize the root certificate of the home domain authentication center of presetting, and comes by Transport Layer Security the running fix equipment in the described visit territory to be authenticated.
7. running fix equipment according to claim 5 is characterized in that, also comprises
A storage device wherein prestores the root certificate of the authentication center of home domain,
Wherein, if the root certificate at the root certificate of described home domain authentication center and visit domain authentication center is not simultaneously, then described authenticate device utilizes the root certificate of described home domain authentication center and the home domain authentication center of presetting in the running fix equipment in described visit territory gives the visit domain authentication certificate that sign and issue at the center, comes to authenticate by the running fix equipment of cross-certification mechanism to described visit territory.
8. according to each described running fix equipment among the claim 5-7, it is characterized in that, also comprise
One connects apparatus for establishing, is used for newly-built one or more communicating to connect between described home domain running fix equipment and visit territory running fix equipment;
Described authenticate device is used for fetching by described newly-built communication link described visit territory running fix equipment is authenticated.
9. support the method that is used to carry out the running fix of secured user's aspect in the user terminal of mobile location service, described user terminal to be in the visit territory outside the home domain in wireless network for one kind, this method may further comprise the steps:
Reception is from the visit territory relevant information of running fix equipment in the described home domain;
Newly-built one or more communicating to connect between described user terminal and running fix equipment;
Fetch by described newly-built communication link the running fix equipment in the described home domain is authenticated;
If authentication is passed through, then use described visit territory relevant information to carry out running fix.
10. method according to claim 9 is characterized in that, the described step that running fix equipment in the described home domain is authenticated comprises:
Utilize the root certificate of the home domain authentication center of presetting in the described user terminal, come the running fix equipment in the described home domain to be authenticated by Transport Layer Security.
11. a user terminal that is used for the running fix of secured user's aspect in wireless network, described user terminal are arranged in the visit territory outside the home domain, it is characterized in that, comprising:
A receiving system is used for receiving the message from the described visit territory relevant information of described home domain running fix equipment;
One connects apparatus for establishing, is used for newly-built one or more communicating to connect between described user terminal and home domain running fix equipment;
An authenticate device is used for authenticating by the running fix equipment that described newly-built communication link fetches described home domain;
A positioner is used for utilizing described visit territory relevant information to carry out running fix when described authentication is passed through.
12. user terminal according to claim 11 is characterized in that, also comprises
A storage device is used to prestore the root certificate of its home domain authentication center;
Wherein, described authenticate device is used to utilize the root certificate of described home domain authentication center, comes by Transport Layer Security the running fix equipment in the described home domain to be authenticated.
13. method that in the visit territory running fix equipment of wireless network, is used for a target terminal user is carried out the auxiliary moving location, described target terminal user is just roamed in the described visit territory by its home domain, wherein, the root certificate authority in described visit territory is different with the root certificate authority of described home domain, said method comprising the steps of:
Send visit territory relevant information to the running fix equipment in the home domain of described target terminal user;
Certificate that the described home domain root certificate authority that presets signs and issues to the visit territory root certificate authority running fix equipment to described home domain is provided.
14. the visit territory running fix equipment that is used for a target terminal user is carried out the auxiliary moving location at wireless network, described target terminal user is just roamed in the described visit territory by its home domain, comprising:
A storage device is used for preserving visit territory relevant information;
A dispensing device is used to send the running fix equipment of described visit territory relevant information to described home domain;
It is characterized in that,
When the root certificate authority of the root certificate authority in described visit territory and described home domain not simultaneously, described storage device also prestores described home domain root certificate authority and gives the visit territory certificate that root certificate authority is signed and issued;
Described dispensing device also is used for giving the running fix equipment of described home domain for the visit territory certificate that root certificate authority is signed and issued described home domain root certificate authority.
CN200510024369A 2005-03-14 2005-03-14 Method and device for security user's layer mobile positioning in radio network Active CN1835621B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200510024369A CN1835621B (en) 2005-03-14 2005-03-14 Method and device for security user's layer mobile positioning in radio network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200510024369A CN1835621B (en) 2005-03-14 2005-03-14 Method and device for security user's layer mobile positioning in radio network

Publications (2)

Publication Number Publication Date
CN1835621A CN1835621A (en) 2006-09-20
CN1835621B true CN1835621B (en) 2010-05-12

