EP1856936A1 - Communications method and system - Google Patents
Communications method and systemInfo
- Publication number
- EP1856936A1 EP1856936A1 EP05744773A EP05744773A EP1856936A1 EP 1856936 A1 EP1856936 A1 EP 1856936A1 EP 05744773 A EP05744773 A EP 05744773A EP 05744773 A EP05744773 A EP 05744773A EP 1856936 A1 EP1856936 A1 EP 1856936A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- communications
- identity data
- data
- entity
- communications device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
Definitions
- the present invention generally relates to ' communications methods and communications systems and in particular to a method and system for operating a communications device in at least to two different communications environments.
- Mobile communications particularly in the field of mobile telephone communications, is well known.
- mobile communications are limited to a home communications environment of a communications device, e.g. in a geographical area in which a user of the communications device lives.
- a communications de- vice in different communications environments such that, for example, the communications device can be moved from a geographical area serviced by a telephone network to a geographical area serviced by another telephone network (e.g. telephone networks in different countries and/or different telephone networks in the same country) .
- this capability is also referred to as "roaming" .
- this is com- monly accomplished by storing, in the Home Locations Registers HLRs of the involved communications environments, data indicating that a particular communications device may be operated in the respective communications environment.
- the HLRs store an International Mobile Subscriber Identity IMSI of the communications device to be operated in the communications environments.
- the concerned communications environment proofs whether the IMSI received from the communications device is stored in its HLR. If the stored IMSI and the received IMSI correspond, the communications device is allowed to communicate in the communications environment. If the stored IMSI and the received IMSI do not correspond, communications by this communications device in the communications environment is denied.
- a reason for such restrictions is, for example, the way communications to and from a communications device operated outside its home communications environment are routed, the manner a communications device outside its home communications environment is identified and addressed, and how administrative and managing processes (e.g. billing procedures) are designed.
- the present invention provides a method for operating a communications device, which has first identity data associated to a first communications environment, in at least one further communications environment, which method comprises the steps of communicating, from the communications device to a central entity, a request to operate the communications device in a second communications environment, communicating, from the central entity to the communications device in response to the request, second identity data associated to the second communications environment, and storing, by the communications device upon receipt of the second identity data, the second identity data.
- the present invention provides a system comprising a first communications environment, a communications device, which has first identity data associated to the first communications environment, a second communications environment to which second identity data is associated, and a central entity, wherein the central entity is adapted to communicate, upon a request from the communications device to operate the communications device in the second communications environment, the second identity data to the communications device, and the communications device is adapted to store the second identity data.
- the present invention provides a software program including software program portions for carrying out the method steps according to the present invention.
- the present invention provides a communications device being adapted to carry out the method steps according to the present invention.
- the present invention provides a central entity being adapted to carry out the method steps according to the present invention.
- the present invention provides a communications environment being adapted to carry out the method steps according to the present invention.
- Figs. 1 to 7 show preferred embodiments of the present in- vention.
- the communications device may be a mobile communications device
- the first and second communications environments may be mobile telephone environments
- the central entity may be an en- tity providing roaming services for the communications device in the first and second communications environments.
- Examples for a communications device include mobile telephones (e.g. GSM and UMTS devices) , mobile computing devices having communications capabilities and the like.
- mobile telephones e.g. GSM and UMTS devices
- mobile computing devices having communications capabilities and the like.
- Examples for a communications environment include mobile telephone environ- ments (e.g. GSM and UMTS networks) , communications systems including wireless and wired communications links (e.g. radio and terrestrial communications networks optionally including the Internet) and the like.
- mobile telephone environ- ments e.g. GSM and UMTS networks
- communications systems including wireless and wired communications links (e.g. radio and terrestrial communications networks optionally including the Internet) and the like.
- Examples for a central entity which can be used in the pre- sent invention, include a communications network interconnecting the first communications environment and second communications environment, a communications server, a telephone switch and the like.
- the request may be communicated from the communications device to an identity data providing entity and from the identity data providing entity to the central entity.
- the central entity upon receipt of the request, may retrieve a first part of the second identity data.
- the first part of the second identity data may be stored in association to the central entity and the identity data providing entity such the central entity and the identity data providing entity have access to the first part of the second identity data.
- Examples for such a storage include to store the first part of the second identity data in a first storage means to which the central entity is connected via at least one of a wired communications link and a wireless communications link and a second storage means to which the identity data providing entity is connected via at least one of a wired communications link and a wireless communications link, or in a storage means to which both the central entity and the identity data providing entity are connected via at least one of a wired communications link and a wireless communications link.
- the identity data providing entity upon receipt of the request, may retrieve a second part of the second identity data.
- the second part of the second identity data may be stored in association to the identity data providing entity only such the identity data providing entity has access to the second part of the second identity data, while access to the second part of the second identity data by the central entity is de- nied.
- Examples for such a storage include to store the second part of the second identity data in a storage unit to which only the identity data providing entity is connected via at least one of a wired communications link and a wireless communica- tions link, while the no communications link between the central entity and the storage unit is allowed.
- the central entity may communicate the first part of the second identity data to the identity data providing entity.
- the identity data providing entity may communicate the first part of the second identity data and the second part of the second identity data to the communications device.
- the first part of the second identity data may be an International Mobile Subscriber Identity IMSI for a mobile communications environment, and the second part of the second identity data may be a Ki key for a mobile communications environment.
- At least one of the first part of the second identity data and the second part of the second identity data may be encoded by the identity data providing entity before being communicated to the communications device.
- the at least one encoding step may be carried out by using a general encoding key.
- At least one of the first part of the second identity data and the second part of the second identity data may be decoded by the Communications device upon receipt.
- the at least one decoding step may be carried out by using a general decoding key.
- the general decoding key may be previously stored in the communications device under control of the identity data provid- ing entity. This can be for example accomplished by the identity data providing entity before the communications device is provided to a user, e.g. during a manufacturing process of the communications device.
- Communicating by means of the communications device in the first communications environment may include a step of identifying the communications device in the first communications environment by means of the first identity data.
- the identifying step may include operating the communications device such that the first identity data is defined as valid identity data.
- the first identity data may be communicated from the communications device to a first communications system in the first communications environment.
- the identifying step may include communicating first communi- cations request data to the central entity.
- Examples for the first communications request data include data indicating that the communications device is now to be operated in the first communications environment.
- the first communications request data may be communicated di- rectly from the communications device or via a first communi- cations system in the first communications environment to the central entity upon receipt of the first identity data by the first communications system.
- Examples for a communications system useable as first communi- cations system in the present invention include a provider or operator of the first communications environment and respective components and units, respectively, a telephone switch, a GSM switch, an UMTS switch and the like.
- the central entity may communicate erasing data to the commu- nications device in response to the first communications request data, wherein the erasing data effects removing the second identity data from the communications device.
- the erasing step may include communicating an empty identity data template replacing the stored second identity data.
- the second identity data may be marked as invalid identity data.
- the marking step may be carried out by a second communications system in the second communications environment upon receipt of a marking request communicated from the central entity to the second communications environment in response to the first communications request data.
- Examples for a communications system useable as second communications system in the present invention include a provider or operator of the first communications environment and respective components and unit, respectively, a telephone switch, a GSM switch, an UMTS switch and the like.
- the re- quest may be communicated from the communications device being operated in the first communications environment to the central entity.
- the second identity data may be then communicated from the central entity to the communications device in the first com- munications environment.
- Communications from the communications device to the central entity may be carried out via a first communications system in the first communications environment, while communications from the central entity to the communications device may be carried out via an identity data providing entity, at least as regards the communications related to the second identity data.
- Communicating by means of the communications device in the second communications environment may include a step of identifying the communications device in the second communications environment by means of the second identity data.
- the identifying step may include operating the communications device such that the second identity data is defined as valid identity data.
- the second identity data may be communicated from the communi- cations device to a second communications system in the second communications environment.
- the identifying step may include communicating second communications request data to the central entity.
- Examples for the second communications request data include data indicating that the communications device is now to be operated in the second communications environment .
- the second communications request data may be communicated from a second communications system in the second communications environment to the central entity.
- the second communications request data may be communicated from the communications device being operated in the second communications environment directly to the central entity.
- the central entity may communicate, in response to the second communications request, a identity data transfer request to a first communications system in the first communications environment, and the first communications system may then route communications, which are to be carried out with the communications device and including first identifying data for iden- tifying the communications device in the first communications environment, to the central entity.
- Examples for data to be used as first identifying data include data identifying the communications device as such (e.g. a Mobile Subscriber ISDN Number MSISDN, a Mobile Subscriber Iden- tification Number MSIN, International Mobile Subscriber Identity IMSI) , a telephone number of the communications device, an Internet address of the communications device, a communications link via which the communications device can receive communications, a CLIP (Calling Line Identification Presenta- tion) and the like.
- the central entity may replace, in the communications routed to the central entity, the first identifying data by second identifying data for identifying the communications device in the second communications environment, and the communications to be carried out with the communications device and now having the second identifying data can be routed to the communications device in the second communications environment.
- Examples for data to be used as second identifying data include data identifying the communications device as such (e.g. a Mobile Subscriber ISDN Number MSISDN, a Mobile Subscriber
- Communications to and from the communications device in the second communications environment may be routed via the cen- tral entity, preferably at least partially routed via an SS7/C7 voice link.
- Communications from the communications device to be carried out in the second communications environment may include second identifying data for identifying the communications device in the second communications environment, wherein the central entity may replace the second identifying data by first identifying data for identifying the communications device in the second communications environment, and wherein the central entity may route the communications from the communications de- vice and now including the first identifying data to a communications target in the second communications environment with which the communications from the communications device are to be carried out.
- identifying data apply to this embodiment also. Examples for a communications target in- elude communications devices comparable to the above mentioned communications device.
- Communications from the communications device to be carried out in a communications environment outside the second communications environment may include second identifying data for identifying the communications device in the second communications environment, wherein the central entity may replace the second identifying data by first identifying data for identifying the communications device in the first communications environment, and wherein the central entity may route the com- munications from the communications device and now including the first identifying data to the communications environment outside the second communications environment in which the communications from the communications device are to be carried out .
- Communications to the communications device to be carried out in the second communications environment may include first identifying data for identifying the communications device in the first communications environment, wherein the central en- tity may replace the first identifying data by second identifying data for identifying the communications device in the second communications environment, and wherein the central entity may route the communications now including the second identifying data to the communications device.
- the central entity in response to the second communications request data, may transfer communications allowance data indicating that the communications device is allowed to communicate from a first communications allowance data providing entity associated to the first communications environment to a central communications allowance data providing entity associated to the central entity.
- the central entity in response to the second communications request data, may transfer communications allowance data indicating that the communications device is allowed to communi- cate from a first communications allowance data providing entity associated to the first communications environment to a second communications allowance data providing entity associated to the second communications environment.
