US2015289138A1PendingUtilityA1

Femtocell access control

Assignee: QUALCOMM INCPriority: Jun 8, 2009Filed: Jun 19, 2015Published: Oct 8, 2015
Est. expiryJun 8, 2029(~2.8 yrs left)· nominal 20-yr term from priority
H04L 63/101H04W 84/045H04W 12/08H04L 63/0892H04W 12/06H04W 4/24H04W 48/02
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Access by a mobile station to a femto access point (FAP) of a wireless communication system is controlled by an enforcement point in response to mobile station authorization data provided from a storage point that is remote from the FAP. The authorization data is provided in response to FAP authentication data. The authentication data may include a FAP identifier and a message authenticator that the FAP generates by hashing shared secret information. The storage point may provide the authorization data in response to determining that the message authenticator is a hash of the shared secret information.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method, comprising:
 computing a request authenticator at a femto access point (FAP) in a wireless communication network, using first shared information obtained during a prior authentication session with an entity in the wireless communication network; and   transmitting a request message from the FAP to a remote Authorization, Authentication and Accounting server (AAA), the request message comprising a FAP identifier and the request authenticator, thereby enabling the AAA to determine whether the FAP identifier is valid for the FAP.   
     
     
         3 . The method of  claim 2 , wherein the first shared information comprises first secret information from the entity, and further comprising determining whether the FAP identifier is valid for the FAP, by independently computing a check value for the request authenticator at the AAA using the first secret information. 
     
     
         4 . The method of  claim 2 , wherein the FAP receives a response to the request message generated by the AAA in response to determining that the FAP identifier is valid for the FAP, the response comprising a FAP type identifier and an access control list for the FAP. 
     
     
         5 . The method of  claim 4 , wherein a network entity controls access by mobile stations via the FAP, using the FAP type identifier and the access control list, the network entity selected from the group consisting of the AAA, a femto gateway device (FGW) and a Packet Data Serving Node (PDSN). 
     
     
         6 . The method of  claim 2 , further comprising computing a message authenticator at the FAP using second secret information shared with a security gateway device (SeGW) for the FAP, and including the message authenticator in the request message. 
     
     
         7 . The method of  claim 6 , wherein a femto gateway device (FGW) interposed between the AAA and the SeGW forwards the request message from the FAP to the AAA, in response to determining that the message authenticator is valid. 
     
     
         8 . The method of  claim 7 , wherein the FGW checks validity of the message authenticator by independently computing a comparison value using the second secret information. 
     
     
         9 . The method of  claim 6 , wherein the AAA transmits a response to the request message in response to determining that the FAP identifier is valid for the FAP, the response comprising the message authenticator and an access control list for the FAP. 
     
     
         10 . The method of  claim 9 , wherein the SeGW forwards the response from the AAA to the FAP, in response to determining that the message authenticator is valid. 
     
     
         11 . The method of  claim 9 , wherein the FAP controls access by mobile stations to the FAP, using the access control list from the response. 
     
     
         12 . The method of  claim 2 , wherein the first shared information comprises an IP address assigned by the wireless communication network to the FAP during the prior authentication session, prior to determining the request authenticator. 
     
     
         13 . The method of  claim 12 , further comprising obtaining the first shared information from a security gateway device (SeGW) for the FAP during the prior authentication session. 
     
     
         14 . A communications apparatus, comprising:
 a memory that retains instructions for computing a request authenticator at a femto access point (FAP) in a wireless communication network, using first secret information shared with a remote femto Authorization, Authentication and Accounting server (AAA), and for transmitting a request message from the FAP to the AAA, the request message comprising a FAP identifier and the request authenticator, thereby enabling the AAA to determine whether the FAP identifier is valid for the FAP; and   a processor that executes the instructions.   
     
     
         15 . The communications apparatus of  claim 14 , wherein the memory retains further instructions for receiving a response to the request message generated by the AAA in response to determining that the FAP identifier is valid for the FAP, the response comprising a FAP type identifier and an access control list for the FAP. 
     
     
         16 . The communications apparatus of  claim 15 , wherein the memory retains further instructions for controlling access by mobile stations to the FAP, using the type identifier and the access control list. 
     
     
         17 . The communications apparatus of  claim 15 , wherein the memory retains further instructions for computing a message authenticator at the FAP using second secret information shared with a security gateway device (SeGW) for the FAP, and including the message authenticator in the request message. 
     
     
         18 . A communications apparatus, comprising:
 means for computing a request authenticator at a femto access point (FAP) in a wireless communication network, using first secret information shared with a remote Authorization, Authentication and Accounting server (AAA); and   means for transmitting a request message to the AAA, the request message comprising a FAP identifier and the request authenticator, thereby enabling the AAA to determine whether the FAP identifier is valid for the FAP.   
     
     
         19 . The communications apparatus of  claim 18 , further comprising means for receiving a response to the request message generated by the AAA in response to determining that the FAP identifier is valid for the FAP, the response comprising a FAP type identifier and an access control list for the FAP. 
     
     
         20 . The communications apparatus of  claim 18 , further comprising means for controlling access by mobile stations to the FAP, using the type identifier and the access control list. 
     
     
         21 . The communications apparatus of  claim 18 , further comprising means for computing a message authenticator at the FAP using second secret information shared with a security gateway device (SeGW) for the FAP, and including the message authenticator in the request message.

Join the waitlist — get patent alerts

Track US2015289138A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.