WO2007036623A2 - Authentification unique pour acces reseau et enregistrement a un service de telecommunication - Google Patents

Authentification unique pour acces reseau et enregistrement a un service de telecommunication Download PDF

Info

Publication number
WO2007036623A2
WO2007036623A2 PCT/FR2006/002123 FR2006002123W WO2007036623A2 WO 2007036623 A2 WO2007036623 A2 WO 2007036623A2 FR 2006002123 W FR2006002123 W FR 2006002123W WO 2007036623 A2 WO2007036623 A2 WO 2007036623A2
Authority
WO
WIPO (PCT)
Prior art keywords
network
terminal
message
service
address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/FR2006/002123
Other languages
English (en)
Other versions
WO2007036623A3 (fr
Inventor
Claire Duranton
Bernard Massicot
Frédéric JACQ
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
France Telecom SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by France Telecom SA filed Critical France Telecom SA
Publication of WO2007036623A2 publication Critical patent/WO2007036623A2/fr
Publication of WO2007036623A3 publication Critical patent/WO2007036623A3/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities

Definitions

  • the present invention relates to managing access to a network and recording to a telecommunication service for a terminal.
  • a terminal authentication method is conventionally implemented before allowing the terminal access to a network and also a method before registering the terminal with a telecommunication service offered in the terminal. network.
  • EAP Extensible Authentication Protocol
  • RFC 3748 for 'Request For Comment' of I 1 IETF for 'Internet Engineering Task Force'
  • EAP is unique in that it defines generic exchanges for carrying various authentication methods.
  • EAP supports several authentication methods, for example and non-exhaustively EAP MD5-Challenge from I 1 IETF RFC 3748, EAP-AKA from I 1 IETF http://www.ietf.org/internet-drafts/draft -arkko-pppext-eap-aka-15.txt.
  • a client connects to an access controller.
  • the latter queries an AS Authentication Server.
  • the client sends the access controller its identity, which is then transmitted to the authentication server.
  • the server authenticates the client by applying an authentication method.
  • an access control protocol is generally set up integrating a method of authentication of the network terminal.
  • An access control protocol such as the IEEE 802.1X standard defined by the IEEE (for the Institute of Electrical and Electronics Engineers) or a protocol of the type PANA (for Protocol for carrying Authentication for Network Access) can be used. ') defined in RFC 4058.
  • Access control protocols are usually based on an EAP protocol and an authentication method associated, for example EAP-AKA.
  • a terminal Once a terminal is allowed to access a network, it can then register with services offered in the network so that it can benefit. At this stage, too, a phase of authentication of the terminal is generally implemented before the registration of the terminal to a service.
  • a terminal wishing to access a service offered in a network may therefore be required to be authenticated twice in the same network, a first time to access the network and a second time to access the required service.
  • the terminal is again invited to a new authentication within another session to register. the terminal to a service offered in the same network.
  • IP for 'Internet Protocol'
  • MIP for 'Mobile Internet Protocol'
  • a first authentication procedure is then set up to control access to the network; then, a second authentication procedure is set up to decide whether to register this terminal to the MIP service in this network.
  • Figure 1 illustrates a network architecture for implementing an access control and then a registration to a MIP service.
  • a first network 12 comprises a server 17 managing the IP mobility service for the terminals belonging to the network 12.
  • a server is classically called 'Home Agent' or HA.
  • a terminal 10 belonging to the first network 12 that is to say having an IP address in this first network, wishes to register via a second network 13 with the MIP service, the second network 13 being connected to the first network 12. Registration with the MIP service is preceded by access control to the second network 13 for the terminal 10.
  • Such a MIP service allows the terminal 10 having a first address in the first network 12, or nominal network, to keep this same first address vis-à-vis other equipment with which it communicates when connected via another network in which it has a second address.
  • a message sent to the first address of the terminal 10 is routed to the second address of the terminal in the second network 13.
  • the second network 13, or visited network comprises a gateway 14 and a server 16 able to communicate with a server 15 of the nominal network 12. It also comprises an access controller 11 able to carry out the access control to the second network 13 of the terminal 10.
  • the servers 16 and 15 are AAA type servers (for 'Authentication, Authorization and Accounting'), so that the first and second networks can cooperate with each other.
  • the servers 15 and 16, respectively referenced AAAH (for 'AAA Home') and AAA F (for 'AAA Foreign') can communicate with each other on the basis of a protocol AAA type for transporting between several networks functions of authentication. Diameter, as defined in RFC 3588, is an example of a protocol that provides this function.
  • FIG. 2 represents an exchange of messages corresponding to the architecture illustrated in FIG.
  • This exchange of messages can be described in two successive phases, a first phase corresponding to a network access control of the terminal and a second phase corresponding to the registration of the terminal to the MIP service.
  • the first phase is performed within a session according to the EAP protocol which is opened with a message 201 'Request identity' then closed with a message 213 'Success'.
  • the second phase is performed according to the MIP protocol.
  • the exchange of messages within the first and second networks, and between the first and second networks, is based on Diameter protocol applications called Diameter-EAP and Diameter-MIP.
  • EAP-AKA The exchange of messages during the first phase of control Access uses a particular authentication method: EAP-AKA. Another method of EAP authentication could be used.
  • the terminal associates with the network 13 via the access controller 11.
  • the access controller 11 transmits the message 201 to the terminal according to the EAP protocol by which it requires an identifier of the terminal 10.
  • the latter responds to this request by sending a message 202 according to the EAP protocol 'Response Identity' in which it transmits an identifier.
  • the access controller 11 relays this message to the server AAAF 16 by a message 203.
  • the server 16 relays this message 203 to the server AAAH 15 by a message 204.
  • the messages 203 and 204 can be transmitted to the server AAAH 15.
  • message exchange 201 and 202 relating to the identity of the terminal 10.
  • These messages 203 and 204 are issued according to a Diameter-EAP application by encapsulation of messages of the EAP session.
  • the server 15 initiates an authentication phase of the terminal in which it requires certain information via a message 205 sent to the terminal 10 and transiting according to the Diameter-EAP protocol according to a message of the type 'Diameter-EAP-Answer / AKA Challenge' by the server AAA F 16, then by the access controller 11, in the form of the messages 205 and 206. Then, the access controller 11 relays the message 206 to the terminal 10 according to the EAP protocol in the form of a message 207 type ⁇ AP-Request / AKA Challenge '.
  • the terminal 10 On receipt of this message 207, the terminal 10 sends a message 208 ⁇ AP-Response / AKA Challenge 'according to the EAP protocol, thus transmitting to the AAAH server 15 information relating to its authentication prior to its access to the network.
  • This message is relayed to the AAAF server 15 successively by the access controller 11 and then by the server 16, according to the Diameter-EAP protocol in the form of the messages 209 and 210 of the 'Diameter-EAP-Request' type.
  • the AAAH server 15 Upon receipt of this message 210, the AAAH server 15 authenticates the terminal 10, then decides to allow the terminal 10 to access the network 13. It responds by sending a message 211 to the terminal 10, which is relayed by the AAAF server 16 to the access controller 11 by a message 212, the messages 211 and 212 being of type 'Diameter-EAP- Answer / DIAMETER_SUCCESS' according to the Diameter-EAP application.
  • the access controller 11 relays the message 212 to the terminal 10 in the form of a message 213 according to the EAP protocol type 'EAP-Success'. This message terminates the EAP session, opened with message 201.
  • An optional message exchange referenced 214 corresponds to an exchange of information intended to enable the terminal to encrypt the information transmitted on the network.
  • the terminal 10 has access to the network 13. It is therefore able to register with the MIP service that is managed at the HA server 17 in its nominal network.
  • the second phase corresponding to the registration of the terminal with the MIP mobility service can then begin.
  • This second part is based on the Diameter-MIP protocol, as defined for example in RFC 4004 'Diameter Mobile IPv4 application', which corresponds to an application of the Diameter protocol to the transport of data relating to the MIP service.
  • Such a protocol is based on the Diameter protocol as well as RFC 3957 'AAA Registration Keys for Mobile IPv4'.
  • the gateway 14 assigns a second address to the terminal in the second network that it visits and informs the terminal. For this purpose, the gateway 14 transmits to the terminal 10 a message 215 according to the MIP protocol type 'MIP RA' (for 'MIP Router Advertisement'), containing the second address, or address CoA (for 'Care of Address' ').
  • MIP protocol type 'MIP RA' for 'MIP Router Advertisement'
  • CoA for 'Care of Address' '
  • the terminal On receipt of this message 215, the terminal transmits to the nominal network a message 216 for registration request to the MIP service according to the MIPv4 protocol type 'RRQ' (for 'Registration ReQuest').
  • This last message is relayed by the gateway 14 to the server AAAF 16 by a message 217 according to the protocol Diameter-MIP type 'AMR' (for 'AA Mobile Node Request').
  • the server 16 relays this message to the server AAAH 15 by a message 218 according to the Diameter-MIP protocol 'AMR'.
  • the AAAH server 15 authenticates the terminal 10.
  • the HA server 17 sends the HA server 17 a message 219 according to the Diameter-MIP protocol ⁇ AR '(for' Home Agent MIP Request ').
  • the HA server 17 is then able to associate the IP address, CoA, of the terminal 10 in the visited network 13 and the IP address of the terminal 10 in the nominal network 12 (the term commonly used for this association of addresses is the English term 'binding').
  • Such a step corresponds to the registration of the terminal 10 to the MIP service.
  • this recording is acknowledged by the HA server 17 in the form of a message 220 according to the Diameter-MIP protocol 'HAA' (for 'Home Agent MIP Answer') which is relayed by the AAAH server 15 and then by the server AAAF in the form of the message 221 and the message 222, to the gateway 14.
  • the gateway 14 transforms the message 222 to the terminal 10 in the form of a message 223 according to the MIP protocol type 'RRP' (for 'Registration RePIy ').
  • the latter message 223 terminates the second phase corresponding to the registration of the terminal with the MIP service managed by the HA server 17.
  • such a mechanism implements two successive phases, a first phase relating to the access to the network of the terminal, and a second phase relating to the registration of the terminal to a service, each of these phases being carried out on the base of a terminal authentication managed by the AAAH server 15 in the nominal network 12.
  • the present invention aims to simplify the mechanism of network access and registration to a service of a terminal.
  • a first aspect of the present invention provides a method of managing access to a network and recording to a telecommunication service for a terminal belonging to a first telecommunication network.