- Examples for communications allowance data include data repre- senting an account associated to the communications device, a balance associated to the communications device, data obtained from a prepaid communications card and the like.
- Examples for communications allowance data providing entities include billing platforms, units, clearing centers and the like respectively associated to the first communications environment, the second communications environment and the central entity.
- the second identity data is preferably selected from a plurality of identity data reserved to be used as second identity data for carrying out the method.
- Communicating by means of the communications device may in- elude operating the communications device in a second identity data request mode under control of a software program associated to the communications device.
- Storing the second identity data in the communications device may include operating the communications device in a second identity data storing mode under control of a software program associated to the communications device.
- the communications device is adapted to store the first identity data and a plurality of second identity data.
- the second identity data may be communicated from the central entity to the communications device by means of at least one of a SMS, a MMS, an e-mail and a WAP link.
- Communications to and from the communications device may include at least one of voice communications, SMS communications, MMS communications, e-mail communications and data communica- tions.
- the communications device may be a mobile communications device
- the first and second communications environments may be mobile telephone environments
- the central entity may be an entity providing roaming services for the communications device in the first and second communications environments.
- the system may further comprise an identity data providing en- tity and wherein the request may be communicated from the com- munications device to the identity data providing entity and from the identity data providing entity to the central entity.
- the system may further include at least one first storage entity in which a first part of the second identity data is stored such that access to the first part of the second identity data by the central entity and the identity data providing entity is allowed and wherein the central entity, upon receipt of the request, may retrieve the first part of the second identity data from the at least one first storage entity and may communicate the second part of the second identity data to the identity data providing entity.
- the system may further include a second storage entity in which a second part of the second identity data is stored such that access to the second part of the second identity data by the identity data providing entity is allowed and access to the second part of the second identity data by the central entity is denied and wherein the identity data providing entity, upon receipt of the request , may retrieve the second part of the second identity data from the second storage entity.
- the identity data providing entity may communicate the first part of the second identity data and the second part of the second identity data to the communications device.
- the first part of the second identity data may be an International Mobile Subscriber Identity IMSI for a mobile communica- tions environment, and the second part of the second identity data may be a Ki key for a mobile communications environment.
- the identity data providing entity may comprise an encoding unit for encoding at least one of the first part of the second identity data and the second part of the second identity data before being communicated to the communications device.
- the encoding unit may comprise a general encoding key.
- the Communications device may comprise a decoding unit for decoding at least one of the first part of the second identity data and the second part of the second identity data.
- the decoding unit may comprise a general decoding key.
- the system may further comprise a first communications system in the first communications environment .
- the system may further comprise a first voice communications link between the first communications system and the central entity.
- the system may further comprise a second communications system in the second communications environment.
- the system may further comprise a second voice communications link between the second communications system and the central entity.
- At least one of the first communications link and the second communications link is an SS7/C7 voice link.
- the system may further comprise a first communications allowance data providing entity associated to the first communications environment .
- the system may further comprise a second communications allowance data providing entity associated to the second communications environment .
- the system may further comprise a central communications allowance data providing entity associated to the central entity.
- the system may further comprise at least one secured data link between at least two of the communications allowance data providing entities.
- at least one of the at least one secured data link is at least one of a n x 64 Kbps data link and a tunneling Internet connection.
- the system is adapted to be operated according to the method steps according to the present invention.
- the present invention contemplates communications in three, four up to a plurality of communications environments.
- the present invention is not limited to telephone communications. Rather, the present invention can be used in any communications scenario wherein a communications device, which may communicate in a communications environment, is not (automatically) allowed to communicate in another communications environment.
- the present invention envisages scenarios wherein a computing device having communications capabilities (i.e. a communications device) may access a computer network or computer network area (i.e. a communica- tions environment) , while access to a different computer network or computer network area would be denied if the present invention is not used.
- communications environments envisaged by the present invention can be based on any type o 2nd and 3rd generation communications environments.
- Fig. 1 illustrates a first communications environment 2.
- the first communications environment 2 comprises a first mobile telephone network 4 serviced by first base stations of which a single first base station 6 is shown as representative example .
- the first communications environment 2 further comprises a first switching unit 8 and a first communications allowance data providing entity including a first billing server 10.
- the first communications allowance data providing entity includes a first prepaid platform 12 serving as billing unit in relation to users of the first communications environment 2 utilizing prepaid communications services (e.g. utiliz- ing a mobile telephone using prepaid cards) .
- Fig. 1 shows the first communications allowance data providing entity as integral part of the first communications environment 2, the present invention contemplates that the first communications allowance data providing entity is at least associated the first communications environment 2.
- the first communications environment 2 further comprises at least a communications connection 14 (e.g. a SS7 link) to a first non-mobile telephone network 16 (e.g. public switching telephone network) , which may be a part of the first communi- cations environment 2 also.
- a communications connection 14 e.g. a SS7 link
- a first non-mobile telephone network 16 e.g. public switching telephone network
- the first switching unit 8 is coupled with the first base stations 6 for routing communications to and from the first mobile telephone network 4 from and to, respectively, first non- mobile telephone network 16 and, and as set forth below, from and to, respectively, further communications environments.
- Billing of communications within the first mobile telephone network 4 and between the first mobile telephone network 4 and other communications networks is accomplished by the first billing server 10.
- the first billing server 10 is coupled with the first base stations 6.
- a communications connection 18 (e.g. a n x 64 Kbps secured link) is used.
- a communications connection 20 (e.g. a n x El SS7/C7 voice link) is used.
- Communications devices in form of mobile telephones can communicate in the first mobile telephone network 4 with each other and can communicate via the first mobile telephone network 4 with communications device not serviced in the first mobile telephone network 4.
- communications devices 22 may communicate with the first non-mobile telephone network 16 and/or via communications connection 20.
- Fig. 1 further illustrates a second communications environment 24.
- the second communications environment 24 comprises a second mobile telephone network 26 serviced by second base stations of which a single second base station 28 is shown as represen- tative example.
- the second communications environment 24 further comprises a second switching unit 30 and a second communications allowance data providing entity including a second billing server 32.
- the second communications allowance data providing entity includes a second prepaid platform 34 serving as billing unit in relation to users of the second communications environment 24 utilizing prepaid communications services (e.g. utilizing a mobile telephone using prepaid cards) .
- Fig. 1 shows the second communications allowance data provid- ing entity as integral part of the second communications environment 24, the present invention contemplates that the second communications allowance data providing entity is at least associated the second communications environment 24.
- the second communications environment 24 further comprises at least a communications connection 36 (e.g. a SS7 link) to a second non-mobile telephone network 38 (e.g. public switching telephone network) , which may be a part of the second communications environment 24 also.
- the second switching unit 30 is coupled with the second base stations 28 for routing communications to and from the second mobile telephone network 26 from and to, respectively, the second non-mobile telephone network 38 and, and as set forth below, from and to, respectively, further communications environments .
- Billing of communications within the second mobile telephone network 26 and between the second mobile telephone network 26 and other communications networks is accomplished by the sec- ond billing server 32.
- the second billing server 32 is coupled with the second base stations 28.
- a communications connection 40 (e.g. a n x 64 Kbps secured link) is used.
- a communications connection 42 (e.g. a n x El SS7/C7 voice link) is used.
- Communications devices in form of mobile telephones can communicate in the second mobile telephone network 26 with each other and can communicate via the second mobile telephone network 38 with communications device not serviced in the second mobile telephone network 26.
- communications devices 44 may communicate with the second non- mobile telephone network 38 and/or via communications connection 42.
- Fig. 1 further illustrates a central entity 46.
- the central entity 46 comprises a central network 48 coupled with the first communications environment 2 via communications connection 20 and coupled with the second communications environment 24 via communications connection 42.
- the central entity 46 comprises a central switching unit 50 and a central billing server 52 serving as central communica- tions allowance data providing entity.
- a communications allowance data providing entity which is associated (i.e. is no integral part of the central entity 46) can be used.
- the central entity 46 further comprises a database 54 and, connected with the database 54, an SMS center 56, both of which will be described in greater detail below.
- the central billing server 52 For communications with the first billing server 12 and the second billing server 32 and, if applicable, with the first prepaid platform 12 and the second prepaid platform 34, the central billing server 52 is connected to communications connection 18 and communications connection 40, respectively.
- the central entity 46 utilizes the central billing server 52 to store CRDs information, to manage balances and financial transactions as regards communications devices and their subscribers, respectively, using the present invention.
- the central entity 46 utilizes the central database 54 to store identity data in a from described below and telephone numbers of communications devices and their subscribers, respectively, using the present invention in order to ensure a proper identification thereof. Still in this context, the central entity 46 utilizes the SMS center 56 for SMS communications with communications devices and their subscribers, respectively, using the present invention as set forth below in greater detail .
- Providing the cen- tral entity 46 with its own SMS center instead of using an SMS facility Df,- for example first and/or second communications environment, allows to communicate with participating communications devices using their home mobile telephone network numbers, to up-date participating communications devices, particularly their SIM cards, and to provide identity data to participating communications devices as described below.
- an aspect of the present invention is to communicate, in response to a request from a communications device to operate that communications device in a different com- munications environment (i.e. outside its communications environment) , identity data from the central entity to the requesting communications device.
- a communications device 22 in form of a GSM telephone and identity data in form of International Mobile Subscriber Identities (IMSIs) and keys used for generating so- called authentication triplets (Ki 1 S).
- IMSIs International Mobile Subscriber Identities
- Ki 1 S keys used for generating so- called authentication triplets
- Each communications device in the assumed scenario uses a SIM card to which a unique IMSI and a Ki associated to the IMSI are associated.
- a communications device can be identified in a telephone network and authorized to communicate in the telephone network.
- a GSM switching unit of the telephone network has access to and/or maintains a database providing information on correlations of IMSIs and associated Ki ' s for different communications devices .
- SIM cards have a single IMSI and a single associated Ki.
- communications devices and, in case of the specifically assumed scenario of GSM communications, SIM cards are able to hold more then one IMSI-Ki-pair .
- a communications device or SIM card
- holding capabilities for one IMSI-Ki-pair for a home communications environment and one IMSI-Ki-pair for a further communications environment can be considered sufficient.
- IMSI-Ki-pair e.g. the IMSI-Ki-pair of a home telephone network
- the procedures described below should be modified in manner to include steps of removing a IMSI-Ki-pair from the communications device (SIM card) upon receipt of a new IMSI-Ki-pair and re-installation of the previously removed IMSI-Ki-pair (e.g. the IMSI-Ki-pair of a home telephone network) , for example be transmission thereof from the home telephone network provider or the central entity.
- Fig. 2 illustrates the first communi- cations environment 2, the central entity 46 and a communications device 22.
- Fig. 2 further illustrates a identity data providing entity 58 in form of a manufacturer of SIM cards.
