Method and system for negotiation based on IKE messages
US-9438566-B2 · Sep 6, 2016 · US
US2016183085A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016183085-A1 |
| Application number | US-201514975535-A |
| Country | US |
| Kind code | A1 |
| Filing date | Dec 18, 2015 |
| Priority date | Dec 19, 2014 |
| Publication date | Jun 23, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Apparatus and methods to support location specific control to allow and/or disallow access to services through untrusted wireless networks by a wireless communication device are disclosed. One or more network elements obtain a location of the wireless communication device and selectively allow and/or disallow access to one or more cellular network services and/or one or more access point names (APNs) based on the location of the wireless communication device when connecting through an untrusted wireless network.
Opening claim text (preview).
What is claimed is: 1 . A method to control service access for a wireless communication device, the method comprising: by the wireless communication device: establishing an encrypted connection with a server through a non-3GPP wireless access network; establishing an authenticated connection with the server through the non-3GPP wireless access network; providing geographic location information for the wireless communication device to the server; requesting access to one or more services provided through one or more access point names (APNs) to the server; and receiving an indication to allow or disallow access to at least one of the one or more services and/or to the one or more APNs based at least in part on the provided geographic location information. 2 . The method as recited in claim 1 , wherein the geographic location information is provided to the server by the wireless communication device as an attribute in an Internet Key Exchange Version 2 (IKEv2) protocol message. 3 . The method as recited in claim 2 , wherein the IKEv2 protocol message comprises a configuration request message sent during an authentication phase before authentication of the server by the wireless communication device is complete. 4 . The method as recited in claim 2 , wherein the IKEv2 protocol message comprises an informational notification message sent after authentication of the server by the wireless communication device is complete. 5 . The method as recited in claim 1 , wherein the server comprises an evolved packet data gateway (ePDG) associated with a wireless service provider. 6 . The method as recited in claim 5 , wherein the indication to allow or disallow access comprises a notification message from the ePDG that disallows establishment of at least one Internet Protocol Security (IPSec) tunnel to at least one of the one or more APNs. 7 . The method as recited in claim 1 , wherein the server comprises an Internet Protocol Multimedia Subsystem (IMS) server associated with a wireless service provider. 8 . The method as recited in claim 7 , wherein the geographic location information is provided to the IMS server by the wireless communication device in a Session Initiation Protocol (SIP) registration message. 9 . The method as recited in claim 7 , wherein the indication to allow or disallow access comprises a SIP message denying registration of the wireless communication device for the at least one of the one or more services. 10 . The method as recited in claim 7 , wherein the indication to allow or disallow access comprises a SIP message to start a network-initiated deregistration procedure for the at least one of the one or more services after successful registration of the wireless communication device. 11 . The method as recited in claim 1 , wherein the indication to allow or disallow access comprises a notification that disallows access to at least one service via the non-3GPP wireless access network based on the geographic location information provided by the wireless communication device. 12 . The method as recited in claim 11 , wherein the indication to allow or disallow access further comprises an indication of an alternative connection through which the wireless communication device can access the at least one service. 13 . The method as recited in claim 12 , wherein the alternative connection comprises a connection via a cellular wireless access network of a wireless service provider. 14 . The method as recited in claim 1 , wherein the geographic location information comprises a mobile country code (MCC) and/or a mobile network code (MNC). 15 . The method as recited in claim 1 , wherein the geographic location information comprises longitude and latitude information derived from a global positioning system (GPS) receiver of the wireless communication device. 16 . The method as recited in claim 1 , wherein the geographic location information comprises wireless local area network (WLAN) access point (AP) location data. 17 . A wireless communication device comprising one or more processors and a storage medium storing instructions that, when executed on the one or more processors, cause the wireless device to establish an encrypted connection with a server through a non-3GPP wireless access network; establish an authenticated connection with the server through the non-3GPP wireless access network; provide geographic location information for the wireless communication device to the server; request access to one or more services provided through one or more access point names (APNs) to the server; and receive an indication to allow or disallow access to at least one of the one or more services and/or to the one or more APNs based at least in part on the provided geographic location information. 18 . The wireless communication device of claim 17 , wherein geographic location information is provided to the server by the wireless communication device as configuration attribute in an Internet Key Exchange Version 2 (IKEv2) protocol informational notification message sent after authentication of the server by the wireless communication device is complete. 19 . The wireless communication device of claim 17 , wherein the indication to allow or disallow access to at least one of the one or more services and/or to the one or more APNs comprises notification to disallow access to a first service and to allow access to a second service. 20 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a wireless communication device, cause the wireless communication device to: establish an encrypted connection with a server through a non-3GPP wireless access network; establish an authenticated connection with the server through the non-3GPP wireless access network; provide geographic location information for the wireless communication device to the server; request access to one or more services provided through one or more access point names (APNs) to the server; and receive an indication to allow or disallow access to at least one of the one or more services and/or to the one or more APNs based at least in part on the provided geographic location information.
by using a location-limited connection, e.g. near-field communication or limited proximity of entities · CPC title
Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title
Electricity · mapped topic
Authentication · CPC title
IP multimedia subsystem [IMS] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.