  • the first network includes an authentication function of the terminal and offers the telecommunication service.
  • the method is characterized in that access to the network and recording at the service are managed in a common phase for the terminal; the phase comprising the following steps:
  • Ib on receiving said first message in the first network, decide, on the basis of said authentication function and the information included in said first message, to allow the terminal to access the second network and to record the terminal to said service ;
  • Id to receive on the terminal from the first network via said second network a second message allowing the terminal to access the second network and indicating the registration of the terminal said service.
  • the second network before step / a / and after a phase of identification of the terminal by the second network, the second network sends an initiation message to the terminal so as to detect if the terminal is adapted to handle the steps / a / to Here and to send to the terminal information to generate the first message.
  • the telecommunication service offered in the first network may allow the terminal to receive messages, initially addressed to a first address of the terminal in the first network, to a second address in the second network. Registration to the service then comprises an association of the first and second addresses (in English 'binding').
  • the second address can then be allocated and sent to the terminal in an initiation message by the second network, and the second address is retrieved and included in the first message.
  • the terminal and the second network can communicate according to an EAP type protocol, the first message being a 'Response' type message.
  • the initiation message can be a 'Request' type message according to an EAP type protocol
  • a second aspect of the present invention provides a terminal in a first telecommunication network comprising a terminal authentication function and providing a telecommunication service.
  • the terminal comprises: a transmission unit adapted to transmit to the first network, via a second network connected to said first network, a first message comprising information indicating both a network access request and a registration request to said network; service; a reception unit adapted to receive from the first network via said second network a second message allowing the terminal to access the second network and indicating the registration of the terminal to said service.
  • the terminal may further comprise a message generation unit adapted to retrieve information from an initiation message sent from the second network and received by the receiving unit, and to generate the first message based on said recovered information.
  • a message generation unit adapted to retrieve information from an initiation message sent from the second network and received by the receiving unit, and to generate the first message based on said recovered information.
  • a third aspect of the present invention provides a telecommunication gateway adapted to cooperate with a terminal belonging to a first network comprising an authentication function of the terminal and offering a telecommunication service.
  • the gateway belongs to a second network and includes: a reception unit adapted to receive, on the one hand from said terminal a first message, intended for the first network, comprising information indicating both a network access request and a registration request to a telecommunication service, and on the other hand, from the second network a second message allowing the terminal to access the second network and indicating the registration of the terminal to said service; and a transmission unit adapted to transmit to the first network said first message and to transmit to the terminal said second message transmitted by the first network.
  • the gateway may comprise, when the telecommunication service allows the terminal to receive messages initially addressed to a first address of the terminal in the first network on a second address in the second network, on the one hand, an allocation unit of an address adapted to assign the second address of the second network to the terminal, the transmission unit being adapted to transmit to the terminal the second address assigned by the assignment unit in an initiation message, and on the other hand, a conversion unit adapted to convert the first message received by the reception unit and transmitted by the terminal, into a converted message to the first network, and adapted to convert the second message received by the reception unit and transmitted by the first network via the second network into a converted message to the terminal.
  • a fourth aspect of the present invention provides a network access management and telecommunication service registration system for a terminal, according to the second aspect, belonging to a first telecommunication network.
  • the first network includes an authentication function of the terminal and offers the telecommunication service.
  • the system is characterized in that it provides the terminal, in a common phase, on the one hand access to the second network and on the other hand a registration to the service.
  • the second network may comprise a telecommunication gateway having: a reception unit adapted to receive, on the one hand from said terminal, a first message intended for the first network, comprising information indicating on the one hand a request network access and secondly a registration request to a telecommunication service, and secondly, from the second network a second message allowing the terminal to access the second network and indicating the registration of the terminal auditing. service; and a transmission unit adapted to transmit to the first network said first message and to transmit to the terminal said second message transmitted by the first network.
  • the gateway may comprise, when the telecommunication service allows the terminal to receive messages initially addressed to a first address of the terminal in the first network on a second address in the second network, on the one hand a unit of assignment of address adapted to assign the second address of the second network to the terminal, the transmission unit being adapted to transmit to the terminal said second address assigned by the assignment unit in an initiation message, and secondly a conversion unit adapted to convert the first message received by the reception unit and transmitted by the terminal into a converted message to the first network and to convert the second message received by the reception unit and transmitted by the first network via the second network in a converted message to the terminal.
  • a fifth aspect of the present invention proposes a computer program product intended to be installed in a terminal, comprising instructions able to implement the method according to the first aspect, during execution of the program by means of processing the program. terminal.
  • a sixth aspect of the present invention proposes a computer program product intended to be installed in a gateway, comprising instructions able to implement the method according to the invention.
  • first aspect during execution of the program by means of processing the gateway.
  • Figure 3 illustrates the main steps of a method according to an embodiment of the present invention
  • Figure 4 illustrates an architecture of a system according to an embodiment of the present invention
  • Fig. 5 illustrates a message exchange according to a method according to an embodiment of the present invention
  • Figure 6 illustrates a telecommunication gateway according to an embodiment of the present invention
  • Fig. 7 illustrates a terminal according to an embodiment of the present invention.
  • the invention is described hereinafter in its application to telecommunication networks offering a mobility service on the IP protocol (for 'Internet Protocol'), such as a MIP-type service as described in previous sections.
  • IP protocol for 'Internet Protocol'
  • MIP-type service as described in previous sections.
  • An object of the present invention is to provide a mechanism for increasing the efficiency of network access management and telecommunications service management for the terminals, while maintaining a security level in the networks. .
  • Such a mechanism rests, from the point of view of a terminal, on the management of both a network access request and a registration request to a service, in a single phase, by the implementation of a procedure of single sign-on for both network access control and service registration.
  • Figure 3 illustrates the main steps of a method according to an embodiment of the present invention.
  • a terminal 30 (or MN for 'Mobile Node') according to one embodiment of the present invention transmits to a first network 12 a first message 31 via a second network 43.
  • the network 12 includes an authentication function 33 of a terminal and offers a telecommunication service 34.
  • the second network decides to register the terminal with the service 34.
  • the first network 12 sends a second message 32 to the terminal 30, the second message allowing access to the network to the terminal and indicating the registration of the terminal with the service 34.
  • the terminal 30 in a single phase started with the first message 31 and then terminated with the second message 32, the terminal 30 obtains network access and registration with the service 34.
  • FIG. 4 illustrates an architecture of a system according to an embodiment of the present invention in its application to the MIP mobility service, the present invention not being limited to this type of service.
  • the first network 12 or nominal network of the terminal 30 is similar to that described above with reference to FIG. 1.
  • This nominal network is connected to a second network 43, corresponding to the network visited by the terminal.
  • the latter comprises the AAAF server 16 communicating with the AAAH server 15, thus enabling the two networks 43 and 12 to link.
  • the second network 43 comprises a gateway 44 intended to manage an interface between the terminal 30 and the second network 43.
  • a terminal 30 wishes to access the network 43 and benefit from a mobility management service on the IP protocol offered by the network 12.
  • a mobility management service on the IP protocol offered by the network 12.
  • the terminal having a first address in its nominal network 12, can keep this address to other devices in the network with which it exchanges data even when it moves to another network, as described in previous sections.
  • Such a service can be implemented on the basis of a protocol of MIPv4 type (for 'Mobile IP version 4'), such as that defined in RFC 3344.
  • the terminal attaches to the visited network, corresponding to the second network 43, and retrieves a second IP address (CoA) in this network 43. Then, it registers with the HA server 17 which is by indicating the CoA address he obtained in the visited network.
  • the HA server 17 manages an association of the first address and the second address (or 'binding').
  • the two networks cooperate with each other on the basis of an Authentication, Authorization and Accounting 1 (AAA) protocol, for example, Diameter, to provide AAA capabilities for authenticating users and to allow them access to certain services.
  • AAA Authentication, Authorization and Accounting 1
  • the present invention covers any type of protocol that makes it possible to implement a cooperation of networks of this type.
  • the present invention is described in its application to the Diameter protocol and the Diameter-MIP application which is adapted for to convey Mobile IP data securely regardless of the networks visited, but this invention is not limited to such an application.
  • the gateway 44 preferably comprises an entity 44a adapted to implement both access control functions in accordance with the access controller 11 according to FIG. 1, an entity 44b adapted to implement authentication functions and an entity 44c adapted to implement Foreign Agent (FA) server functions for managing the terminal 30 and Client functions according to a Diameter-MIP type protocol to communicate with the AAAp server 16.
  • FA Foreign Agent