- the identity data providing entity 58 comprises, beside further not shown parts, a Ki generator 60, an SMS gateway 62 and a database 64.
- the Ki's generator 60 serves for generating Ki ' s each to be associated to an IMSI.
- the SMS gateway 62 serves for SMS communications with communications devices, in particular to communicate IMSIs and asso- ciated Ki's to communications devices.
- the database 54 stores, inter alia, IMSIs and associated Ki's.
- the identity data providing entity 58 creates a special group or block of Ki 1 S, the number of which may, for example, depend on an assumed or anticipated average and/or peak number of participating communications devices .
- the identity data providing entity 58 further generates two encoding and decoding keys, here referred to as "open key” only for encoding and “secret key” only for decoding.
- the secret key will be written to the SIM card of the communi- cations device 22 by the identity data providing entity 58, for example, during a manufacturing process of the SIM card.
- the secret key is preferably written to an assigned location on the SIM card such that no undesired access (copy and/or read access) is possible.
- the identity data providing entity 58 communicates the group or block Ki ' s to the first communications environment 2, for example using a conventional "transport key".
- the identity data providing entity 58 encodes the group or block Ki ' s with the "open key” and stores them in the database 64 together with IMSIs reserved for being used in combination with these Ki ' s . These IMSIs are also encoded with the "open key” .
- an IMSI represents a first part of identity data and a Ki represents a second part of identity data.
- IMSIs are communicated to the central database 54 and stored therein.
- the central entity 46 has access to the IMSIs only, but no access to the Ki ' s .
- the request is forwarded to the central entity 46.
- the central entity 46 confirms the request and for- wards the request to the identity data providing entity 58.
- An encoded IMSI-Ki-pair is retrieved from the databases 54 and 64 and communicated via the SMS gateway 62 to the communications device 22.
- the IMSI-Ki-pair is communicated by means of a secured and/or encoded SMS.
- the communications device 22 Upon receipt of the IMSI-Ki-pair, the communications device 22 decodes the IMSI-Ki-pair using the "secret key” and writes the decoded IMSI and Ki to its SIM card.
- the communications device 22 is prepared to be used for communications in a communications environment 24 outside the service range of its home communications environment 2, here first communications environment 2.
- the communications device 22 is yet not set up such that communications in a different communications environment is actually possible. Rather, the communications device 22 is still configured for communications in the first communications environment 2.
- communications devices usable with the present invention preferably comprise hardware and/or software supported functions.
- communications devices usable with the present invention provide a so-called "roaming service menu" at least supporting in generating the request.
- the "roaming service menu” may, for example, provide information on all available communications environments in which communications with the communications device 22 can be requested. In order to request communications in a desired communications environment, selection of a respective menu entry will generate a respective request. Communications environments not longer available and/or communications environment newly available can be added, for example, by SMS communications from the central entity 46.
- communications devices usable with the present invention preferably comprise dedicated software and/or hardware portions and components, respectively, for the above decoding and storing steps .
- the communications device 22 is associated to the first communications environment 2 (e.g. a wireless telephone network) and has a home IMSI-Ki-pair associated to first communications environment 2 (i.e. first identity data) enabling the communications device 22 to communications within the first communications environment 2 and from first communications environment 2 to further communications environments.
- the first identity data of communications device 22 is not sufficient for communications by the communications device 22 within communications environments other than its home/first communications environment 2.
- the communications device 22 sends a request to the central entity 46 "I want to go to second com- munications environment 24" (see Fig. 3) . This can be accomplished by activating a respective entry in the above "roaming service menu” .
- the central entity 47 communicates an encrypted IMSI-Ki-pair, which is associated to second communications environment 24 (i.e. second identity data), to the communications device 22, e.g. as set forth above, via the SMS gateway 62 of identity data providing entity 48 (see Fig. 4) .
- the communications device 22 decodes the encoded second identity data and stores the same on its SIM card. It contemplated that the communications device 22 receives a confirmation from the central entity 46 that the second identity data has been communicated and that communications in the desired communications environment 24 is possible now.
- the Communications device 22 has first and second identity data, i.e.
- the Communications device 22 Upon entry in the service range of second communications environment 24, the Communications device 22 activates the second identity data, i.e. the IMSI-Ki-pair associated to second communications environment 24, and logs on to the second communications environment 24 using the second identity data, i.e. the IMSI-Ki-pair associated to second communications environment 24 (see Fig. 6) .
- the communications device 22 can use all communications services of the second communications environment 24.
- Activation of the second identity data can be accomplished by operating the communications device 22, for example by means of the "roaming service menu", to mark the first identity data as not active and to mark the second iden- tity data as active. Then, log on of the communications device 22 to second communications environment 24 can be carried using the second identity data.
- the communications device 22 When the communications device 22 returns to the first communications environment 2, the communications device 22 acti- vates the first identity data, i.e. the IMSI-Ki-pair associated to first communications environment 2, and logs on to the first communications environment 2 using the first identity data, i.e. the IMSI-Ki-pair associated to first communications environment 2.
- Activation of the first identity data can be accomplished by operating the communications device 22, for example by means of the "roaming service menu", to mark the first identity data as active and to mark the second identity data as not active. Then, log on of the communications device 22 to first communications environment 2 can be carried using the second identity data.
- the Communications device 22 can use all communications services of the first communications environment 2.
- the central entity 46 Upon log on to first communications environment 2, the central entity 46 communicates erasing data to the communications device 22 such that the second identity data is removed (e.g. erased) from the communications device 22 (see Fig. 7)
- second communications environment 24 detects from the block of first parts of second identity data (e.g. IMSIs) provided to its switching unit 30 allocated for the method according to the present invention (e.g. roaming service) that the communications device 22 is trying to login to the second communications environment 24. Then, at least procedures de- scribed below are contemplated.
- IMSIs identity data
- switching unit 30 allocated for the method according to the present invention (e.g. roaming service) that the communications device 22 is trying to login to the second communications environment 24.
- the second communications environment 24 requests from the central billing server 52 a account and/or balance associated to the communications device 22.
- the central entity 46 receives this request from the home first communications environment 2 of the communications device 22.
- the central entity 46 complies with this request, i.e, virtually transfers money to the an account and/or balance of the communications device 22 associated the second communications environment 24, e.g. maintained in the second billing server 32. Then, the account/balance of the communications device 22 associated to its home first communications environment 2 is " zero" .
- the central entity 46 will handle the account/balance of the communications device 22 online. This may be accomplished, for example, by storing and managing an ac- count/balance, which is associated to the communications device 22 as being operated in the second communications environment 24, in the central billing server 52. Then, for example, in case the second communications environment 24 is a telephone network, the second communications environment 24 can treat the communications device 22 as normal "prepaid communications device" .
- the central entity 46 communicates data (e.g. a special order) to the home first communications environment 2 of the communications device 22 effecting that the first communications environment 2 transfers first identifying data for identifying the communications device 22 in the first communications environment 2 (e.g. home telephone number) to the cen- tral entity 46.
- data e.g. a special order
- the central entity 46 communicates data (e.g. a special order) to the home first communications environment 2 of the communications device 22 effecting that the first communications environment 2 transfers first identifying data for identifying the communications device 22 in the first communications environment 2 (e.g. home telephone number) to the cen- tral entity 46.
- any communications device trying to communicate with the communications device 22 using the first identifying data will be routed to the central entity 46, which, in turn, will forward a communications link to the com- munications device 22 in the second communications environment 24.
- the login request and/or a respective service message is communi- cated from the communications device 22 directly to the central entity 46. Then, the central entity 46 executes the same sequences as described above.
- the communications device 22 can communicate within the second communications environment 24 (e.g. make outgoing tele- phone calls and send SMS) , from the second communications environment 24 to outside communications environments and can receive communications to the communications device 22 (e.g. incoming telephone calls) . All Communications will be routed via the central entity 46.
- Data for identifying the communications device 22 in the second communications environment 24, here referred to as second identifying data is not known to anybody except the central entity 46. Communications from the communications device 22 are going through the central entity 46 first where the second identifying data is substituted by the central entity 46 with first identifying data (e.g. the original/home number of the communications device 22) .
- the first and second identifying data may be a first CLIP' for the first communications environment 2 and a second CLIP for the second communications environment 24. Then, it is contemplated that the central entity 46 makes a substitution of the second CLIP for outgoing calls with the first CLIP of the communications device 22.
- Incoming communications to the communications device 22 are also routed via the central entity 46.
- the second identifying data for identifying the communications device 22 in second communications environment 24 is not known. Communications to the communications device 22 will therefore identify the communications device 22 as communications target by using the first identifying data. Due to the transfer of the first identifying data to the central entity 46, such communications will be routed to the central entity 46. The central entity 46 in turn routed the communications to the communications device 22 by using the second identifying data.
- Routing of communications can be carried out according to according the LCR of the second communications environment 24 or the LCR of the central entity 46 for communications to communications environments outside second communications environment 24 (e.g. international outgoing telephone calls) and according to the LCR of the second communications environment 24 for communications within the second communications environ- ment 24 (e.g. outgoing domestic telephone calls) .
- Billing for communications of the communications device 22 in the second communications environment 24 can be handled, as set forth above, by the second communications environment 24 or the central entity 46.
- the second communications environment 24 or the central entity 46 denies communications from the communications device 22; this may also apply to communications to the communications device 22. Communications are allowed again if the ac- count/balance is re-filled again. This can be accomplished by using a prepaid card of the second communications environment 24 and/or re-filling the account/balance of the communications device 22 in its home communications environment, i.e. the first communications environment 2, and transferring the ac- count/balance to the second billing server 32 or the central billing server 52.
- the first identity data (e.g. IMSI and Ki) is activated, e.g. by manually choosing the first identity data from a SIM menu. Then, further logins to the first communications environment 2 will be carried out as usually.
- the first communications environment 2 detects from the block of first parts of first identity data (e.g. IMSI) provided to the first switching unit 8 allocated for the method according to the present invention (e.g. roaming service) , that the communications device 22 is trying to login to the first communications environment 24. Then, at least the procedures described below are contemplated.
- first identity data e.g. IMSI
- the first switching unit 8 allocated for the method according to the present invention (e.g. roaming service)
- the first communications environment 24 requests from the central entity 46 the account/balance the communications device 22. Then, the central entity 46 transfers the account/balance from the second billing server 32 of the second communications environment 24 or the account/balance from the central billing server 52 to the first billing server 10. As a result, the account/balance of the communications device 22 in the second billing server 32 or the central billing server 52 is "zero".
- the second communications environment 24 blocks the second identity data previously used by the communications device 22 and the first communications environment 2 cancels the transfer of the first identifying data of the communications device 22 to the central entity 46.
