METHOD AND ARRANGEMENT FOR AUTHENTICATION PROCEDURES IN A COMMUNICATION NETWORK
First Claim
1. An authentication method in a communication system including a Subscriber with a terminal, an Operator Node and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator and the Service Provider, the method is characterized by the following steps:
- the Subscriber with terminal performing strong authentication with the Operator Node acting as Registration Authority;
generating by the Operator Node a Mobile Strong Authentication Assertion MSAA;
transmitting the generated MSAA to the Service Provider Node andvalidating in the Service Provider node the MSAA.
1 Assignment
0 Petitions
Accused Products
Abstract
The present invention is related to an authentication method and arrangements in a communication system including a Subscriber (50) with a terminal (51), an Operator Node (52) and a Service Provider Node (53), which authentication method is based on an SLA agreement between the Operator (OP) and the Service Provider (SP). The method includes that the Subscriber (50) with terminal (51) performs (5) strong authentication with the Operator Node (52) acting as Registration Authority OP(RA). After the strong authentication is performed by the Operator Node (52) a Mobile Strong Authentication Assertion MSAA is generated (6) and transmitted to the Service Provider Node (53) for validation. By this method the authentication is being delegated from the Service Provider to the Mobile Operator.
29 Citations
15 Claims
-
1. An authentication method in a communication system including a Subscriber with a terminal, an Operator Node and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator and the Service Provider, the method is characterized by the following steps:
-
the Subscriber with terminal performing strong authentication with the Operator Node acting as Registration Authority; generating by the Operator Node a Mobile Strong Authentication Assertion MSAA; transmitting the generated MSAA to the Service Provider Node and validating in the Service Provider node the MSAA. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An authentication method in an Operator Node within a communication system including a subscriber having a trust relation with the operator and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator OP and the Service Provider the method including the following steps:
-
receiving a Request for authentication, the request includes the Service Provider Node Identity; checking what authentication context is used for the received Service Provider Node; performing authentication in accordance with the authentication context for the received Service Provider Node; generating a Mobile Strong Authentication Assertion MSAA and transmitting the generated MSAA to the Service Provider node, whereby the Operator Node is acting as Registration Authority for the Service Provider.
-
-
9. An arrangement in an Operator Node OP within a communication system including a subscriber having a trust relation with the operator and a Service Provider Node SP (53), the Service Provider having an SLA agreement with the Operator OP the arrangement is characterized in:
-
an SLA database for checking what authentication context to be used for a service request; an Authentication unit for performing of the authentication in accordance with the authentication context and an MSAA generator for generation of the MSAA and sending it to the Service Provider Node, whereby the Operator Node act as Registration Authority for the Service Provider. - View Dependent Claims (10)
-
-
11. An authentication method in a Service Provider Node within a communication system including also a subscriber with a terminal and an Operator Node the method is based on an SLA agreement with the Operator characterized by the following steps:
-
receiving a service request from the terminal, the request includes the Operator Node identity; checking in the Service Provider node that the Operator node identity relates to an operator having an agreement with the Service Provider; if there is an agreement then; sending information to the terminal about the Service Provider receiving an MSAA generated by the Operator; validating of the received MSAA; registering the user and delivering the service to the terminal. - View Dependent Claims (12, 13)
-
-
14. A Service Provider Node within a communication system including a subscriber having a trust relation with an operator, the Service Provider having an SLA agreement with the Operator, the arrangement is characterized in:
-
a validation unit for validation of a received Mobile Strong Authentication Assertion; a registration unit for registering the subscriber upon validation of the MSAA; whereby the Service Provider utilize the Operator for authentication of the subscriber. - View Dependent Claims (15)
-
Specification