  • the entities 44a, 44b and 44c can be co-located as is the case in the illustrated architecture. They can also be located at different locations in the visited network.
  • the HA server 17 is further adapted to implement an Agent Diameter-MIP type function with the AAAH server 15.
  • FIG. 5 illustrates the message exchanges between these different network entities for the implementation of a method according to an embodiment of the present invention.
  • the terminal 30 associates with the network.
  • Such a step may be performed according to a given association procedure a 802.11 protocol defined by IEEE I 1.
  • the network 43 requests the terminal 30 an identifier.
  • the gateway 44 sends to the terminal a message 502 'Request Identity' according to an EAP type protocol such as that defined in a previous section. An EAP session is thus opened.
  • the terminal 30 responds to this message by transmitting to the gateway information relating to its identity by sending a message 503. This message can be sent according to the EAP protocol in the form of a 'Response Identity' message.
  • This information relating to the identity of the terminal may in particular comprise a network access identifier or NAI for 'Network Access Identifier', which identifies, among other things, the nominal network 12 of the terminal 30. More generally, such information allows to identify the network in which a terminal authentication procedure can be implemented for access to the network as well as for registration to the required service.
  • This message 503 is received by the entity 44a before being relayed to the entity 44b.
  • the gateway 44 initiates a network access and registration mechanism to the mobility service according to an embodiment of the present invention, i.e. in a single phase from the point of view of the terminal.
  • This mechanism can be initiated by sending a message 504 to the terminal 30.
  • this message is a request message according to the EAP protocol, which proposes to the terminal 30 a network access and one-phase service registration according to an embodiment of the present invention. It preferably indicates an identifier of the mechanism according to the invention which enables the terminal 30 to indicate to the gateway whether it is able to manage such a mechanism.
  • the identifier of the mechanism according to the invention contained in the initiation message 504 indicates the use of a particular EAP method, denoted EAP-MIP in FIG. exchange of information between the terminal 30 and the gateway 44.
  • the initiation message 504 contains information on the second network 43 enabling the terminal 30 to implement said mechanism.
  • the initiation message 504 contains the second address, or CoA, allocated to the terminal by the second network 43.
  • the network 43 is informed and can then propose a network access mechanism and a service record in two phases such as that described above with reference to Figures 1 and 2.
  • the terminal 30 is adapted to manage a mechanism for accessing the network and recording the service in one phase according to one embodiment of the invention. It then responds to this message with a message 505 which is a message of the type 'Response' according to the EAP protocol. In one embodiment of the invention, this message contains information similar to that contained in the message 216 as described with reference to FIG. 2. This message may correspond to an encapsulated MIP Registration Request MIP message. in a message "AP-Response / EAP-MIP".
  • the terminal 30 retrieves the CoA address assigned to it by the second network 43 and sent to it in the message 504. Therefore, in such an embodiment, the message 505 includes a field corresponding to the CoA address of the terminal 30 in the network 43 which is filled by the terminal from the information sent by the gateway 44 in the message 504.
  • the entity 44a Upon receipt of this message 505, the entity 44a extracts the information relating to the MIP registration request ( 1 EAP-M IP / RRQ ') and relays it to the entity 44b which processes the message and transmits it to the entity 44c.
  • Entity 44c is adapted to act as a Diameter-MIP client. It is therefore able to generate a message 506 corresponding to a registration request to the MIP service for the terminal 30.
  • the message 506 indicates the second address, or CoA.
  • This message may be issued as a 507 'AA-Mobile-Node-Request - AMR' message according to the Diameter-MIP protocol to the visited network server AAAF 16.
  • the server AAAF 16 analyzes the content of the received message 506 and extracts the information relating to the MIP record from which it deduces the nominal network corresponding to the terminal 30. The server 16 then routes to the nominal network 12 the request of recording to the MIP service in the form of a 507 message according to the Diameter-MIP / AMR protocol to the Diameter server 15 of the nominal network, 'AA-Mobile-Node-Request - AMR'.
  • the AAAH server 15 analyzes the contents of the registration request message 507 to the MIP service. It then retrieves the information relating to the authentication of the terminal 30 and the MIP registration request. At this point, if the AAA server H 15 authenticates the terminal 30, it then generates encryption information to establish MSAs (for 'Mobile Security Association') for the terminal with the entity 44c which acts as a 'Foreign' server. Agent 'according to the MIP service, and with the HA server 17.
  • the authentication function of the terminal is located at the AAAH server 15 in the first network.
  • This example is not limiting. Indeed, such an authentication function of the terminal 30 can be implemented at the level of the HA server 17.
  • the present invention covers all the locations of the authentication function of the terminal 30 within the first network 12.
  • the server 15 can associate a single use encryption information (the term commonly used is the English term 'Nonce').
  • the registration request of the terminal 30 is sent to the HA server 17, in a message 508 following the Diameter-MIP protocol 'HAR Registration Request' (for 'Home-Agent-MIP-Request Registration Request').
  • This registration request contains the MSAs secure associations and previously generated nonces relating to the relationships between the HA server 17 and the terminal 30 as well as between the HA server 17 and the entity 44c of the gateway 44.
  • the HA server 17 Upon receipt of the message 508, the HA server 17 retrieves the registration request. Then, it registers the terminal 30 to the MIP service by associating the IP address, CoA, of the terminal 30 in the visited network 43 and the IP address of the terminal 30 in the nominal network 12 (in English, 'binding'). The HA server 17 also stores the MSAs secure associations and the nonces that have been associated with it for this record.
  • the HA server 17 returns a registration acceptance message 509 according to the Diameter-MIP protocol 'HAA Registration Reply'.
  • This message may further include the first address of the terminal 30 in the nominal network 12.
  • the server 15 AAAH retrieves the information received in the message 509 'HAA Registration Reply' and encapsulates them according to the protocol Diameter-MIP in an AMA type message 510 for 'AA-Mobile-Node-Answer', preferably adding the MSAs secure associations and the encryption information (nonces or keys) from the authentication process of the terminal 30.
  • the AAAF server 16 relays this message 510 to the entity 44c in the form of a message 511 according to the Diameter-MIP protocol.
  • the entity 44c analyzes the contents of the message 511 to extract the information relating to the acceptance of the registration to the MIP service, the secure associations and the encryption information that will allow it to have a secure relationship with the HA server 17 and with the terminal 30
  • the entity 44c transmits the registration acceptance information to the MIP service, the secure associations and the encryption information to the entity 44b.
  • the latter transmits, to the terminal via the entity 44a, this information in a message 512 according to the EAP protocol ⁇ AP-Request '(EAP-MIP / RRP).
  • the terminal retrieves the registration confirmation information from the MIP mobility service, with the secure association information (MSAs) and the encryption information, that is, the nuncios and / or encryption keys, which will allow it to have secure exchanges with the HA server 17 as well as the 44c entity of the gateway 44 which acts as server 'FA.
  • MSAs secure association information
  • the encryption information that is, the nuncios and / or encryption keys
  • the terminal acknowledges the receipt of this message 512 by sending a message 513 according to the EAP protocol 'EAP-Response' (EAP-MIP / End).
  • the gateway 44 sends a message 514 ⁇ AP-Success' to the terminal 30.
  • the terminal 30 On receipt of this message 514 'EAP-Success', the terminal 30 has access to the network 43 and can use the telecommunication service with which it is registered. .
  • the result obtained at the end of the two phases described with reference to FIG. 2 is, in one embodiment of the present invention, obtained in a single phase from the point of view of the terminal.
  • One embodiment of the present invention is easy to implement in an existing network. Indeed, the establishment of such a mechanism requires only simple modifications on the one hand of the gateway and the other terminal.
  • Fig. 6 shows a gateway according to an embodiment of the present invention.
  • the gateway comprises a reception unit 61 adapted to receive, from the terminal, a message 505, intended for the first network 12, comprising information indicating, on the one hand, a network access request and, on the other hand, a registration request. to a telecommunication service.
  • the information corresponding to the network access request includes the second address, or CoA, which has previously been allocated by the second network. This second address can be sent to the terminal in an initiation message such as the message 504 described with reference to FIG.
  • This receiving unit is also adapted to receive the second message 511 allowing the terminal to access the second network and indicating the registration of the terminal to the service. It further comprises an address assignment unit 62 adapted to assign an address of the second network to the terminal. It also comprises a conversion unit 60 adapted to convert or encapsulate the message 505, received by the reception unit and emanating from the terminal, into a message 506 intended for the first network and the message 511 received by the unit. receiving the server 16 in a message 512 to the terminal 30, and converting the second message 511, received by the receiving unit and transmitted by the first network via the second network to a converted message 512 to the terminal. For example, the message 506 includes in particular the address of the network assigned by the assignment unit. It may also include a transmission unit 63 adapted to transmit to the first network the first message thus modified and to transmit to the terminal an initiation message 504 which includes information such as the CoA address of the terminal.
  • FIG. 7 represents a terminal according to one embodiment of the present invention having a transmission unit 70 adapted to transmit to the first network 12, via the second network 43 connected to the first network, the first message 505 comprising information indicating both a network access request and a registration request to said service. It also comprises a reception unit 71 adapted to receive from the second network an initiation message 504 including the address CoA. It is also adapted to receive, from the first network via the second network, a second message 512 allowing the terminal to access the second network and indicating the registration of the terminal to the service. It may further comprise a generation unit 72 adapted to extract from an initiation message 504 received by the reception unit 71, the address CoA and to assign said address in a field of the first message 505.
  • the gateway on detection of a non-adapted terminal, proposes to this terminal a network access mechanism and registration to the existing service, such as that described at the beginning of the description in two phases.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