- the central entity 46 communicates erasing data (e.g. by sending a service message) to the communications device 22, which erasing data effects a removal of the second identity data from the communications device 22. This may be accomplished, for example, by communicating from the central entity 46 to the communications device 22 a blank IMSI-Ki-pair, which erases or over-writes the previously stored IMSI-Ki-pair. Then, the IMSI-Ki-pair for the communications environment 24 can be used for another communications device requesting communications in the communications environment 24 (e.g. by marking this IMSI-Ki-pair accordingly in the database 54 of the central entity 46) .
- the login request and/or a respective service message is communicated from the communications device 22 directly to the central entity 46. Then, the central entity 46 executes the same sequences as described above.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
The present invention is related to method and a system and related components for operating a communications device (22), which has first identity data associated to a first communications environment (2), in at least one further communications environment, wherein, in response to a request from the communications device (22) to operate the communications device (22) in a second communications environment (24), a central entity (46) communicates second identity data associated to the second communications environment (24) to the communications device (22).
Description
COMMUNICATIONS METHOD AND SYSTEM
FIELD OF THE INVENTION
The present invention generally relates to ' communications methods and communications systems and in particular to a method and system for operating a communications device in at least to two different communications environments.
BACKGROUND OF THE INVENTION
Mobile communications, particularly in the field of mobile telephone communications, is well known. Usually, mobile communications are limited to a home communications environment of a communications device, e.g. in a geographical area in which a user of the communications device lives.
In some cases it is possible to operate a communications de- vice in different communications environments such that, for example, the communications device can be moved from a geographical area serviced by a telephone network to a geographical area serviced by another telephone network (e.g. telephone networks in different countries and/or different telephone networks in the same country) . In the field of mobile telephone communications, this capability is also referred to as "roaming" .
However, providing mobile communications capabilities going beyond the boundaries of a single communications environment and including different communications environment require that a communications device to be operated in different communications environments can be identified in and can log on to each communications environment of interest.
In the case of mobile telephone communications, this is com- monly accomplished by storing, in the Home Locations Registers
HLRs of the involved communications environments, data indicating that a particular communications device may be operated in the respective communications environment. For example, the HLRs store an International Mobile Subscriber Identity IMSI of the communications device to be operated in the communications environments. Upon request from the communications device to communicate in one of the communications environments, the concerned communications environment proofs whether the IMSI received from the communications device is stored in its HLR. If the stored IMSI and the received IMSI correspond, the communications device is allowed to communicate in the communications environment. If the stored IMSI and the received IMSI do not correspond, communications by this communications device in the communications environment is denied.
However, such mobile communications is usually not provided in general. For example in the field of mobile telephone communications, mobile telephones using so-called prepaid cards are not allowed to use roaming services. Rather, to use such a telephone in different communications environments requires using the telephone with a prepaid card for each communications environment .
A reason for such restrictions is, for example, the way communications to and from a communications device operated outside its home communications environment are routed, the manner a communications device outside its home communications environment is identified and addressed, and how administrative and managing processes (e.g. billing procedures) are designed.
Therefore, there is need for enhanced solutions providing increased mobility in communications, preferably to allow world- wide mobile communications without restriction.
It is an object of the present invention to provide a communications method and a communications system as well as related components, which overcome the above-mentioned problems, for example, relating to an operation of a communications device in different communications environments.
SUMMARY OF THE INVENTION
According to an aspect, the present invention provides a method for operating a communications device, which has first identity data associated to a first communications environment, in at least one further communications environment, which method comprises the steps of communicating, from the communications device to a central entity, a request to operate the communications device in a second communications environment, communicating, from the central entity to the communications device in response to the request, second identity data associated to the second communications environment, and storing, by the communications device upon receipt of the second identity data, the second identity data.
According to a further aspect, the present invention provides a system comprising a first communications environment, a communications device, which has first identity data associated to the first communications environment, a second communications environment to which second identity data is associated, and a central entity, wherein the central entity is adapted to communicate, upon a request from the communications device to operate the communications device in the second communications environment, the second identity data to the communications device, and the communications device is adapted to store the second identity data.
According to a further aspect, the present invention provides a software program including software program portions for carrying out the method steps according to the present invention.
According to a further aspect, the present invention provides a communications device being adapted to carry out the method steps according to the present invention.
According to a further aspect, the present invention provides a central entity being adapted to carry out the method steps according to the present invention.
According to a further aspect, the present invention provides a communications environment being adapted to carry out the method steps according to the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS
Embodiments of the invention will now be described, by way of example, and with reference to the accompanying drawings, in which:
Figs. 1 to 7 show preferred embodiments of the present in- vention.
DESCRIPTION OF PREFERRED EMBODIMENTS
The figures illustrate, in exemplary manner, preferred embodiments of the present invention. Before proceeding further with the detailed description of the figures, however, a few items of further preferred embodiments will be discussed.
In the method according to the present invention, the communications device may be a mobile communications device, the first and second communications environments may be mobile telephone environments, and the central entity may be an en- tity providing roaming services for the communications device in the first and second communications environments.
Examples for a communications device, which can be used in the present invention, include mobile telephones (e.g. GSM and
UMTS devices) , mobile computing devices having communications capabilities and the like.
Examples for a communications environment, which can be used in the present invention, include mobile telephone environ- ments (e.g. GSM and UMTS networks) , communications systems including wireless and wired communications links (e.g. radio and terrestrial communications networks optionally including the Internet) and the like.
Examples for a central entity, which can be used in the pre- sent invention, include a communications network interconnecting the first communications environment and second communications environment, a communications server, a telephone switch and the like.
The request may be communicated from the communications device to an identity data providing entity and from the identity data providing entity to the central entity.
The central entity, upon receipt of the request, may retrieve a first part of the second identity data.
The first part of the second identity data may be stored in association to the central entity and the identity data providing entity such the central entity and the identity data providing entity have access to the first part of the second identity data.
Examples for such a storage include to store the first part of the second identity data in a first storage means to which the central entity is connected via at least one of a wired communications link and a wireless communications link and a second storage means to which the identity data providing entity is connected via at least one of a wired communications link and a wireless communications link, or in a storage means to which both the central entity and the identity data providing entity
are connected via at least one of a wired communications link and a wireless communications link.
The identity data providing entity, upon receipt of the request, may retrieve a second part of the second identity data.
The second part of the second identity data may be stored in association to the identity data providing entity only such the identity data providing entity has access to the second part of the second identity data, while access to the second part of the second identity data by the central entity is de- nied.
Examples for such a storage include to store the second part of the second identity data in a storage unit to which only the identity data providing entity is connected via at least one of a wired communications link and a wireless communica- tions link, while the no communications link between the central entity and the storage unit is allowed.
The central entity may communicate the first part of the second identity data to the identity data providing entity.
The identity data providing entity may communicate the first part of the second identity data and the second part of the second identity data to the communications device.
The first part of the second identity data may be an International Mobile Subscriber Identity IMSI for a mobile communications environment, and the second part of the second identity data may be a Ki key for a mobile communications environment.
At least one of the first part of the second identity data and the second part of the second identity data may be encoded by the identity data providing entity before being communicated to the communications device.
The at least one encoding step may be carried out by using a general encoding key.
At least one of the first part of the second identity data and the second part of the second identity data may be decoded by the Communications device upon receipt.
The at least one decoding step may be carried out by using a general decoding key.
The general decoding key may be previously stored in the communications device under control of the identity data provid- ing entity. This can be for example accomplished by the identity data providing entity before the communications device is provided to a user, e.g. during a manufacturing process of the communications device.
Communicating by means of the communications device in the first communications environment may include a step of identifying the communications device in the first communications environment by means of the first identity data.
The identifying step may include operating the communications device such that the first identity data is defined as valid identity data.
The first identity data may be communicated from the communications device to a first communications system in the first communications environment.
The identifying step may include communicating first communi- cations request data to the central entity. Examples for the first communications request data include data indicating that the communications device is now to be operated in the first communications environment.
The first communications request data may be communicated di- rectly from the communications device or via a first communi-
cations system in the first communications environment to the central entity upon receipt of the first identity data by the first communications system.
Examples for a communications system useable as first communi- cations system in the present invention include a provider or operator of the first communications environment and respective components and units, respectively, a telephone switch, a GSM switch, an UMTS switch and the like.
The central entity may communicate erasing data to the commu- nications device in response to the first communications request data, wherein the erasing data effects removing the second identity data from the communications device.
The erasing step may include communicating an empty identity data template replacing the stored second identity data.
For communications in the first communications environment, the second identity data may be marked as invalid identity data.
The marking step may be carried out by a second communications system in the second communications environment upon receipt of a marking request communicated from the central entity to the second communications environment in response to the first communications request data.
Examples for a communications system useable as second communications system in the present invention include a provider or operator of the first communications environment and respective components and unit, respectively, a telephone switch, a GSM switch, an UMTS switch and the like.
In preparation of communications by means of the communications device in the second communications environment, the re- quest may be communicated from the communications device being
operated in the first communications environment to the central entity.
The second identity data may be then communicated from the central entity to the communications device in the first com- munications environment.
Communications from the communications device to the central entity may be carried out via a first communications system in the first communications environment, while communications from the central entity to the communications device may be carried out via an identity data providing entity, at least as regards the communications related to the second identity data.
Communicating by means of the communications device in the second communications environment may include a step of identifying the communications device in the second communications environment by means of the second identity data.
The identifying step may include operating the communications device such that the second identity data is defined as valid identity data.
The second identity data may be communicated from the communi- cations device to a second communications system in the second communications environment.
The identifying step may include communicating second communications request data to the central entity. Examples for the second communications request data include data indicating that the communications device is now to be operated in the second communications environment .
The second communications request data may be communicated from a second communications system in the second communications environment to the central entity.
The second communications request data may be communicated from the communications device being operated in the second communications environment directly to the central entity.
The central entity may communicate, in response to the second communications request, a identity data transfer request to a first communications system in the first communications environment, and the first communications system may then route communications, which are to be carried out with the communications device and including first identifying data for iden- tifying the communications device in the first communications environment, to the central entity.
Examples for data to be used as first identifying data include data identifying the communications device as such (e.g. a Mobile Subscriber ISDN Number MSISDN, a Mobile Subscriber Iden- tification Number MSIN, International Mobile Subscriber Identity IMSI) , a telephone number of the communications device, an Internet address of the communications device, a communications link via which the communications device can receive communications, a CLIP (Calling Line Identification Presenta- tion) and the like.
Then, the central entity may replace, in the communications routed to the central entity, the first identifying data by second identifying data for identifying the communications device in the second communications environment, and the communications to be carried out with the communications device and now having the second identifying data can be routed to the communications device in the second communications environment.
Examples for data to be used as second identifying data include data identifying the communications device as such (e.g. a Mobile Subscriber ISDN Number MSISDN, a Mobile Subscriber
Identification Number MSIN) , a telephone number of the communications device, an Internet address of the communications device, a communications link via which the communications de-
vice can receive communications, a CLIP (Calling Line Identification Presentation) and the like.