Family

ID=37003188

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200510024369A Active CN1835621B (en) 2005-03-14 2005-03-14 Method and device for security user's layer mobile positioning in radio network

Country Status (1)

Country Link
CN (1) CN1835621B (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2103077B1 (en) * 2007-01-04 2011-03-09 Telefonaktiebolaget LM Ericsson (publ) Method and apparatus for determining an authentication procedure
CN104902566B (en) * 2015-06-10 2019-06-11 北京讯腾智慧科技股份有限公司 In a kind of high-iron carriage under wireless aps redundant configuration terminal device mobile location method and system

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1479494A (en) * 2002-08-31 2004-03-03 深圳市中兴通讯股份有限公司上海第二 System of interconnecting CDMA system and radiolocal network

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1479494A (en) * 2002-08-31 2004-03-03 深圳市中兴通讯股份有限公司上海第二 System of interconnecting CDMA system and radiolocal network

Also Published As

Publication number Publication date
CN1835621A (en) 2006-09-20

Similar Documents

Publication Publication Date Title
US8838148B2 (en) Location based wireless tower caching
CN102572689B (en) Mobile terminal location system and method
WO2014180324A1 (en) Method and relevant apparatus for implementing national roaming of mobile terminal
US8300605B2 (en) General access network controller bypass to facilitate use of standard cellular handsets with a general access network
CN104768155B (en) LTE cellular mobile network access system and corresponding communication method
TW201347491A (en) Direct mode communication system and communication attaching method thereof
CN104023328A (en) Operator mobile cellular network access system and corresponding communication method
CN101227710A (en) Equipment and method for synchronizing locating trigger information
US20070188298A1 (en) Establishing secure tunnels for using standard cellular handsets with a general access network
US7471953B2 (en) Location services for unlicensed mobile access
US20140171090A1 (en) Using Standard Cellular Handsets with a General Access Network
JP5130382B2 (en) POSITIONING SYSTEM, POSITION INFORMATION PROVIDING DEVICE, POSITION INFORMATION MANAGEMENT DEVICE, AND POSITIONING METHOD
CN110740489A (en) 5G network communication control method, device and communication system
CN101217570A (en) A third party remoistening method and realization system
CA2796852C (en) Region access platform, mobile positioning method and system
US20100273451A1 (en) Method and Apparatus for Mobile Terminal Positioning Operations
CN1835621B (en) Method and device for security user's layer mobile positioning in radio network
CN109936840A (en) Communication means, device and electronic equipment
CN100372441C (en) Mobile terminal positioning method
CN105379320A (en) Method of and system for enacting digital communication for mobile subscriber
CN107786937A (en) Implementation method, mobile terminal and the roam server of mobile terminal localized roaming
CN104735749A (en) Network accessing method, wireless router, and portal platform server
CN110636501B (en) Mobile position information hiding method and system
CN106331999A (en) Method for locating AGPS mobile phone in mobile communication network
JP3889639B2 (en) Server apparatus and information communication method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C56 Change in the name or address of the patentee

Owner name: SHANGHAI ALCATEL-LUCENT CO., LTD.

Free format text: FORMER NAME: BEIER AERKATE CO., LTD., SHANGHAI

CP01 Change in the name or title of a patent holder
CP01 Change in the name or title of a patent holder

Address after: 201206 Pudong Jinqiao Export Processing Zone, Nanjing Road, No. 388, Shanghai

Patentee after: Shanghai Alcatel-Lucent Co., Ltd.

Patentee after: China Mobile Communication Group Co., Ltd.

Address before: 201206 Pudong Jinqiao Export Processing Zone, Nanjing Road, No. 388, Shanghai

Patentee before: Beier Aerkate Co., Ltd., Shanghai

Patentee before: China Mobile Communication Group Co., Ltd.

CP01 Change in the name or title of a patent holder
CP01 Change in the name or title of a patent holder

Address after: 201206 Pudong Jinqiao Export Processing Zone, Nanjing Road, No. 388, Shanghai

Co-patentee after: China Mobile Communication Group Co., Ltd.

Patentee after: Shanghai NOKIA Baer Limited by Share Ltd

Address before: 201206 Pudong Jinqiao Export Processing Zone, Nanjing Road, No. 388, Shanghai

Co-patentee before: China Mobile Communication Group Co., Ltd.

Patentee before: Shanghai Alcatel-Lucent Co., Ltd.