Un terminal (30) appartient à un premier réseau de télécommunication (12), qui comprend une fonction d'authentification (33) du terminal et qui offre un service de télécommunication (34). D'une part l'accès au réseau et d'autre part l'enregistrement au service sont gérés en une phase commune pour le terminal (30). Dans cette phase, on émet depuis le terminal à destination du premier réseau, via un second réseau (43) relié au premier réseau, un premier message (31) comprenant des informations indiquant une requête d'accès réseau et une requête d'enregistrement au service. Puis, sur réception du premier message dans le premier réseau, on décide, sur la base de la fonction d'authentification et des informations comprises dans le premier message, d'autoriser Ie terminal à accéder au second réseau et d'enregistrer le terminal au service. Ensuite, on reçoit sur le terminal depuis le premier réseau via le second réseau un second message (32) permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal au service.

Description

AUTHENTIFICATION UNIQUE POUR ACCES RESEAU ET ENREGISTREMENT A UN SERVICE DE TELECOMMUNICATION
La présente invention concerne une gestion de l'accès à un réseau et de l'enregistrement à un service de télécommunication pour un terminal.
Afin de sécuriser les réseaux de télécommunication, on met en œuvre classiquement une méthode d'authentification du terminal avant de permettre à ce terminal l'accès à un réseau et également une méthode avant d'enregistrer le terminal à un service de télécommunication offert dans le réseau.
De nombreux protocoles sont à la disposition de l'homme du métier pour permettre une authentification d'un terminal avant d'autoriser son accès au réseau. On connaît notamment le protocole EAP (pour 'Extensible Authentication Protocol') pour lequel la RFC 3748 (pour 'Request For Comment' de I1IETF pour 'Internet Engineering Task Force') fournit une définition. EAP a ceci de particulier qu'il définit des échanges génériques permettant de transporter diverses méthodes d'authentification. EAP supporte plusieurs méthodes d'authentification, par exemple et de façon non exhaustive EAP MD5-Challenge issue de I1IETF RFC 3748, EAP-AKA issue de I1IETF http://www.ietf.org/internet-drafts/draft-arkko-pppext-eap-aka-15.txt.
Selon le protocole EAP, un client se connecte à un contrôleur d'accès. Ce dernier interroge un Serveur d'Authentification AS. Sur requête, le client envoie au contrôleur d'accès son identité qui est ensuite transmise au serveur d'authentification. En fonction de l'identité reçue, le serveur authentifie le client en appliquant une méthode d'authentification.
Plus précisément, avant d'autoriser un terminal à accéder à un réseau, on met en général en place un protocole de contrôle d'accès intégrant une méthode d'authentification du terminal réseau. On peut utiliser un protocole de contrôle d'accès tel que le standard IEEE 802.1X défini par l'IEEE (pour Mnstitute of Electrical and Electronics Engineers'), ou encore un protocole du type PANA (pour 'Protocol for carrying Authentication for Network Access') défini dans la RFC 4058. Les protocoles de contrôle d'accès sont en général basés sur un protocole de type EAP et une méthode d'authentification associée, par exemple EAP-AKA.
Puis, une fois qu'un terminal est autorisé à accéder à un réseau, il peut alors s'enregistrer auprès de services offerts dans le réseau de façon à pouvoir en bénéficier. A cette étape, également, une phase d'authentification du terminal est généralement mise en œuvre avant l'enregistrement du terminal à un service.
Un terminal souhaitant accéder à un service offert dans un réseau, peut donc être amené à être authentifié deux fois dans le même réseau, une première fois pour accéder au réseau et une seconde fois pour accéder au service requis. Ainsi, après une authentification au sein d'une session selon le protocole EAP visant à contrôler un accès au réseau telle que détaillée dans une section précédente, on invite à nouveau le terminal à une nouvelle authentification au sein d'une autre session visant à enregistrer le terminal à un service offert dans le même réseau.
Tel est le cas, par exemple dans un réseau IP (pour 'Internet Protocol'), lorsque le terminal souhaite bénéficier d'un service de mobilité sur IP tel que MIP (pour 'Mobile Internet Protocol'). Un tel service est défini par exemple dans la RFC 3344 'MIPv4'. Une première procédure d'authentification est alors mise en place pour contrôler un accès au réseau ; puis, une seconde procédure d'authentification est mise en place pour décider si on enregistre ce terminal au service MIP dans ce réseau.
La figure 1 illustre une architecture de réseau permettant la mise en œuvre d'un contrôle d'accès puis d'un enregistrement à un service MIP.
Un premier réseau 12 comprend un serveur 17 gérant le service de mobilité sur IP pour les terminaux appartenant au réseau 12. Un tel serveur est classiquement appelé 'Home Agent' ou encore HA. Un terminal 10 appartenant au premier réseau 12, c'est-à-dire ayant une adresse IP dans ce premier réseau, souhaite s'enregistrer via un second réseau 13 auprès du service MIP, le second réseau 13 étant relié au premier réseau 12. L'enregistrement au service MIP est précédé d'un contrôle d'accès au second réseau 13 pour le terminal 10.
Un tel service MIP permet au terminal 10 ayant une première adresse dans le premier réseau 12, ou réseau nominal, de conserver cette même première adresse vis-à-vis d'autres équipements avec lesquels il communique lorsqu'il est connecté via un autre réseau dans lequel il dispose d'une seconde adresse. Ainsi, lorsque le terminal 10 est enregistré auprès du serveur HA 17 pour le service de mobilité, un message émis à destination de la première adresse du terminal 10, est acheminé jusqu'à la seconde adresse du terminal dans le second réseau 13.
Le second réseau 13, ou réseau visité, comprend une passerelle 14 et un serveur 16 apte à dialoguer avec un serveur 15 du réseau nominal 12. Il comprend également un contrôleur d'accès 11 apte à réaliser le contrôle d'accès au second réseau 13 du terminal 10. Le contrôleur d'accès 11 , pour réaliser le contrôle d'accès, dialogue avec le serveur 16. Les serveurs 16 et 15 sont des serveurs de type AAA (pour 'Authentication, Authorization and Accounting'), de sorte que les premier et second réseaux peuvent coopérer entre eux. Les serveurs 15 et 16, respectivement référencés AAAH (pour 'AAA Home') et AAAF (pour 'AAA Foreign') peuvent communiquer entre eux sur la base d'un protocole de type AAA permettant de transporter entre plusieurs réseaux des fonctions d'authentification. Diameter, tel que défini dans la RFC 3588, est un exemple de protocole assurant cette fonction.
La figure 2 représente un échange de messages correspondant à l'architecture illustrée à la figure 1.
Cet échange de messages peut être décrit en deux phases successives, une première phase correspondant à un contrôle d'accès réseau du terminal et une seconde phase correspondant à l'enregistrement du terminal au service MIP. Du point de vue du terminal, la première phase est réalisée au sein d'une session selon le protocole EAP qui est ouverte avec un message 201 'Request identity' puis fermée avec un message 213 'Success'. La seconde phase est effectuée selon le protocole MIP. L'échange de messages à l'intérieur des premier et second réseaux, et entre les premier et second réseaux, est basé sur des applications du protocole Diameter appelées Diameter-EAP et Diameter-MIP.
L'échange de messages pendant la première phase de contrôle d'accès utilise une méthode d'authentification particulière : EAP-AKA. Une autre méthode d'authentification EAP pourrait être utilisée.
Suivant un échange de message 200, le terminal s'associe au réseau 13 via le contrôleur d'accès 11. A la suite de cette association, le contrôleur d'accès 11 émet à destination du terminal le message 201 selon le protocole EAP par lequel elle requiert un identifiant du terminal 10.
Ce dernier répond à cette requête en émettant un message 202 selon le protocole EAP 'Response Identity' dans lequel il transmet un identifiant.
Le contrôleur d'accès 11 relaie ce message au serveur AAAF 16 par un message 203. Le serveur 16 relaie ce message 203 au serveur AAAH 15 par un message 204. Les messages 203 et 204 permettent de transmettre jusqu'au serveur AAAH 15 l'échange de messages 201 et 202 relatif à l'identité du terminal 10. Ces messages 203 et 204 sont émis selon une application Diameter-EAP par encapsulation de messages de la session EAP.
En fonction de l'identifiant du terminal 10 reçu dans ce message 204, le serveur 15 initie une phase d'authentification du terminal dans laquelle il requiert certaines informations via un message 205 émis à destination du terminal 10 et transitant selon le protocole Diameter-EAP selon un message du type 'Diameter-EAP-Answer/AKA Challenge' par le serveur AAAF 16, puis par le contrôleur d'accès 11 , sous la forme des messages 205 et 206. Ensuite, le contrôleur d'accès 11 relaie le message 206 à destination du terminal 10 selon le protocole EAP sous la forme d'un message 207 de type ΕAP-Request/AKA Challenge'.
Sur réception de ce message 207, le terminal 10 émet un message 208 ΕAP-Response/AKA Challenge' selon le protocole EAP, transmettant ainsi au serveur AAAH 15 des informations relatives à son authentification préalable à son accès au réseau.
Ce message est relayé vers le serveur AAAF 15 successivement par le contrôleur d'accès 11 puis par le serveur 16, selon le protocole Diameter-EAP sous la forme des messages 209 et 210 de type 'Diameter- EAP-Request'.
Sur réception de ce message 210, le serveur AAAH 15 authentifie le terminal 10, puis décide d'autoriser le terminal 10 à accéder au réseau 13. Il répond donc en émettant un message 211 à destination du terminal 10, qui est relayé par le serveur AAAF 16 vers le contrôleur d'accès 11 par un message 212, les messages 211 et 212 étant de type 'Diameter-EAP- Answer/DIAMETER_SUCCESS' selon l'application Diameter-EAP.
Ensuite, le contrôleur d'accès 11 relaie le message 212 vers le terminal 10 sous la forme d'un message 213 selon le protocole EAP de type 'EAP- Success'. Ce message termine la session EAP, ouverte avec le message 201.
Un échange optionnel de messages référencé 214 correspond à un échange d'informations destinées à permettre au terminal de chiffrer les informations émises sur le réseau.