Communications to and from the communications device in the second communications environment may be routed via the cen- tral entity, preferably at least partially routed via an SS7/C7 voice link.
Communications from the communications device to be carried out in the second communications environment may include second identifying data for identifying the communications device in the second communications environment, wherein the central entity may replace the second identifying data by first identifying data for identifying the communications device in the second communications environment, and wherein the central entity may route the communications from the communications de- vice and now including the first identifying data to a communications target in the second communications environment with which the communications from the communications device are to be carried out. Above examples for identifying data apply to this embodiment also. Examples for a communications target in- elude communications devices comparable to the above mentioned communications device.
Communications from the communications device to be carried out in a communications environment outside the second communications environment may include second identifying data for identifying the communications device in the second communications environment, wherein the central entity may replace the second identifying data by first identifying data for identifying the communications device in the first communications environment, and wherein the central entity may route the com- munications from the communications device and now including the first identifying data to the communications environment outside the second communications environment in which the communications from the communications device are to be carried out .
Communications to the communications device to be carried out in the second communications environment may include first identifying data for identifying the communications device in the first communications environment, wherein the central en- tity may replace the first identifying data by second identifying data for identifying the communications device in the second communications environment, and wherein the central entity may route the communications now including the second identifying data to the communications device.
The central entity, in response to the second communications request data, may transfer communications allowance data indicating that the communications device is allowed to communicate from a first communications allowance data providing entity associated to the first communications environment to a central communications allowance data providing entity associated to the central entity.
The central entity, in response to the second communications request data, may transfer communications allowance data indicating that the communications device is allowed to communi- cate from a first communications allowance data providing entity associated to the first communications environment to a second communications allowance data providing entity associated to the second communications environment.
Examples for communications allowance data include data repre- senting an account associated to the communications device, a balance associated to the communications device, data obtained from a prepaid communications card and the like.
Examples for communications allowance data providing entities include billing platforms, units, clearing centers and the like respectively associated to the first communications environment, the second communications environment and the central entity.
The second identity data is preferably selected from a plurality of identity data reserved to be used as second identity data for carrying out the method.
Communicating by means of the communications device may in- elude operating the communications device in a second identity data request mode under control of a software program associated to the communications device.
Storing the second identity data in the communications device may include operating the communications device in a second identity data storing mode under control of a software program associated to the communications device.
Preferably, the communications device is adapted to store the first identity data and a plurality of second identity data.
The second identity data may be communicated from the central entity to the communications device by means of at least one of a SMS, a MMS, an e-mail and a WAP link.
Communications to and from the communications device may include at least one of voice communications, SMS communications, MMS communications, e-mail communications and data communica- tions.
The above given examples correspondingly apply to the following preferred embodiments.
In the system according to the present invention, the communications device may be a mobile communications device, the first and second communications environments may be mobile telephone environments, and the central entity may be an entity providing roaming services for the communications device in the first and second communications environments.
The system may further comprise an identity data providing en- tity and wherein the request may be communicated from the com-
munications device to the identity data providing entity and from the identity data providing entity to the central entity.
The system may further include at least one first storage entity in which a first part of the second identity data is stored such that access to the first part of the second identity data by the central entity and the identity data providing entity is allowed and wherein the central entity, upon receipt of the request, may retrieve the first part of the second identity data from the at least one first storage entity and may communicate the second part of the second identity data to the identity data providing entity.
The system may further include a second storage entity in which a second part of the second identity data is stored such that access to the second part of the second identity data by the identity data providing entity is allowed and access to the second part of the second identity data by the central entity is denied and wherein the identity data providing entity, upon receipt of the request , may retrieve the second part of the second identity data from the second storage entity.
The identity data providing entity may communicate the first part of the second identity data and the second part of the second identity data to the communications device.
The first part of the second identity data may be an International Mobile Subscriber Identity IMSI for a mobile communica- tions environment, and the second part of the second identity data may be a Ki key for a mobile communications environment.
The identity data providing entity may comprise an encoding unit for encoding at least one of the first part of the second identity data and the second part of the second identity data before being communicated to the communications device.
The encoding unit may comprise a general encoding key.
The Communications device may comprise a decoding unit for decoding at least one of the first part of the second identity data and the second part of the second identity data.
The decoding unit may comprise a general decoding key.
The system may further comprise a first communications system in the first communications environment .
The system may further comprise a first voice communications link between the first communications system and the central entity.
The system may further comprise a second communications system in the second communications environment.
The system may further comprise a second voice communications link between the second communications system and the central entity.
Preferably, at least one of the first communications link and the second communications link is an SS7/C7 voice link.
The system may further comprise a first communications allowance data providing entity associated to the first communications environment .
The system may further comprise a second communications allowance data providing entity associated to the second communications environment .
The system may further comprise a central communications allowance data providing entity associated to the central entity.
The system may further comprise at least one secured data link between at least two of the communications allowance data providing entities.
Preferably, at least one of the at least one secured data link is at least one of a n x 64 Kbps data link and a tunneling Internet connection.
Preferably, the system is adapted to be operated according to the method steps according to the present invention.
In the following the present invention will be described with respect to mobile communications environments providing mobile telephone communications for a communications device in form of a mobile telephone in two different communications environ- ments both being in form of a telephone communications environment based on GSM technology.
However, referring to such a scenario is not intended to limit the present invention.
For example, the present invention contemplates communications in three, four up to a plurality of communications environments. Also, the present invention is not limited to telephone communications. Rather, the present invention can be used in any communications scenario wherein a communications device, which may communicate in a communications environment, is not (automatically) allowed to communicate in another communications environment. For example, the present invention envisages scenarios wherein a computing device having communications capabilities (i.e. a communications device) may access a computer network or computer network area (i.e. a communica- tions environment) , while access to a different computer network or computer network area would be denied if the present invention is not used. Further, communications environments envisaged by the present invention can be based on any type o 2nd and 3rd generation communications environments.
Fig. 1 illustrates a first communications environment 2.
The first communications environment 2 comprises a first mobile telephone network 4 serviced by first base stations of
which a single first base station 6 is shown as representative example .
The first communications environment 2 further comprises a first switching unit 8 and a first communications allowance data providing entity including a first billing server 10. Optionally, the first communications allowance data providing entity includes a first prepaid platform 12 serving as billing unit in relation to users of the first communications environment 2 utilizing prepaid communications services (e.g. utiliz- ing a mobile telephone using prepaid cards) . Although, Fig. 1 shows the first communications allowance data providing entity as integral part of the first communications environment 2, the present invention contemplates that the first communications allowance data providing entity is at least associated the first communications environment 2.
The first communications environment 2 further comprises at least a communications connection 14 (e.g. a SS7 link) to a first non-mobile telephone network 16 (e.g. public switching telephone network) , which may be a part of the first communi- cations environment 2 also.
The first switching unit 8 is coupled with the first base stations 6 for routing communications to and from the first mobile telephone network 4 from and to, respectively, first non- mobile telephone network 16 and, and as set forth below, from and to, respectively, further communications environments.
Billing of communications within the first mobile telephone network 4 and between the first mobile telephone network 4 and other communications networks is accomplished by the first billing server 10. To this end, the first billing server 10 is coupled with the first base stations 6. The same applies to the first prepaid platform 12 if provided.
For communications between the first billing server 10 and, if applicable, the first prepaid platform 12 and another server (s)
also serving for billing purposes, a communications connection 18 (e.g. a n x 64 Kbps secured link) is used.
For communications via the first switching unit 8 to another communications environment and/or communications network, a communications connection 20 (e.g. a n x El SS7/C7 voice link) is used.
Communications devices in form of mobile telephones (in Fig. 1 for illustrative purposes only one communications device 22 is shown) can communicate in the first mobile telephone network 4 with each other and can communicate via the first mobile telephone network 4 with communications device not serviced in the first mobile telephone network 4. For example, communications devices 22 may communicate with the first non-mobile telephone network 16 and/or via communications connection 20.
Fig. 1 further illustrates a second communications environment 24.
The second communications environment 24 comprises a second mobile telephone network 26 serviced by second base stations of which a single second base station 28 is shown as represen- tative example.
The second communications environment 24 further comprises a second switching unit 30 and a second communications allowance data providing entity including a second billing server 32. Optionally, the second communications allowance data providing entity includes a second prepaid platform 34 serving as billing unit in relation to users of the second communications environment 24 utilizing prepaid communications services (e.g. utilizing a mobile telephone using prepaid cards) . Although, Fig. 1 shows the second communications allowance data provid- ing entity as integral part of the second communications environment 24, the present invention contemplates that the second communications allowance data providing entity is at least associated the second communications environment 24.
The second communications environment 24 further comprises at least a communications connection 36 (e.g. a SS7 link) to a second non-mobile telephone network 38 (e.g. public switching telephone network) , which may be a part of the second communications environment 24 also.
The second switching unit 30 is coupled with the second base stations 28 for routing communications to and from the second mobile telephone network 26 from and to, respectively, the second non-mobile telephone network 38 and, and as set forth below, from and to, respectively, further communications environments .
Billing of communications within the second mobile telephone network 26 and between the second mobile telephone network 26 and other communications networks is accomplished by the sec- ond billing server 32. To this end, the second billing server 32 is coupled with the second base stations 28. The same applies to the second prepaid platform 34 if provided.
For communications between the second billing server 32 and, if applicable, the second prepaid platform 34 and another server (s) also serving for billing purposes, a communications connection 40 (e.g. a n x 64 Kbps secured link) is used.
For communications via the second switching unit 30 to another communications environment and/or communications network, a communications connection 42 (e.g. a n x El SS7/C7 voice link) is used.
Communications devices in form of mobile telephones (in Fig. 1 for illustrative purposes only one communications device 44 is shown) can communicate in the second mobile telephone network 26 with each other and can communicate via the second mobile telephone network 38 with communications device not serviced in the second mobile telephone network 26. For example, communications devices 44 may communicate with the second non-
mobile telephone network 38 and/or via communications connection 42.
Fig. 1 further illustrates a central entity 46. The central entity 46 comprises a central network 48 coupled with the first communications environment 2 via communications connection 20 and coupled with the second communications environment 24 via communications connection 42.
The central entity 46 comprises a central switching unit 50 and a central billing server 52 serving as central communica- tions allowance data providing entity. As alternative, instead of central billing server 52 a communications allowance data providing entity, which is associated (i.e. is no integral part of the central entity 46) can be used.
The central entity 46 further comprises a database 54 and, connected with the database 54, an SMS center 56, both of which will be described in greater detail below.
For communications with the first billing server 12 and the second billing server 32 and, if applicable, with the first prepaid platform 12 and the second prepaid platform 34, the central billing server 52 is connected to communications connection 18 and communications connection 40, respectively.
