Method and arrangement for authentication procedures in a communication network
First Claim
1. An authentication method in a communication system including a Subscriber with a terminal, an Operator Node and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator and the Service Provider, the method comprising the following steps:
- sending a service request to the Service Provider Node from the terminal, the request includes the Operator Node identity;
checking in the Service Provider Node that the Operator node identity relates to an Operator having an SLA agreement with the Service Provider andif there is an SLA agreement then sending the Service Provider node Identity to the terminal andsending a Request for strong authentication from the terminal to the Operator Node, the request includes the Service Provider Node Identity;
the Subscriber with terminal performing strong authentication with the Operator Node acting as Registration Authority;
generating by the Operator Node a Mobile Strong Authentication Assertion MSAA;
transmitting the generated MSAA to the Service Provider Node; and
validating in the Service Provider node the MSAA.
1 Assignment
0 Petitions
Accused Products
Abstract
The present invention is related to an authentication method and arrangements in a communication system including a Subscriber (50) with a terminal (51), an Operator Node (52) and a Service Provider Node (53), which authentication method is based on an SLA agreement between the Operator (OP) and the Service Provider (SP). The method includes that the Subscriber (50) with terminal (51) performs (5) strong authentication with the Operator Node (52) acting as Registration Authority OP(RA). After the strong authentication is performed by the Operator Node (52) a Mobile Strong Authentication Assertion MSAA is generated (6) and transmitted to the Service Provider Node (53) for validation. By this method the authentication is being delegated from the Service Provider to the Mobile Operator.
6 Citations
10 Claims
-
1. An authentication method in a communication system including a Subscriber with a terminal, an Operator Node and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator and the Service Provider, the method comprising the following steps:
-
sending a service request to the Service Provider Node from the terminal, the request includes the Operator Node identity; checking in the Service Provider Node that the Operator node identity relates to an Operator having an SLA agreement with the Service Provider and if there is an SLA agreement then sending the Service Provider node Identity to the terminal and sending a Request for strong authentication from the terminal to the Operator Node, the request includes the Service Provider Node Identity; the Subscriber with terminal performing strong authentication with the Operator Node acting as Registration Authority; generating by the Operator Node a Mobile Strong Authentication Assertion MSAA; transmitting the generated MSAA to the Service Provider Node; and validating in the Service Provider node the MSAA. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. An authentication method in an Operator Node within a communication system including a subscriber having a trust relation with the operator and a Service Provider Node, which authentication method is based on an SLA agreement between the Operator OP and the Service Provider, the method comprising the following steps:
-
receiving a Request for authentication, the request includes the Service Provider Node Identity; checking what authentication context is used for the received Service Provider Node; performing authentication in accordance with the authentication context for the received Service Provider Node; generating a Mobile Strong Authentication Assertion MSAA and transmitting the generated MSAA to the Service Provider node, whereby the Operator Node is acting as Registration Authority for the Service Provider.
-
-
8. An authentication method in a Service Provider Node within a communication system including also a subscriber with a terminal and an Operator Node, the method is based on an SLA agreement with the Operator comprising the following steps:
-
receiving a service request from the terminal, the request includes the Operator Node identity; checking in the Service Provider node that the Operator node identity relates to an operator having an agreement with the Service Provider; if there is an agreement then; sending information to the terminal about the Service Provider; receiving an MSAA generated by the Operator; validating of the received MSAA; registering the user; and delivering the service to the terminal. - View Dependent Claims (9, 10)
-
Specification