A ce stade, la première phase correspondant au contrôle d'accès au réseau est complète. Par conséquent, le terminal 10 a accès au réseau 13. Il est donc en mesure de s'enregistrer auprès du service MIP qui est géré au niveau du serveur HA 17 dans son réseau nominal. La seconde phase correspondant à l'enregistrement du terminal auprès du service de mobilité MIP peut alors commencer.
Cette seconde partie est basée sur le protocole Diameter-MIP, tel que défini par exemple dans la RFC 4004 'Diameter Mobile IPv4 application', qui correspond à une application du protocole Diameter au transport de données relatives au service MIP. Un tel protocole repose sur le protocole Diameter ainsi que sur la RFC 3957 'AAA Registration Keys for Mobile IPv4'.
A ce stade, en premier lieu, la passerelle 14 affecte une seconde adresse au terminal dans le second réseau qu'il visite et en informe le terminal. A cet effet, la passerelle 14 émet à destination du terminal 10 un message 215 selon le protocole MIP de type 'MIP RA' (pour 'MIP Router Advertisement'), contenant la seconde adresse, ou encore adresse CoA (pour 'Care of Adress').
Sur réception de ce message 215, le terminal émet à destination du réseau nominal un message 216 de requête d'enregistrement au service MIP selon le protocole MIPv4 de type 'RRQ' (pour 'Registration ReQuest'). Ce dernier message est relayé par la passerelle 14 vers le serveur AAAF 16 par un message 217 selon le protocole Diameter-MIP de type 'AMR' (pour 'AA Mobile Node Request'). Le serveur 16 relaie ce message vers le serveur AAAH 15 par un message 218 selon le protocole Diameter-MIP 'AMR'.
Puis, sur la base des informations reçues dans ce message 218, le serveur AAAH 15 authentifie le terminal 10.
Ensuite, il envoie au serveur HA 17 un message 219 selon le protocole Diameter-MIP ΗAR' (pour 'Home Agent MIP Request'). Le serveur HA 17 est alors en mesure d'associer l'adresse IP, CoA, du terminal 10 dans le réseau visité 13 et l'adresse IP du terminal 10 dans le réseau nominal 12 (le terme couramment utilisé pour cette association d'adresses est le terme anglais 'binding'). Une telle étape correspond à l'enregistrement du terminal 10 au service MIP.
Puis, cet enregistrement est acquitté par le serveur HA 17 sous la forme d'un message 220 selon le protocole Diameter-MIP 'HAA' (pour 'Home Agent MIP Answer') qui est relayé par le serveur AAAH 15 puis par le serveur AAAF sous la forme du message 221 puis du message 222, jusqu'à la passerelle 14. La passerelle 14 transforme le message 222 vers le terminal 10 sous la forme d'un message 223 selon le protocole MIP de type 'RRP' (pour 'Registration RePIy').
Ce dernier message 223 met fin à la seconde phase correspondant à l'enregistrement du terminal auprès du service MIP géré par le serveur HA 17.
On note qu'un tel mécanisme met en œuvre deux phases successives, une première phase relative à l'accès au réseau du terminal, et une seconde phase relative à l'enregistrement du terminal à un service, chacune de ces phases étant réalisée sur la base d'une authentification du terminal gérée par le serveur AAAH 15 dans le réseau nominal 12.
La présente invention vise à simplifier le mécanisme d'accès au réseau et d'enregistrement à un service d'un terminal.
Un premier aspect de la présente invention propose un procédé de gestion d'accès à un réseau et d'enregistrement à un service de télécommunication pour un terminal appartenant à un premier réseau de télécommunication. Le premier réseau comprend une fonction d'authentification du terminal et offre le service de télécommunication. Le procédé est caractérisé en ce que l'accès au réseau et l'enregistrement au service sont gérés en une phase commune pour le terminal ; la phase comprenant les étapes suivantes :
/a/ émettre depuis le terminal à destination du premier réseau, via un second réseau relié audit premier réseau, un premier message comprenant des informations indiquant d'une part une requête d'accès réseau et d'autre part une requête d'enregistrement audit service ;
Ib/ sur réception dudit premier message dans le premier réseau, décider, sur la base de ladite fonction d'authentification et des informations comprises dans ledit premier message, d'autoriser le terminal à accéder au second réseau et d'enregistrer le terminal audit service ;
Id recevoir sur le terminal depuis le premier réseau via ledit second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service.
Dans un mode de réalisation de la présente invention, avant l'étape /a/ et après une phase d'identification du terminal par le second réseau, le second réseau envoie un message d'initiation au terminal de façon à détecter si le terminal est adapté pour gérer les étapes /a/ à Ici et de façon à envoyer au terminal des informations pour générer le premier message.
Le service de télécommunication offert dans le premier réseau peut permettre au terminal de recevoir des messages, initialement adressés à une première adresse du terminal dans le premier réseau, sur une seconde adresse dans le second réseau. L'enregistrement au service comprend alors une association des première et seconde adresses (en anglais 'binding').
La seconde adresse peut alors être allouée et envoyée au terminal dans un message d'initiation par le second réseau, et la seconde adresse est récupérée, puis incluse dans le premier message.
Le terminal et le second réseau peuvent communiquer selon un protocole de type EAP, le premier message étant un message de type 'Response'. Le message d'initiation peut être un message de type 'Request' selon un protocole de type EAP
Un deuxième aspect de la présente invention propose un terminal dans un premier réseau de télécommunication comprenant une fonction d'authentification de terminal et offrant un service de télécommunication. Le terminal comprend : une unité d'émission adaptée pour émettre à destination du premier réseau, via un second réseau relié audit premier réseau, un premier message comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement audit service ; une unité de réception adaptée pour recevoir depuis le premier réseau via ledit second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service.
Le terminal peut en outre comprendre une unité de génération de message adaptée pour récupérer des informations à partir d'un message d'initiation émis à partir du second réseau et reçu par l'unité de réception, et pour générer le premier message sur la base desdites informations récupérées. Dans un mode de réalisation de la présente invention, lorsque le service de télécommunication offert dans le premier réseau permet au terminal de recevoir des messages, initialement adressés à une première adresse du terminal dans le premier réseau, sur une seconde adresse dans le second réseau, et lorsque l'enregistrement au service comprend une association des première et seconde adresses, les informations récupérées à partir du message d'initiation comprennent la seconde adresse du terminal dans le second réseau et le premier message comprend la seconde adresse.
Un troisième aspect de la présente invention propose une passerelle de télécommunication adaptée pour coopérer avec un terminal appartenant à un premier réseau comprenant une fonction d'authentification du terminal et offrant un service de télécommunication. La passerelle appartient à un second réseau et comprend : une unité de réception adaptée pour recevoir, d'une part depuis ledit terminal un premier message, destiné au premier réseau, comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement à un service de télécommunication, et d'autre part, depuis le second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; et une unité de transmission adaptée pour transmettre au premier réseau ledit premier message et pour transmettre au terminal ledit second message émis par le premier réseau.
La passerelle peut comprendre, lorsque le service de télécommunication permet au terminal de recevoir des messages initialement adressés à une première adresse du terminal dans le premier réseau sur une seconde adresse dans le second réseau, d'une part, une unité d'affectation d'adresse adaptée pour affecter la seconde adresse du second réseau au terminal, l'unité de transmission étant adaptée pour transmettre au terminal la seconde adresse affectée par l'unité d'affectation dans un message d'initiation, et, d'autre part, une unité de conversion adaptée pour convertir le premier message reçu par l'unité de réception et transmis par le terminal, en un message converti à destination du premier réseau, et adaptée pour convertir le second message reçu par l'unité de réception et transmis par le premier réseau via le second réseau en un message converti à destination du terminal.
Un quatrième aspect de la présente invention propose un système de gestion d'accès à un réseau et d'enregistrement à un service de télécommunication pour un terminal, selon le second aspect, appartenant à un premier réseau de télécommunication. Le premier réseau comprend une fonction d'authentification du terminal et offre le service de télécommunication. Le système est caractérisé en ce qu'il fournit au terminal, en une phase commune, d'une part un accès au second réseau et d'autre part un enregistrement au service. Dans un tel système, le second réseau peut comprendre une passerelle de télécommunication ayant : une unité de réception adaptée pour recevoir, d'une part depuis ledit terminal un premier message, destiné au premier réseau, comprenant des informations indiquant d'une part une requête d'accès réseau et d'autre part une requête d'enregistrement à un service de télécommunication, et d'autre part, depuis le second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; et une unité de transmission adaptée pour transmettre au premier réseau ledit premier message et pour transmettre au terminal ledit second message émis par le premier réseau.
Dans ce système, la passerelle peut comprendre, lorsque le service de télécommunication permet au terminal de recevoir des messages initialement adressés à une première adresse du terminal dans le premier réseau sur une seconde adresse dans le second réseau, d'une part une unité d'affectation d'adresse adaptée pour affecter la seconde adresse du second réseau au terminal, l'unité de transmission étant adaptée pour transmettre au terminal ladite seconde adresse affectée par l'unité d'affectation dans un message d'initiation, et d'autre part, une unité de conversion adaptée pour convertir le premier message, reçu par l'unité de réception et transmis par le terminal, en un message converti à destination du premier réseau, et pour convertir le second message, reçu par l'unité de réception et transmis par le premier réseau via le second réseau en un message converti à destination du terminal. Un cinquième aspect de la présente invention propose un produit programme d'ordinateur destiné à être installé dans un terminal, comprenant des instructions aptes à mettre en œuvre le procédé selon le premier aspect, lors d'une exécution du programme par des moyens de traitement du terminal.