For carrying out a preferred embodiment of the method according to present invention, the central entity 46 utilizes the central billing server 52 to store CRDs information, to manage balances and financial transactions as regards communications devices and their subscribers, respectively, using the present invention.
In this context, the central entity 46 utilizes the central database 54 to store identity data in a from described below and telephone numbers of communications devices and their subscribers, respectively, using the present invention in order to ensure a proper identification thereof.
Still in this context, the central entity 46 utilizes the SMS center 56 for SMS communications with communications devices and their subscribers, respectively, using the present invention as set forth below in greater detail . Providing the cen- tral entity 46 with its own SMS center, instead of using an SMS facility Df,- for example first and/or second communications environment, allows to communicate with participating communications devices using their home mobile telephone network numbers, to up-date participating communications devices, particularly their SIM cards, and to provide identity data to participating communications devices as described below.
As noted above, an aspect of the present invention is to communicate, in response to a request from a communications device to operate that communications device in a different com- munications environment (i.e. outside its communications environment) , identity data from the central entity to the requesting communications device.
This aspect will be illustrated if the following with respect to the first communications environment 2 in form of a GSM telephone network, a communications device 22 in form of a GSM telephone and identity data in form of International Mobile Subscriber Identities (IMSIs) and keys used for generating so- called authentication triplets (Ki 1S).
Each communications device in the assumed scenario uses a SIM card to which a unique IMSI and a Ki associated to the IMSI are associated. By means of these parameters, a communications device can be identified in a telephone network and authorized to communicate in the telephone network. To this end, usually a GSM switching unit of the telephone network has access to and/or maintains a database providing information on correlations of IMSIs and associated Ki ' s for different communications devices .
Traditional SIM cards have a single IMSI and a single associated Ki.
For preferred embodiments of the present invention illustrated here, it is preferred that communications devices and, in case of the specifically assumed scenario of GSM communications, SIM cards are able to hold more then one IMSI-Ki-pair . For ex- ample, in a preferred embodiment a communications device (or SIM card) can hold up to 256 different IMSI-Ki-pairs . However, holding capabilities for one IMSI-Ki-pair for a home communications environment and one IMSI-Ki-pair for a further communications environment can be considered sufficient.
Nevertheless, it has to be noted that communications devices
(or SIM cards) holding only one IMSI-Ki-pair at a time will be also sufficient. In such cases, the procedures described below should be modified in manner to include steps of removing a IMSI-Ki-pair from the communications device (SIM card) upon receipt of a new IMSI-Ki-pair and re-installation of the previously removed IMSI-Ki-pair (e.g. the IMSI-Ki-pair of a home telephone network) , for example be transmission thereof from the home telephone network provider or the central entity.
Consistent with Fig. 1, Fig. 2 illustrates the first communi- cations environment 2, the central entity 46 and a communications device 22. Fig. 2 further illustrates a identity data providing entity 58 in form of a manufacturer of SIM cards.
The identity data providing entity 58 comprises, beside further not shown parts, a Ki generator 60, an SMS gateway 62 and a database 64.
The Ki's generator 60 serves for generating Ki ' s each to be associated to an IMSI.
The SMS gateway 62 serves for SMS communications with communications devices, in particular to communicate IMSIs and asso- ciated Ki's to communications devices.
The database 54 stores, inter alia, IMSIs and associated Ki's.
The identity data providing entity 58 creates a special group or block of Ki 1S, the number of which may, for example, depend on an assumed or anticipated average and/or peak number of participating communications devices .
To ensures security, the identity data providing entity 58 further generates two encoding and decoding keys, here referred to as "open key" only for encoding and "secret key" only for decoding.
The secret key will be written to the SIM card of the communi- cations device 22 by the identity data providing entity 58, for example, during a manufacturing process of the SIM card. The secret key is preferably written to an assigned location on the SIM card such that no undesired access (copy and/or read access) is possible.
Further, the identity data providing entity 58 communicates the group or block Ki ' s to the first communications environment 2, for example using a conventional "transport key".
In addition, the identity data providing entity 58 encodes the group or block Ki ' s with the "open key" and stores them in the database 64 together with IMSIs reserved for being used in combination with these Ki ' s . These IMSIs are also encoded with the "open key" . In general terms of the present invention, an IMSI represents a first part of identity data and a Ki represents a second part of identity data.
These IMSIs are communicated to the central database 54 and stored therein. In has to be noted that the central entity 46 has access to the IMSIs only, but no access to the Ki ' s .
Upon request from the communications device 22 to operate the communications device 22 in a communications environment 24 outside the communications service range of its home communications environment 2, the request is forwarded to the central entity 46. The central entity 46 confirms the request and for-
wards the request to the identity data providing entity 58. An encoded IMSI-Ki-pair is retrieved from the databases 54 and 64 and communicated via the SMS gateway 62 to the communications device 22. Preferably, the IMSI-Ki-pair is communicated by means of a secured and/or encoded SMS.
Upon receipt of the IMSI-Ki-pair, the communications device 22 decodes the IMSI-Ki-pair using the "secret key" and writes the decoded IMSI and Ki to its SIM card.
Then, the communications device 22 is prepared to be used for communications in a communications environment 24 outside the service range of its home communications environment 2, here first communications environment 2. However, it has to be noted that the communications device 22 is yet not set up such that communications in a different communications environment is actually possible. Rather, the communications device 22 is still configured for communications in the first communications environment 2.
For generating a request to be operated in a different communications environment, communications devices usable with the present invention preferably comprise hardware and/or software supported functions. For example, it is envisaged that communications devices usable with the present invention provide a so-called "roaming service menu" at least supporting in generating the request. The "roaming service menu" may, for example, provide information on all available communications environments in which communications with the communications device 22 can be requested. In order to request communications in a desired communications environment, selection of a respective menu entry will generate a respective request. Communications environments not longer available and/or communications environment newly available can be added, for example, by SMS communications from the central entity 46.
Further, communications devices usable with the present invention preferably comprise dedicated software and/or hardware
portions and components, respectively, for the above decoding and storing steps .
With reference to Figs. 3 to 7, a preferred embodiment of the method of the present invention will be described.
The communications device 22 is associated to the first communications environment 2 (e.g. a wireless telephone network) and has a home IMSI-Ki-pair associated to first communications environment 2 (i.e. first identity data) enabling the communications device 22 to communications within the first communications environment 2 and from first communications environment 2 to further communications environments. The first identity data of communications device 22 is not sufficient for communications by the communications device 22 within communications environments other than its home/first communications environment 2.
To communicate in other communications environments (e.g. a wireless telephone network) , for example, in the second communications environment 24, the communications device 22 sends a request to the central entity 46 "I want to go to second com- munications environment 24" (see Fig. 3) . This can be accomplished by activating a respective entry in the above "roaming service menu" .
In response to this request, the central entity 47 communicates an encrypted IMSI-Ki-pair, which is associated to second communications environment 24 (i.e. second identity data), to the communications device 22, e.g. as set forth above, via the SMS gateway 62 of identity data providing entity 48 (see Fig. 4) . Upon receipt of the second identity data, the communications device 22 decodes the encoded second identity data and stores the same on its SIM card. It contemplated that the communications device 22 receives a confirmation from the central entity 46 that the second identity data has been communicated and that communications in the desired communications environment 24 is possible now.
Now, the Communications device 22 has first and second identity data, i.e. an IMSI-Ki-pair associated to first communications environment 2 and an IMSI-Ki-pair associated to second Communications environment 24. However, the communications de- vice 22 is still in the first communications environment 2 and only the first identity data, i.e. the IMSI-Ki-pair associated to first Communications environment 2, is active (see Fig. 5).
Upon entry in the service range of second communications environment 24, the Communications device 22 activates the second identity data, i.e. the IMSI-Ki-pair associated to second communications environment 24, and logs on to the second communications environment 24 using the second identity data, i.e. the IMSI-Ki-pair associated to second communications environment 24 (see Fig. 6) . Now, the communications device 22 can use all communications services of the second communications environment 24. Activation of the second identity data can be accomplished by operating the communications device 22, for example by means of the "roaming service menu", to mark the first identity data as not active and to mark the second iden- tity data as active. Then, log on of the communications device 22 to second communications environment 24 can be carried using the second identity data.
When the communications device 22 returns to the first communications environment 2, the communications device 22 acti- vates the first identity data, i.e. the IMSI-Ki-pair associated to first communications environment 2, and logs on to the first communications environment 2 using the first identity data, i.e. the IMSI-Ki-pair associated to first communications environment 2. Activation of the first identity data can be accomplished by operating the communications device 22, for example by means of the "roaming service menu", to mark the first identity data as active and to mark the second identity data as not active. Then, log on of the communications device 22 to first communications environment 2 can be carried using the second identity data.
Now, the Communications device 22 can use all communications services of the first communications environment 2. Upon log on to first communications environment 2, the central entity 46 communicates erasing data to the communications device 22 such that the second identity data is removed (e.g. erased) from the communications device 22 (see Fig. 7)
In the following some exemplary communications scenarios are described.
Assuming second communications environment 24 detects from the block of first parts of second identity data (e.g. IMSIs) provided to its switching unit 30 allocated for the method according to the present invention (e.g. roaming service) that the communications device 22 is trying to login to the second communications environment 24. Then, at least procedures de- scribed below are contemplated.
The second communications environment 24 requests from the central billing server 52 a account and/or balance associated to the communications device 22.
The central entity 46 receives this request from the home first communications environment 2 of the communications device 22. The central entity 46 complies with this request, i.e, virtually transfers money to the an account and/or balance of the communications device 22 associated the second communications environment 24, e.g. maintained in the second billing server 32. Then, the account/balance of the communications device 22 associated to its home first communications environment 2 is " zero" .
In case the second communications environment 24 capabilities are not sufficient to proceed in this way (e.g. if the second communications environment 24 is a GSM telephone network and has no IN platform) , the central entity 46 will handle the account/balance of the communications device 22 online. This may be accomplished, for example, by storing and managing an ac-
count/balance, which is associated to the communications device 22 as being operated in the second communications environment 24, in the central billing server 52. Then, for example, in case the second communications environment 24 is a telephone network, the second communications environment 24 can treat the communications device 22 as normal "prepaid communications device" .
Also, in reply to the request of the second communications environment 24, the central entity 46 communicates data (e.g. a special order) to the home first communications environment 2 of the communications device 22 effecting that the first communications environment 2 transfers first identifying data for identifying the communications device 22 in the first communications environment 2 (e.g. home telephone number) to the cen- tral entity 46.
After this transfer, any communications device trying to communicate with the communications device 22 using the first identifying data will be routed to the central entity 46, which, in turn, will forward a communications link to the com- munications device 22 in the second communications environment 24.