Un sixième aspect de la présente invention propose un produit programme d'ordinateur destiné à être installé dans une passerelle, comprenant des instructions aptes à mettre en œuvre le procédé selon le premier aspect, lors d'une exécution du programme par des moyens de traitement de la passerelle.
D'autres aspects, buts et avantages de l'invention apparaîtront à la lecture de la description d'un de ses modes de réalisation.
L'invention sera également mieux comprise à l'aide des dessins, sur lesquels : la figure 1 , précédemment décrite, illustre une architecture selon un art antérieur ; la figure 2, précédemment décrite, illustre un échange de messages selon un art antérieur ; la figure 3 illustre les principales étapes d'un procédé selon un mode de réalisation de la présente invention ; la figure 4 illustre une architecture d'un système selon un mode de réalisation de la présente invention ; la figure 5 illustre un échange de message suivant un procédé selon un mode de réalisation de la présente invention ; la figure 6 illustre une passerelle de télécommunication selon un mode de réalisation de la présente invention ; la figure 7 illustre un terminal selon un mode de réalisation de la présente invention.
L'invention est décrite ci-après dans son application aux réseaux de télécommunication proposant un service de mobilité sur le protocole IP (pour 'Internet Protocol'), tel qu'un service de type MIP comme décrit dans des sections précédentes.
Cette description n'est pas limitative et il convient de noter que la présente invention peut trouver une application simple et efficace pour tout autre type de service dans une telle architecture de réseaux de télécommunication.
Un objet de la présente invention est de proposer un mécanisme permettant d'accroître l'efficacité d'une gestion d'accès au réseau et d'une gestion des services de télécommunication pour les terminaux, tout en conservant un niveau de sécurité dans les réseaux. Un tel mécanisme repose, du point de vue d'un terminal, sur la gestion à la fois d'une requête d'accès réseau et d'une requête d'enregistrement à un service, en une seule phase, par la mise en œuvre d'une procédure d'authentification unique, relative à la fois au contrôle d'accès réseau et à l'enregistrement au service.
Grâce à ces dispositions, on peut réduire les échanges entre le réseau et le terminal par rapport aux mécanismes du type de celui de l'art antérieur précédemment décrit qui met en œuvre une telle gestion en deux phases successives. On peut alors avantageusement simplifier la configuration du terminal en permettant des procédures d'accès au réseau et aux services plus rapides. Il résulte également de ces dispositions un gain en temps pour que l'utilisateur accède à un service, ce qui améliore la qualité de service perçue par l'utilisateur.
La figure 3 illustre les principales étapes d'un procédé selon un mode de réalisation de la présente invention.
Un terminal 30 (ou MN pour 'Mobile Node') selon un mode de réalisation de la présente invention émet à destination d'un premier réseau 12 un premier message 31 via un second réseau 43. Le réseau 12 comprend une fonction d'authentification 33 d'un terminal et offre un service de télécommunication 34. Sur la base des informations reçues dans le premier message 31 et de la fonction d'authentification 33, le second réseau décide d'enregistrer le terminal auprès du service 34. Et enfin, le premier réseau 12 émet un second message 32 à destination du terminal 30, ce second message autorisant l'accès au réseau au terminal et indiquant l'enregistrement du terminal auprès du service 34.
En effet, dans un mode de réalisation de la présente invention, en une seule phase commencée avec le premier message 31 puis terminée avec le second message 32, le terminal 30 obtient un accès réseau et un enregistrement auprès du service 34.
La figure 4 illustre une architecture d'un système selon un mode de réalisation de la présente invention dans son application au service de mobilité MIP, la présente invention n'étant pas limitée à ce type de service.
Le premier réseau 12 ou réseau nominal du terminal 30 est similaire à celui décrit ci-avant en référence à la figure 1. Ce réseau nominal est relié à un second réseau 43, correspondant au réseau visité par le terminal. Ce dernier comprend le serveur AAAF 16 communiquant avec le serveur AAAH 15, permettant ainsi la liaison des deux réseaux 43 et 12. Le second réseau 43 comprend une passerelle 44 destinée à gérer une interface entre le terminal 30 et le second réseau 43.
Dans une telle architecture, un terminal 30 souhaite accéder au réseau 43 et bénéficier d'un service de gestion de mobilité sur le protocole IP offert par le réseau 12. Grâce à ce service, le terminal ayant une première adresse dans son réseau nominal 12, peut conserver cette adresse vis-à-vis d'autres équipements du réseau avec lesquels il échange des données même lorsqu'il se déplace dans un autre réseau, comme décrit dans des sections précédentes. Un tel service peut être mis en place sur la base d'un protocole de type MIPv4 (pour 'Mobile IP version 4'), tel que celui défini dans la RFC 3344.
Selon le principe du protocole MIP, le terminal s'attache au réseau visité, correspondant au second réseau 43, et récupère une seconde adresse IP (CoA) dans ce réseau 43. Puis, il s'enregistre auprès du serveur HA 17 qui lui est associée en lui indiquant l'adresse CoA qu'il a obtenue dans le réseau visité. Lorsqu'un autre terminal envoie des paquets au terminal 30 sur sa première adresse, les paquets sont tout de même acheminés jusqu'au terminal 30 sur sa seconde adresse de visiteur CoA. Le serveur HA 17 gère une association de la première adresse et de la seconde adresse (ou 'binding').
Dans un mode de réalisation de la présente invention, les deux réseaux coopèrent entre eux sur la base d'un protocole de type AAA (pour 'Authentication, Authorization and Accounting1), par exemple Diameter, pour offrir des fonctionnalités AAA permettant d'authentifier des utilisateurs et de leur autoriser l'accès à certains services. La présente invention couvre tout type de protocole permettant de mettre en œuvre une coopération de réseaux de ce type.
Plus précisément, la présente invention est décrite dans son application au protocole Diameter et l'application Diameter-MIP qui est adaptée pour véhiculer des données de Mobile IP de manière sécurisée indépendamment des réseaux visités, mais cette invention n'est pas limitée à une telle application.
La passerelle 44 comprend de préférence une entité 44a adaptée pour mettre en œuvre à la fois des fonctions de contrôle d'accès conformément au contrôleur d'accès 11 selon la figure 1 , une entité 44b adaptée pour mettre en œuvre des fonctions d'authentification et une entité 44c adaptée pour mettre en œuvre des fonctions de serveur de type Foreign Agent (FA) pour gérer le terminal 30 et des fonctions de Client suivant un protocole de type Diameter- MIP pour communiquer avec le serveur AAAp 16. On note que les entités 44a, 44b et 44c peuvent être co-localisées comme cela est le cas dans l'architecture illustrée. Elles peuvent également être localisées à différents emplacements dans le réseau visité. Le serveur HA 17 est par ailleurs adapté pour mettre en œuvre une fonction de type Agent Diameter-MIP avec le serveur AAAH 15.
La figure 5 illustre les échanges de messages entre ces différentes entités de réseau pour la mise en œuvre d'un procédé selon un mode de réalisation de la présente invention.
Au cours d'un échange de messages 501 entre le terminal 30 et la passerelle 44, le terminal 30 s'associe au réseau. Une telle étape peut être réalisée selon une procédure d'association suivant un protocole de type 802.11 défini par I1IEEE.
Le réseau 43 demande au terminal 30 un identifiant. A cet effet, la passerelle 44 émet à destination du terminal un message 502 'Request Identity' suivant un protocole de type EAP tel que celui défini dans une section précédente. Une session EAP est ainsi ouverte. Le terminal 30 répond à ce message en transmettant à la passerelle des informations relatives à son identité par l'envoi d'un message 503. Ce message peut être émis selon le protocole EAP sous la forme d'un message 'Response Identity'.
Ces informations relatives à l'identité du terminal peuvent notamment comprendre un identificateur d'accès réseau ou NAI pour 'Network Accès Identifier', qui identifie, entre autres, le réseau nominal 12 du terminal 30. Plus, généralement, de telles informations permettent d'identifier le réseau dans lequel une procédure d'authentification du terminal peut être mise en œuvre pour un accès au réseau ainsi que pour un enregistrement au service requis.
Ce message 503 est reçu par l'entité 44a avant d'être relayé à l'entité 44b. Ensuite, la passerelle 44 initie un mécanisme d'accès au réseau et d'enregistrement au service de mobilité selon un mode de réalisation de la présente invention, c'est-à-dire en une seule phase du point de vue du terminal. Ce mécanisme peut être initié en émettant à destination du terminal 30 un message 504. Dans un mode de réalisation de la présente invention, ce message est un message de type 'Request' selon le protocole EAP, qui propose au terminal 30 un accès réseau et un enregistrement au service en une seule phase selon un mode de réalisation de la présente invention. Il indique de préférence un identifiant du mécanisme selon l'invention qui permet au terminal 30 d'indiquer à la passerelle s'il est en mesure de gérer un tel mécanisme. Dans un mode de réalisation de l'invention, l'identifiant du mécanisme selon l'invention contenu dans le message d'initiation 504 indique l'utilisation d'une méthode EAP particulière, notée EAP-MIP dans la figure 5, pour l'échange d'informations entre le terminal 30 et la passerelle 44. Dans un mode de réalisation de l'invention, le message d'initiation 504 contient des informations sur le second réseau 43 permettant au terminal 30 de mettre en oeuvre ledit mécanisme. Dans un tel mode de réalisation, le message d'initiation 504 contient la seconde adresse, ou CoA, allouée au terminal par le second réseau 43.
Préférablement, dans le cas où le terminal ne supporte pas un tel mécanisme d'accès et d'enregistrement en une seule phase, le réseau 43 en est informé et peut alors proposer un mécanisme d'accès au réseau et un enregistrement au service en deux phases tel que celui décrit ci-avant en référence aux figures 1 et 2.
Dans le cas contraire, le terminal 30 est adapté pour gérer un mécanisme d'accès au réseau et d'enregistrement au service en une phase selon un mode de réalisation de l'invention. Il répond alors à ce message par un message 505 qui est un message de type 'Response' selon le protocole EAP. Dans un mode de réalisation de l'invention, ce message contient des informations similaires à celles contenues dans le message 216 tel que décrit en référence à la figure 2. Ce message peut correspondre à un message d'enregistrement MIP 'MIP Registration Request' encapsulé dans un message ΕAP-Response/EAP-MIP'. Il peut indiquer l'adresse du serveur HA 17 correspondant au terminal 30, des informations relatives à l'authentification du terminal dans le réseau 12, des demandes de 'MSAs' (pour 'Mobility Security Association') ainsi que, éventuellement, un identifiant du type 'NAI'.
Dans un mode de réalisation de l'invention, le terminal 30 récupère l'adresse CoA qui lui a été affectée par le second réseau 43 et qui lui a été envoyée dans le message 504. Par conséquent, dans un tel mode de réalisation, le message 505 comprend un champ correspondant à l'adresse CoA du terminal 30 dans le réseau 43 qui est renseigné par le terminal à partir des informations envoyées par la passerelle 44 dans le message 504.
Sur réception de ce message 505, l'entité 44a extrait les informations relatives à la requête d'enregistrement MIP (1EAP-M I P/RRQ') et les relaie vers l'entité 44b qui traite le message et le transmet à l'entité 44c.
L'entité 44c est adaptée pour agir en tant que client Diameter-MIP. Elle est donc en mesure de générer un message 506 correspondant à une requête d'enregistrement au service MIP pour le terminal 30. Le message 506 indique la seconde adresse, ou CoA. Ce message peut être émis sous la forme d'un message 507 'AA-Mobile-Node-Request - AMR' selon le protocole Diameter- MIP vers le serveur du réseau visité AAAF 16.
Le serveur AAAF 16 analyse le contenu du message 506 reçu et en extrait les informations relatives à l'enregistrement MIP à partir desquelles il en déduit le réseau nominal correspondant au terminal 30. Le serveur 16 route alors vers le réseau nominal 12 la requête d'enregistrement au service MIP sous la forme d'un message 507 selon le protocole Diameter-MIP/AMR au serveur Diameter 15 du réseau nominal, 'AA-Mobile-Node-Request - AMR'.
Le serveur AAAH 15 analyse le contenu du message 507 de requête d'enregistrement au service MIP. Il récupère alors les informations relatives à l'authentification du terminal 30 et à la requête d'enregistrement MIP. A ce stade, si le serveur AAAH 15 authentifie le terminal 30, il génère alors des informations de chiffrement pour établir des MSAs (pour 'Mobile Security Association') pour le terminal avec l'entité 44c qui agit en tant que serveur 'Foreign Agent' selon le service MIP, et avec le serveur HA 17.
On note que, dans l'exemple décrit, la fonction d'authentification du terminal est localisée au niveau du serveur AAAH 15 dans le premier réseau. Cet exemple n'est pas limitatif. En effet, une telle fonction d'authentification du terminal 30 peut être mise en œuvre au niveau du serveur HA 17. La présente invention couvre toutes les localisations de la fonction d'authentification du terminal 30 au sein du premier réseau 12.
A chaque association sécurisée MSA liée au terminal 30, le serveur 15 peut associer une information de chiffrement à usage unique (le terme couramment utilisé est le terme anglais 'Nonce').
Puis, la demande d'enregistrement du terminal 30 est envoyée au serveur HA 17, dans un message 508 suivant le protocole Diameter-MIP 'HAR Registration Request' (pour 'Home-Agent-MIP-Request Registration Request'). Cette requête d'enregistrement contient les associations sécurisées MSAs et les Nonces précédemment générés et relatives aux relations entre le serveur HA 17 et le terminal 30 ainsi qu'entre le serveur HA 17 et l'entité 44c de la passerelle 44.
Sur réception du message 508, le serveur HA 17 récupère la requête d'enregistrement. Puis, il enregistre le terminal 30 au service MIP en associant l'adresse IP, CoA, du terminal 30 dans le réseau visité 43 et l'adresse IP du terminal 30 dans le réseau nominal 12 (en anglais, 'binding'). Le serveur HA 17 stocke également les associations sécurisées MSAs et les Nonces qui lui ont été associés pour cet enregistrement.
Puis, le serveur HA 17 retourne un message 509 d'acceptation d'enregistrement selon le protocole Diameter-MIP 'HAA Registration Reply'. Ce message peut en outre comprendre la première adresse du terminal 30 dans le réseau nominal 12.
Le serveur 15 AAAH, récupère les informations reçues dans le message 509 'HAA Registration Reply' et les encapsule selon le protocole Diameter-MIP dans un message 510 de type AMA pour 'AA-Mobile-Node- Answer' en y ajoutant de préférence les associations sécurisées MSAs et les informations de chiffrement (Nonces ou clés) issus du processus d'authentification du terminal 30.
Le serveur AAAF 16 relaie ce message 510 vers l'entité 44c sous la forme d'un message 511 selon le protocole Diameter-MIP.
L'entité 44c analyse le contenu du message 511 pour en extraire les informations relatives à l'acceptation de l'enregistrement au service MIP, les associations sécurisées et les informations de chiffrement qui lui permettront une relation sécurisée avec le serveur HA 17 et avec le terminal 30
En outre, l'entité 44c transmet les informations relatives à l'acceptation de l'enregistrement au service MIP, les associations sécurisées et les informations de chiffrement à l'entité 44b. Cette dernière transmet, au terminal via l'entité 44a, ces informations dans un message 512 selon le protocole EAP ΕAP-Request' (EAP-MIP/RRP).
Avec ce message, le terminal récupère les informations relatives à la confirmation d'enregistrement au service de mobilité MIP, avec les informations relatives aux associations sécurisées (MSAs) et les informations de chiffrement, c'est-à-dire des Nonces et/ou des clés de chiffrement, qui lui permettront d'avoir des échanges sécurisés avec le serveur HA 17 ainsi qu'avec l'entité 44c de la passerelle 44 qui agit en tant que serveur 'FA.
Puis, le terminal acquitte la réception de ce message 512 en émettant un message 513 selon le protocole EAP 'EAP-Response' (EAP-MIP/End).
Enfin, la passerelle 44 envoie un message 514 ΕAP-Success' au terminal 30. Sur réception de ce message 514 'EAP-Success', le terminal 30 a accès au réseau 43 et peut utiliser le service de télécommunication auprès duquel il est enregistré..
Ainsi, dans un mode de réalisation de la présente invention, en groupant les fonctions d'authentification associées d'une part à l'étape consistant à autoriser un accès réseau et d'autre part à l'étape consistant à enregistrer, on peut avantageusement réaliser ces deux étapes en une seule phase. On note donc que le résultat obtenu à l'issue des deux phases décrites en référence à la figure 2, est, dans un mode de réalisation de la présente invention, obtenu en une seule phase du point de vue du terminal.
Un mode de réalisation de la présente invention est aisé à mettre en œuvre dans un réseau existant. En effet, la mise en place d'un tel mécanisme requiert uniquement de simples modifications au niveau d'une part de la passerelle et d'autre part du terminal.
La figure 6 représente une passerelle selon un mode de réalisation de la présente invention. La passerelle comprend une unité de réception 61 adaptée pour recevoir, depuis le terminal, un message 505, destiné au premier réseau 12, comprenant des informations indiquant d'une part une requête d'accès réseau et d'autre part une requête d'enregistrement à un service de télécommunication. Les informations correspondant à la requête d'accès au réseau comprennent la seconde adresse, ou CoA, qui a préalablement été allouée par le second réseau. Cette seconde adresse peut être envoyée au terminal dans un message d'initiation tel que le message 504 décrit en référence à la figure 5.
Cette unité de réception est également adaptée pour recevoir le second message 511 permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal au service. Elle comprend en outre une unité d'affectation d'adresse 62 adaptée pour affecter une adresse du second réseau au terminal. Elle comprend aussi une unité de conversion 60 adaptée pour convertir, ou encore encapsuler, le message 505, reçu par l'unité de réception et émanant du terminal, en un message 506 à destination du premier réseau et le message 511 reçu par l'unité de réception du serveur 16 en un message 512 à destination du terminal 30, et pour convertir le second message 511 , reçu par l'unité de réception et transmis par le premier réseau via le second réseau en un message converti 512 à destination du terminal. Par exemple, le message 506 comprend notamment l'adresse du réseau affectée par l'unité d'affectation. Elle peut aussi comprendre une unité de transmission 63 adaptée pour transmettre au premier réseau le premier message ainsi modifié et pour transmettre au terminal un message d'initiation 504 qui comprend des informations telles que l'adresse CoA du terminal.
La figure 7 représente un terminal selon un mode de réalisation de la présente invention ayant une unité d'émission 70 adaptée pour émettre à destination du premier réseau 12, via le second réseau 43 relié au premier réseau, le premier message 505 comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement audit service. Il comprend également une unité de réception 71 adaptée pour recevoir depuis le second réseau un message d'initiation 504 comprenant l'adresse CoA. Elle est adaptée également pour recevoir, depuis le premier réseau via le second réseau, un second message 512 permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal au service. Il peut en outre comprendre une unité de génération 72 adaptée pour extraire d'un message d'initiation 504 reçu par l'unité de réception 71 , l'adresse CoA et pour affecter ladite adresse dans un champ du premier message 505.
Par ailleurs, il est aisé de faire coopérer des terminaux qui ne sont pas adaptés pour mettre en œuvre un tel mécanisme et une passerelle proposant un tel mécanisme. En effet, pour cela il suffit que la passerelle, sur détection d'un terminal non adapté, propose à ce terminal un mécanisme d'accès au réseau et d'enregistrement au service déjà existant, tel que celui décrit au début de la description en deux phases.