In case the second communications environment 24 is not able to recognize a login of the communications device 22, the login request and/or a respective service message is communi- cated from the communications device 22 directly to the central entity 46. Then, the central entity 46 executes the same sequences as described above.
Now, the communications device 22 can communicate within the second communications environment 24 (e.g. make outgoing tele- phone calls and send SMS) , from the second communications environment 24 to outside communications environments and can receive communications to the communications device 22 (e.g. incoming telephone calls) .
All Communications will be routed via the central entity 46. Data for identifying the communications device 22 in the second communications environment 24, here referred to as second identifying data (e.g. a telephone number) is not known to anybody except the central entity 46. Communications from the communications device 22 are going through the central entity 46 first where the second identifying data is substituted by the central entity 46 with first identifying data (e.g. the original/home number of the communications device 22) .
In case of telephone communications, the first and second identifying data may be a first CLIP' for the first communications environment 2 and a second CLIP for the second communications environment 24. Then, it is contemplated that the central entity 46 makes a substitution of the second CLIP for outgoing calls with the first CLIP of the communications device 22.
Incoming communications to the communications device 22 are also routed via the central entity 46. The second identifying data for identifying the communications device 22 in second communications environment 24 is not known. Communications to the communications device 22 will therefore identify the communications device 22 as communications target by using the first identifying data. Due to the transfer of the first identifying data to the central entity 46, such communications will be routed to the central entity 46. The central entity 46 in turn routed the communications to the communications device 22 by using the second identifying data.
Routing of communications can be carried out according to according the LCR of the second communications environment 24 or the LCR of the central entity 46 for communications to communications environments outside second communications environment 24 (e.g. international outgoing telephone calls) and according to the LCR of the second communications environment 24 for communications within the second communications environ- ment 24 (e.g. outgoing domestic telephone calls) .
Billing for communications of the communications device 22 in the second communications environment 24 can be handled, as set forth above, by the second communications environment 24 or the central entity 46.
If the account/balance of the communications device 22 is empty, the second communications environment 24 or the central entity 46 denies communications from the communications device 22; this may also apply to communications to the communications device 22. Communications are allowed again if the ac- count/balance is re-filled again. This can be accomplished by using a prepaid card of the second communications environment 24 and/or re-filling the account/balance of the communications device 22 in its home communications environment, i.e. the first communications environment 2, and transferring the ac- count/balance to the second billing server 32 or the central billing server 52.
When the communications device 22 returns to the first communications environment 2, the first identity data (e.g. IMSI and Ki) is activated, e.g. by manually choosing the first identity data from a SIM menu. Then, further logins to the first communications environment 2 will be carried out as usually.
The first communications environment 2 detects from the block of first parts of first identity data (e.g. IMSI) provided to the first switching unit 8 allocated for the method according to the present invention (e.g. roaming service) , that the communications device 22 is trying to login to the first communications environment 24. Then, at least the procedures described below are contemplated.
The first communications environment 24 requests from the central entity 46 the account/balance the communications device 22. Then, the central entity 46 transfers the account/balance from the second billing server 32 of the second communications environment 24 or the account/balance from the central billing
server 52 to the first billing server 10. As a result, the account/balance of the communications device 22 in the second billing server 32 or the central billing server 52 is "zero".
In response to a marking request from the central entity 46, the second communications environment 24 blocks the second identity data previously used by the communications device 22 and the first communications environment 2 cancels the transfer of the first identifying data of the communications device 22 to the central entity 46.
The central entity 46 communicates erasing data (e.g. by sending a service message) to the communications device 22, which erasing data effects a removal of the second identity data from the communications device 22. This may be accomplished, for example, by communicating from the central entity 46 to the communications device 22 a blank IMSI-Ki-pair, which erases or over-writes the previously stored IMSI-Ki-pair. Then, the IMSI-Ki-pair for the communications environment 24 can be used for another communications device requesting communications in the communications environment 24 (e.g. by marking this IMSI-Ki-pair accordingly in the database 54 of the central entity 46) .
In case the first communications environment 2 is not able to recognize a login of the communications device 22, the login request and/or a respective service message is communicated from the communications device 22 directly to the central entity 46. Then, the central entity 46 executes the same sequences as described above.
Although the invention has been described herein with respect to specific embodiments thereof, the appended claims are not to be construed as limited to those embodiments, but rather to include any modifications an variations of the invention which may occur to one of ordinary skill in the art which fairly fall within its scope.
Claims
1. A method for operating a communications device (22), which has first identity data associated to a first communications environment (2) , in at least one further communications environment, comprising the steps of:
- communicating, from the communications device (22) to a central entity (46) , a request to operate the commu- nications device (22) in a second communications environment (24) ,
- communicating, from the central entity (46) to the communications device (22) in response to the request, second identity data associated to the second communi- cations environment (24) , and
- storing, by the communications device (22) upon receipt of the second identity data, the second identity data.
2. The method according to claim 1, wherein, - the communications device (22) is a mobile communications device (22) ,
- the first and second communications environments (24) are mobile telephone environments, and
- the central entity (46) is an entity providing roam- ing services for the communications device (22) in the first and second communications environments (24) .
3. The method according to one of the preceding claims, wherein the request is communicated from the communications device (22) to an identity data providing entity (58) and from the identity data providing entity (58) to the central entity (46) .
4. The method according to claim 3, wherein the central entity (46) , upon receipt of the request, retrieves a first part of the second identity data.
5. The method according to claim 4, wherein the first part of the second identity data is stored in association to the central entity (46) and the identity data providing entity (58) such the central entity (46) and the identity data providing entity (58) have access to the first part of the second identity data.
6. The method according to one of the claims 3 to 5 , wherein the identity data providing entity (58) , upon receipt of the request, retrieves a second part of the second identity data.
7. The method according to claim 6, wherein the second part of the second identity data is stored in association to the identity data providing entity (58) only such the identity data providing entity (58) has access to the second part of the second identity data, while access to the second part of the second identity data by the central entity (46) is denied.
8. The method according to one of the claims 4 to 7, wherein the central entity (46) communicates the first part of the second identity data to the identity data providing entity (58) .
9. The method according to one of the claims 6 to 8 , wherein the identity data providing entity (58) communicates the first part of the second identity data and the second part of the second identity data to the communications device (22) .
10. The method according to one of the claims 3 to 9, wherein
- the first part of the second identity data is an In- ternational Mobile Subscriber Identity for a mobile communications environment, and
- the second part of the second identity data is a Ki key for a mobile communications environment.
11. The method according to one of the claims 4 to 10, wherein at least one of the first part of the second identity data and the second part of the second identity data is encoded by the identity data providing entity (58) before being communicated to the communica- tions device (22) .
12. The method according to claim 11, wherein the at least one encoding step is carried out by using a general encoding key.
13. The method according to one of the claims 4 to 12, wherein at least one of the first part of the second identity data and the second part of the second identity data is decoded by the communications device (22) upon receipt.
14. The method according to claim 13, wherein the at least one decoding step is carried out by using a general decoding key.
15. The method according to claim 14, wherein the general decoding key is previously stored in the communications device (22) under control of the identity data provid- ing entity (58) .
16. The method according to one of the preceding claims, wherein communicating by means of the communications device (22) in the first communications environment (2) includes a step of identifying the communications de- vice (22) in the first communications environment (2) by means of the first identity data.
17. The method according to claim 16, wherein the identifying step includes to operate the communications device (22) such that the first identity data is defined as valid identity data.
18. The method according to claim 16 or 17, wherein the first identity data is communicated from the communications device (22) to a first communications system in the first communications environment (2) .
19. The method according to one of the claims 16 to 18, wherein the identifying step includes communicating first communications request data to the central entity (46) .
20. The method according to claim 19, wherein the first communications request data is communicated directly from the communications device (22) or from a first communications system in the first communications environment (2) to the central entity (46) .
21. The method according to claim 19 or 20, wherein the central entity (46) communicates erasing data to the communications device (22) in response to the first communications request data, wherein the erasing data effects removing the second identity data from the communications device (22) .
22. The method according to claim 21, wherein the erasing step includes communicating an empty identity data template replacing the stored second identity data.
23. The method according to one of the claims 16 to 22, wherein the second identity data is marked as invalid identity data.
24. The method according to claim 24, wherein the marking step is carried out by a second communications system in the second communications environment (24) upon receipt of a marking request communicated from the central entity (46) to the second communications environment (24) in response first communications request data.
25. The method according to one of the preceding claims, wherein, in preparation of communications by means of the communications device (22) in the second communications environment (24) , the request is communicated from the communications device (22) being operated in the first communications environment (2) to the central entity (46) .
26. The method according to claim 25, wherein the second identity data is communicated from the central entity (46) to the communications device (22) in the first communications environment (2) .
27. The method according to claim 25 or 26, wherein communications from the communications device (22) to the central entity (46) are carried out via a first communications system in the first communications environ- ment (2) , while communications from the communications device (46) are carried out via an identity data providing entity (58) at least as regards the second identity data.
28. The method according to claim 27, wherein communicating by means of the communications device (22) in the second communications environment (24) includes a step of identifying the communications device (22) in the second communications environment (24) by means of the second identity data.
29. The method according to claim 28, wherein the identifying step includes operating the communications device (22) such that the second identity data is defined as valid identity data.
30. The method according to claim 28 or 29, wherein the second identity data is communicated from the communications device (22) to a second communications system in the second communications environment (24) .
31. The method according to one of the claims 28 to 30, wherein the identifying step includes communicating second communications request data to the central entity (46) .
32. The method according to claim 31, wherein the second communications request data is communicated from a second communications system in the second communications environment (24) to the central entity (46) .
33. The method according to claim 31, wherein the second communications request data is communicated from the communications device (22) being operated in the second communications environment (24) directly to the central entity (46) .
34. The method according to one of the claims 31 to 33, wherein - the central entity (46) communicates, in response to the second communications request, a identity data transfer request to a first communications system in the first central entity (46) , and
- the first communications system routes, communica- tions, which are to be carried out with the communications device (22) and include first identifying data for identifying the communications device (22) in the first communications environment (2) , to the central entity (46) .
35. The method according to claim 34, wherein
- the central entity (46) replaces, in the communications routed to the central entity (46) , the first identifying data by second identifying data for identi- fying the communications device (22) in the second communications environment (24) , and
- the communications to be carried out with the communications device (22) and comprising the second identi- fying data are routed to the communications device (22) in the second communications environment (24) .
36. The method according to one of the claims 28 to 36, wherein communications to and from the communications device (22) in the second communications environment (24) are routed via the central entity (46) .
37. The method according to claim 36, wherein communications routed via the central entity (46) are at least partially routed via an SS7/C7 voice link.