Claims

REVENDICATIONS
1. Procédé de gestion d'accès à un réseau et d'enregistrement à un service de télécommunication (34) pour un terminal (30) appartenant à un premier réseau de télécommunication (12), ledit premier réseau comprenant une fonction d'authentification (33) du terminal et offrant ledit service ; ledit procédé étant caractérisé en ce que l'accès au réseau et l'enregistrement au service sont gérés en une phase commune; ladite phase comprenant les étapes suivantes :
/a/ émettre depuis le terminal à destination du premier réseau, via un second réseau (43) relié audit premier réseau, un premier message (31) comprenant des informations indiquant d'une part une requête d'accès réseau et d'autre part une requête d'enregistrement audit service ;
/b/ sur réception dudit premier message dans le premier réseau, décider, sur la base de ladite fonction d'authentification et des informations comprises dans ledit premier message, d'autoriser le terminal à accéder au second réseau et d'enregistrer le terminal audit service ;
Id recevoir sur le terminal depuis le premier réseau via ledit second réseau un second message (32) permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service.
2. Procédé de gestion selon la revendication 1 suivant lequel, avant l'étape /a/ et après une phase d'identification (503) du terminal par le second réseau, le second réseau envoie un message d'initiation (504) au terminal de façon à détecter si le terminal est adapté pour gérer les étapes /a/ à Ici et de façon à envoyer au terminal des informations pour générer le premier message (31).
3. Procédé de gestion selon la revendication 2, suivant lequel le service de télécommunication offert dans le premier réseau (12) permet au terminal (30) de recevoir des messages, initialement adressés à une première adresse du terminal dans le premier réseau, sur une seconde adresse dans le second réseau (43) ; et suivant lequel l'enregistrement audit service comprend une association desdites première et seconde adresses.
4. Procédé de gestion selon la revendication 3, suivant lequel, la seconde adresse est allouée et envoyée au terminal (30) dans le message d'initiation (504), par le second réseau (43), et ladite seconde adresse est récupérée et incluse dans le premier message (505).
5. Terminal dans un premier réseau de télécommunication (12) comprenant une fonction d'authentification de terminal et offrant un service de télécommunication, ledit terminal comprenant : une unité d'émission (70) adaptée pour émettre à destination du premier réseau (12), via un second réseau (43) relié audit premier réseau, un premier message (505) comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement audit service ; une unité de réception (71) adaptée pour recevoir depuis le premier réseau via ledit second réseau un second message (512) permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service.
6. Terminal selon la revendication 5, comprenant en outre une unité de génération (72) de message adaptée pour récupérer des informations à partir d'un message d'initiation émis à partir du second réseau et reçu par l'unité de réception (71), et pour générer le premier message sur la base desdites informations récupérées.
7. Terminal selon la revendication 6, dans lequel, lorsque le service de télécommunication offert dans le premier réseau (12) permet au terminal (30) de recevoir des messages, initialement adressés à une première adresse du terminal dans le premier réseau, sur une seconde adresse dans le second réseau (43), et lorsque l'enregistrement audit service comprend une association desdites première et seconde adresses, les informations récupérées à partir du message d'initiation comprennent la seconde adresse du terminal dans le second réseau et le premier message (505) émis indique la seconde adresse.
8. Passerelle de télécommunication (44) adaptée pour coopérer avec un terminal (30) appartenant à un premier réseau (12) comprenant une fonction d'authentification (33) du terminal et offrant un service de télécommunication ; ladite passerelle appartenant à un second réseau et comprenant : une unité de réception (61) adaptée pour recevoir, d'une part depuis ledit terminal un premier message (505), destiné au premier réseau, comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement à un service de télécommunication, et d'autre part, depuis le second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; et une unité de transmission (63) adaptée pour transmettre au premier réseau ledit premier message et pour transmettre au terminal ledit second message émis par le premier réseau.
9. Passerelle de télécommunication selon la revendication 8, comprenant, lorsque le service de télécommunication permet au terminal de recevoir des messages initialement adressés à une première adresse du terminal dans le premier réseau, sur une seconde adresse dans le second réseau, d'une part, une unité d'affectation d'adresse (62) adaptée pour affecter la seconde adresse du second réseau au terminal, l'unité de transmission étant adaptée pour transmettre au terminal ladite seconde adresse affectée par l'unité d'affectation dans un message d'initiation (504), et d'autre part une unité de conversion (60) adaptée pour convertir le premier message (505), reçu par l'unité de réception et transmis par le terminal, en un message converti (506) à destination du premier réseau, et pour convertir le second message (511), reçu par l'unité de réception et transmis par le premier réseau via le second réseau en un message converti (512) à destination du terminal.
10. Système de gestion d'accès à un réseau et d'enregistrement à un service de télécommunication (34) pour un terminal (30), ledit système de gestion appartenant à un premier réseau qui comprend une fonction d'authentification (33) de terminal et qui offre ledit service, et un second réseau, ledit terminal appartenant au premier réseau de télécommunication (12) et comprenant : une unité d'émission (70) adaptée pour émettre à destination du premier réseau (12), via un second réseau (43) relié audit premier réseau, un premier message (505) comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement audit service ; une unité de réception (71) adaptée pour recevoir depuis le premier réseau via ledit second réseau un second message (512) permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; ledit système étant caractérisé en ce qu'il fournit au terminal, en une phase commune, d'une part un accès au second réseau et d'autre part un enregistrement au service.
11. Système de gestion selon la revendication 10, dans lequel le second réseau comprend une passerelle de télécommunication comprenant : une unité de réception (61) adaptée pour recevoir, d'une part depuis ledit terminal un premier message (505), destiné au premier réseau, comprenant des informations indiquant d'une part une requête d'accès réseau et d'autre part une requête d'enregistrement à un service de télécommunication, et d'autre part, depuis le second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; et une unité de transmission (63) adaptée pour transmettre au premier réseau ledit premier message et pour transmettre au terminal ledit second message émis par le premier réseau.
12. Système de gestion selon la revendication 11 , comprenant en outre d'une part une unité d'affectation d'adresse (62) adaptée pour affecter une adresse du second réseau au terminal, l'unité de transmission étant adaptée pour transmettre au terminal ladite seconde adresse affectée par l'unité d'affectation dans un message d'initiation (504), et d'autre part une unité de conversion (60) adaptée pour convertir le premier message (505), reçu par l'unité de réception et transmis par le terminal, en un message converti (506) à destination du premier réseau, le premier message et le message converti (506) comprenant la seconde adresse.
13. Programme d'ordinateur destiné à être installé dans un terminal, comprenant des instructions aptes à mettre en œuvre le procédé selon l'une quelconque des revendications 1 à 4, lors d'une exécution du programme par des moyens de traitement du terminal.
14. Programme d'ordinateur destiné à être installé dans une passerelle adaptée pour coopérer avec un terminal (30) appartenant à un premier réseau (12) comprenant une fonction d'authentification (33) du terminal et offrant un service de télécommunication, comprenant des instructions aptes à mettre en œuvre les étapes suivantes :
- recevoir, d'une part depuis ledit terminal un premier message (505), destiné au premier réseau, comprenant des informations indiquant à la fois une requête d'accès réseau et une requête d'enregistrement à un service de télécommunication, et d'autre part, depuis le second réseau un second message permettant au terminal d'accéder au second réseau et indiquant l'enregistrement du terminal audit service ; et
- transmettre au premier réseau ledit premier message et transmettre au terminal ledit second message émis par le premier réseau ; lors d'une exécution du programme par des moyens de traitement de la passerelle.
PCT/FR2006/002123 2005-09-27 2006-09-15 Authentification unique pour acces reseau et enregistrement a un service de telecommunication Ceased WO2007036623A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0509864A FR2891426A1 (fr) 2005-09-27 2005-09-27 Authentification unique pour acces reseau et enregistrement a un service de telecommunication
FR0509864 2005-09-27

Publications (2)

Publication Number Publication Date
WO2007036623A2 true WO2007036623A2 (fr) 2007-04-05
WO2007036623A3 WO2007036623A3 (fr) 2007-06-14

Family

ID=36617391

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/FR2006/002123 Ceased WO2007036623A2 (fr) 2005-09-27 2006-09-15 Authentification unique pour acces reseau et enregistrement a un service de telecommunication

Country Status (2)

Country Link
FR (1) FR2891426A1 (fr)
WO (1) WO2007036623A2 (fr)

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
FORSBERG NOKIA Y OHBA (ED) TOSHIBA B PATIL NOKIA H TSCHOFENIG SIEMENS A YEGIN SAMSUNG D: "Protocol for Carrying Authentication for Network Access (PANA)" IETF STANDARD-WORKING-DRAFT, INTERNET ENGINEERING TASK FORCE, IETF, CH, vol. pana, no. 4, 7 mai 2004 (2004-05-07), XP015024819 ISSN: 0000-0004 *
JAYARAMAN NET COM R LOPEZ UNIV OF MURCIA Y OHBA (ED) TOSHIBA M PARTHASARATHY NOKIA A YEGIN SAMSUNG P: "PANA Framework" IETF STANDARD-WORKING-DRAFT, INTERNET ENGINEERING TASK FORCE, IETF, CH, vol. pana, no. 1, 16 juillet 2004 (2004-07-16), XP015024807 ISSN: 0000-0004 *
MALINEN J T: "NRC/COM SIM Authentication EAP extension over AAAv6 (SIM6) IPSO/Linux Design Document" NOKIA, 29 mai 2001 (2001-05-29), XP002296876 *

Also Published As

Publication number Publication date
FR2891426A1 (fr) 2007-03-30
WO2007036623A3 (fr) 2007-06-14

Similar Documents

Publication Publication Date Title
EP2415294B1 (fr) Procédé et dispositif de gestion d'une authentification d'un utilisateur
EP3332530B1 (fr) Procedes et dispositifs d'identification d'un serveur d'authentification
Mitton et al. Authentication, authorization, and accounting: protocol evaluation
EP3332531B1 (fr) Identification par des serveurs d'authentification visité et de domicile
EP2291980A2 (fr) Acces reseau a distance via un reseau visite
US7228131B2 (en) IPv6/IPv4 tunneling method
US20150327149A9 (en) Secure Hotspot Roaming
EP2355455A1 (fr) Procédé de génération d'une adresse SIP publique permanente associée à une identité privée sur un réseau IMS
Ventura Diameter: Next generations AAA protocol
WO2014006295A1 (fr) Mise en place d'une association de securite lors de l'attachement d'un terminal a un reseau d'acces
WO2007036623A2 (fr) Authentification unique pour acces reseau et enregistrement a un service de telecommunication
WO2024083694A1 (fr) Procédé de traitement d'une requête en résolution d'au moins un identifiant de nommage, dispositif et programme d'ordinateur correspondants
EP4128717B1 (fr) Délégation d'une fonction de résolution d'identifiants de nommage
FR3110802A1 (fr) Procédé de contrôle de l’attribution d’une adresse IP à un équipement client dans un réseau de communication local, procédé de traitement d’une requête d’attribution d’une adresse IP à un équipement client dans un réseau de communication local, dispositifs, équipement d’accès, équipement serveur et programmes d’ordinateur correspondants.
WO2020128238A1 (fr) Procédé d'acquisition d'une chaîne de délégation relative à la résolution d'un identifiant de nom de domaine dans un réseau de communication
FR3136922A1 (fr) Procédé de communication entre un premier équipement et un serveur distant, procédé de gestion des communications, premier équipement, serveur distant et programme d’ordinateur correspondants.
FR3052004B1 (fr) Procede d'echange de donnees entre un objet connecte et un serveur central.
FR3145253A1 (fr) Procédé de révocation d’un jeton de certification permettant d’authentifier l’établissement d’une connexion entre deux équipements de communication, dispositifs et programmes d’ordinateur correspondants
WO2023247459A1 (fr) Procédé de suspension d'un jeton de certification permettant d'authentifier l'établissement d'une connexion entre deux équipements de communication, dispositifs et programmes d'ordinateur correspondants
EP3970336A1 (fr) Procede de gestion d'une information de securite dans un reseau de communication, dispositif, equipement d'acces audit reseau et programmes d'ordinateur correspondants
Barkley et al. Network Working Group D. Mitton Request for Comments: 3127 Nortel Networks Category: Informational M. St. Johns Rainmaker Technologies
FR3093882A1 (fr) Procédé de configuration d’un objet communicant dans un réseau de communication, terminal utilisateur, procédé de connexion d’un objet communicant au réseau, équipement d’accès et programmes d’ordinateur correspondants.
WO2011023881A1 (fr) Technique pour evaluer une collaboration entre des noeuds d'un reseau de communication

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 06808146

Country of ref document: EP

Kind code of ref document: A2

122 Ep: pct application non-entry in european phase

Ref document number: 06808146

Country of ref document: EP

Kind code of ref document: A2