38. The method according to claim 36 or 37, wherein - communications from the communications device (22) to be carried out in the second communications environment (24) include second identifying data for identifying the communications device (22) in the second communications environment (24) , - the central entity (46) replaces the second identifying data by first identifying data for identifying the communications device (22) in the first communications environment (2), and
- the central entity (46) routes the communications from the communications device (22) including the first identifying data to a communications target in the second communications environment (24) with which the communications from the communications device (22) are to be carried out .
39. The method according to one of the claims 36 to 38, wherein
- communications from the communications device (22) to be carried out in a communications environment outside the second communications environment (24) include sec- ond identifying data for identifying the communications device (22) in the second communications environment (24),
- the central entity (46) replaces the second identify- ing data by first identifying data for identifying the communications device (22) in the first communications environment (2) , and
- the central entity (46) routes the communications from the communications device (22) including the first identifying data to the communications environment outside the second communications environment (24) .
40. The method according to one of the claims 36 to 39, wherein
- communications to the communications device (22) to be carried out in the second communications environment
(24) include first identifying data for identifying the communications device (22) in the first communications environment (2) ,
- the central entity (46) replaces the first identify- ing data by second identifying data for identifying the communications device (22) in the second communications environment (24) , and
- the central entity (46) routes the communications including the second identifying data to the communica- tions device (22) .
41. The method according to one of the claims 31 to 40, wherein the central entity (46) , in response to the second communications request data, transfers communications allowance data indicating that the communica- tions device (22) is allowed to communicate from a first communications allowance data providing entity (10) associated to the first communications environment (2) to a central communications allowance data providing entity (52) associated to the central entity (46) .
42. The method according to one of the claims 31 to 40, wherein the central entity (46) , in response to the second communications request data, transfers communications allowance data indicating that the communica- tions device (22) is allowed to communicate from a first communications allowance data providing entity (10) associated to the first communications environment (2) to a second communications allowance data providing entity (32) associated to the second communications en- vironment (24) .
43. The method according to one of the preceding claims, wherein the second identity data is selected from a plurality of identity data reserved to be used as second identity data for carrying out the method.
44. The method according to one of the preceding claims, wherein communicating the communications device (22) includes operating the communications device (22) in a second identity data request mode under control of a software program associated to the communications de- vice (22) .
45. The method according to one of the preceding claims, wherein storing the second identity data in the communications device (22) includes operating the communications device (22) in a second identity data storing mode under control of a software program associated to the communications device (22) .
46. The method according to one of the preceding claims, wherein the communications device (22) is adapted to store the first identity data and a plurality of second identity data.
47. The method according to one of the preceding claims, wherein the second identity data is communicated from the central entity (46) to the communications device (22) by means of at least one of a SMS, a MMS, an e- mail and a WAP link.
48. The method according to one of the preceding claims, wherein communications to and from the communications device (22) include at least one of voice communications, SMS communications, MMS communications, e-mail communications and data communications.
49. A system, comprising
- a first communications environment (2) , - a communications device (22) , which has first identity data associated to the first communications environment (2) ,
- a second communications environment (24) to which second identity data is associated, and - a central entity (46) , wherein
- the central entity (46) is adapted to communicate, upon a request from the communications device (22) to operate the communications device (22) in the second communications environment (24) , the second identity data to the communications device (22), and
- the communications device (22) is adapted to store the second identity data.
50. The system according to claim 49, wherein, - the communications device (22) is a mobile communications device (22) ,
- the first and second communications environments (24) are mobile telephone environments, and
- the central entity (46) is an entity providing roam- ing services for the communications device (22) in the first and second communications environments (24) .
51. The system according to claim 49 or 50, further comprising a identity data providing entity (58) and wherein the request is communicated from the communica- tions device (22) to the identity data providing entity (58) and from the identity data providing entity (58) to the central entity (46) .
52. The system according to claim 51, further including a at least one first storage entity in which a first part of the second identity data is stored such that access to the first part of the second identity data by the central entity (46) and the identity data providing entity (58) is allowed and wherein the central entity (46), upon receipt of the request, retrieves the first part of the second identity data from the at least one first storage entity and communicates the second part of the second identity data to the identity data providing entity (58) .
53. The system according to claim 51 or 52, further including a second storage entity in which a second part of the second identity data is stored such that access to the second part of the second identity data by the identity data providing entity (58) is allowed and ac- cess to the second part of the second identity data by the central entity (46) is denied and wherein the identity data providing entity (58) , upon receipt of the request, retrieves the second part of the second identity data from the second storage entity.
54. The system according to claim 53, wherein the identity data providing entity (58) communicates the first part of the second identity data and the second part of the second identity data to the communications device (22) .
55. The system according to one of the claims 52 to 54, wherein
- the first part of the second identity data is an International Mobile Subscriber Identity for a mobile communications environment, and - the second part of the second identity data is a Ki key for a mobile communications environment.
56. The system according to one of the claims 52 to 55, wherein the identity data providing entity (58) com- prises an encoding unit for encoding at least one of the first part of the second identity data and the second part of the second identity data before being communicated to the communications device (22) .
57. The system according to claim 56, wherein the encoding unit comprises a general encoding key.
58. The system according to one of the claims 52 to 57, wherein the communications device (22) comprises a decoding unit for decoding at least one of the first part of the second identity data and the second part of the second identity data.
59. The system according to claim 58, wherein the decoding unit comprises a general decoding key.
60. The system according to one of the claims 49 to 59, further comprising a first communications system in the first communications environment (2) .
61. The system according to claim 60, further comprising a first voice communications link between the first communications system and the central entity (46) .
62. The system according to one of the claims 49 to 61, further comprising a second communications system in the second communications environment (24) .
63. The system according to claim 62, further comprising a second voice communications link between the second communications system and the central entity (46) .
64. The system according to one of the claims 61 to 63, wherein at least one of the first communications link and the second communications link is an SS7/C7 voice link.
65. The system according to one of the claims 49 to 64, further comprising a first communications allowance data providing entity (10) associated to the first communications environment (2) .
66. The system according to one of the claims 49 to 65, further comprising a second communications allowance data providing entity (32) associated to the second communications environment (24) .
67. The system according to one of the claims 49 to 66, further comprising a central communications allowance data providing entity (52) associated to the central entity (46) .
68. The system according to one of the claims 65 to 67, further including at least one secured data link between at least two of the communications allowance data providing entities.
69. The system according to claim 68, wherein at least one of the at least one secured data link is at least one of an n x 64 Kbps data link and a tunneling Internet connection.
70. The system according to one of the claims 49 to 69, being adapted to be operated according to the steps according to one of the claims 1 to 48.
71. A software program comprising instructions that enable a system or a device to carry out a method according to one of the claims 1 to 48.
72. The software program according to claim 71, being stored on a computer readable storage medium, on a computer readable storage device or and being downloadable from a computer network.
73. A communications device (22) being adapted to carry out the steps according to one of the claims 1 to 48 as far as relating to a communications device (22) .
74. The communications device (22) according to claim 73, comprising software program portions of the software program according to claim 71 or 72 as far as relating to a communications device (22) .
75. A central entity (46) being adapted to carry out the steps according to one of the claims 1 to 48 as far as relating to a central entity (46) .
76. The central entity (46) according to claim 75, comprising software program portions of the software program according to claim 71 or 72 as far as relating to a central entity (46) .
77. A communications environment being adapted to carry out the steps according to one of the claims 1 to 48 as far as relating to a communications environment.
78. The communications environment according to claim 77, comprising software program portions of the software program according to claim 71 or 72 as far as relating to a communications environment.
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/IB2005/001660 WO2006095216A1 (en) | 2005-03-11 | 2005-03-11 | Communications method and system |
Publications (1)
Publication Number | Publication Date |
---|---|
EP1856936A1 true EP1856936A1 (en) | 2007-11-21 |
Family
ID=35079404
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
EP05744773A Withdrawn EP1856936A1 (en) | 2005-03-11 | 2005-03-11 | Communications method and system |
Country Status (2)
Country | Link |
---|---|
EP (1) | EP1856936A1 (en) |
WO (1) | WO2006095216A1 (en) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104519480B (en) * | 2014-12-30 | 2016-02-17 | 悠游宝(天津)网络科技有限公司 | Communication control unit, authentication device, central controller and communication system |
-
2005
- 2005-03-11 WO PCT/IB2005/001660 patent/WO2006095216A1/en not_active Application Discontinuation
- 2005-03-11 EP EP05744773A patent/EP1856936A1/en not_active Withdrawn
Non-Patent Citations (1)
Title |
---|
See references of WO2006095216A1 * |
Also Published As
Publication number | Publication date |
---|---|
WO2006095216A1 (en) | 2006-09-14 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US7289805B2 (en) | Method and system for providing a temporary subscriber identity to a roaming mobile communications device | |
KR100683976B1 (en) | Method, arrangement and apparatus for authentication | |
US9047444B2 (en) | Mobile application registration | |
US8385889B2 (en) | Radio communications system and method | |
US7363056B2 (en) | Method and system for secured duplication of information from a SIM card to at least one communicating object | |
CN102960004B (en) | The method making mobile device across a network access MSISDN on server | |
US20070293192A9 (en) | Identification of a terminal to a server | |
JP3884432B2 (en) | Telecommunications method, identification module, and computerized service unit | |
US9456409B2 (en) | Method and system for roaming of a mobile communications unit | |
US6141544A (en) | System and method for over the air activation in a wireless telecommunications network | |
US6195547B1 (en) | System and method for a previously activated mobile station to challenge network mobile station knowledge during over the air activation | |
US20100173609A1 (en) | Method and Apparatus for Secure Immediate Wireless Access in a Telecommunications Network | |
WO1998012891A1 (en) | Preventing misuse of a copied subscriber identity in a mobile communication system | |
CN101563944A (en) | IMSI handling system | |
GB2378095A (en) | Re-registering a SIM card with a new home network | |
JPWO2007058024A1 (en) | Mobile communication system, core network, radio network system and method for selecting accommodation network | |
CN1795656B (en) | Method for safely initializing user and confidential data | |
WO2010015883A1 (en) | A sim card personalization system | |
US20050102519A1 (en) | Method for authentication of a user for a service offered via a communication system | |
WO2006095216A1 (en) | Communications method and system | |
JP2006345343A (en) | Roaming method, radio communication system, and mobile | |
EP1413160B1 (en) | System, method and smart card for accessing a plurality of networks | |
CN109121132A (en) | A kind of information processing method, device and computer readable storage medium | |
KR101212131B1 (en) | Method And System for Providing Address Modification Service by Using Short Message Service | |
KR100362576B1 (en) | Method for providing otasp service in radio telecommunication system |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
17P | Request for examination filed |
Effective date: 20070911 |
|
AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU MC NL PL PT RO SE SI SK TR |
|
DAX | Request for extension of the european patent (deleted) | ||
RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04W 8/08 20090101AFI20090803BHEP |
|
GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
18D | Application deemed to be withdrawn |
Effective date: 20100205 |