Authorization and access control system for access rights using relationship graphs
US-2024414161-A1 · Dec 12, 2024 · US
US9392628B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9392628-B2 |
| Application number | US-201113884173-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 7, 2011 |
| Priority date | Nov 8, 2010 |
| Publication date | Jul 12, 2016 |
| Grant date | Jul 12, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and apparatus for providing access of a user equipment to a data network via a wireless communication system is provided. According to an embodiment of the invention, a method of providing access of a user equipment to a data network via a wireless communication system, the user equipment having an associated subscription profile, the wireless communication system utilizing access point identifiers for associating subscribers with specific packet data networks, said subscription profile including at least one access point identifier, the method comprises; setting subscriber profile parameter data in said subscription profile; receiving a first message sent from said user equipment requesting connection using a first access point identifier; determining on the basis of said subscription profile whether or not said user equipment may be connected using the first access point identifier; and dependent on the determination being negative and dependent on the subscriber profile parameter data being set, providing access to a packet data network using a different access point identifier.
Opening claim text (preview).
The invention claimed is: 1. A method of mobility management entity (MME) for providing access of a terminal to a data network via a wireless communication system, the method comprising: setting subscriber profile parameter data in a subscription profile, wherein the subscription profile includes at least one access point identifier; receiving, from the terminal, a first message requesting connection to the data network, the first message including a first access point identifier; determining that the terminal is allowed to be connected to the data network using the first access point identifier, based on the subscription profile; and transmitting a second message requesting a limited connection of the terminal to the data network using a second access point identifier included in the subscriber profile parameter data set in the subscription profile, if the terminal is not allowed to be connected to the data network using the first access point identifier, wherein the terminal is reconfigured to be connected to the data network using the limited connection. 2. The method of claim 1 , further comprising: transmitting, to the terminal, a third message accepting attachment of the terminal to the wireless communication system based on the subscriber profile parameter data set in the subscription profile, if the terminal is not allowed to be connected to the data network using the first access point identifier. 3. The method of claim 1 , further comprising: removing the subscriber profile parameter data in the subscription profile; receiving, from the terminal, a third message requesting connection to the data network, the third message including the first access point identifier; and rejecting access to the data network, if the terminal is not allowed to be connected to the data network using the first access point identifier and the subscriber profile parameter data is removed. 4. The method of claim 1 , wherein the setting of the subscriber profile parameter data comprises setting the subscriber profile parameter data to include the second access point identifier indicating that the terminal is allowed to be connected to the data network using the second access point identifier, if the terminal is not allowed to be connected to the data network using the first access point identifier. 5. The method of claim 1 , wherein the subscriber profile parameter data is held at a server having an association with the wireless communication system. 6. The method of claim 4 , wherein the transmitting of the second message comprises transmitting the second message to a gateway associated with the second access point identifier. 7. The method of claim 6 , further comprising establishing a session including the terminal and the gateway. 8. The method of claim 1 , wherein the first message received from the terminal requesting connection using the first access point identifier specifies an access point name (APN) related to a first gateway. 9. A mobility management entity (MME) arranged to provide access of a terminal to a data network via a wireless communication system, the MME comprising a controller configured to: set a subscriber profile parameter data in a subscription profile, wherein the subscription profile includes at least one access point identifier; receive, from the terminal, a first message requesting connection to the data network, the first message including a first access point identifier; determine that the terminal is allowed to be connected to the data network using the first access point identifier, based on the subscription profile; and transmit a second message requesting a limited connection of the terminal to the data network using a second access point identifier included in the subscriber profile parameter data set in the subscription profile, if the terminal is not allowed to be connected to the data network using the first access point identifier, wherein the terminal is reconfigured to be connected to the data network using the limited connection. 10. A method of a mobility management entity (MME) for providing access of a terminal to a data network via a wireless communication system, the method comprising: setting a subscriber profile parameter data indicating whether a limited connection of the terminal to the data network is allowed in a subscription profile, wherein the subscription profile includes at least one access point identifier; receiving, from the terminal, a first message requesting connection to the data network, the first message including a first access point identifier; transmitting signaling parameter data in association with a session establishment request to the data network including the subscriber profile parameter data, if the terminal is not allowed to be connected to the data network using the first access point identifier and the subscriber profile parameter data indicates that the limited connection of the terminal to the data network is allowed; and establishing a limited connectivity communication session based on the subscriber profile parameter data, wherein the terminal is reconfigured to be connected to the data network using the limited connectivity communication session. 11. The method of claim 10 , further comprising: declining the session establishment request if the subscriber profile parameter data indicates that the limited connection is not allowed. 12. The method of claim 10 , the method comprising: establishing a limited connectivity communication session based on a determination that the terminal is not authorized to be connected to the data network to which connection was requested in the first message. 13. The method of claim 11 , further comprising: declining the session establishment request based on a determination that the terminal is not authorized to be connected to the data network to which connection was requested in the first message. 14. The method of claim 10 , further comprising: setting the subscriber profile parameter data to indicate that access of the terminal to the data network is to be enabled with a limited level of connectivity, if a subscriber is not authorized to connect the terminal to the data network, the limited level of connectivity being restricted relative to a level of connectivity applicable if the subscriber is authorized to connect the terminal to the data network. 15. The method of claim 12 , further comprising determining whether the terminal is authorized to be connected to the data network identified by the access point by means of authentication of a username and password sent from the terminal. 16. The method of claim 10 , wherein each access point identifier has a respective subscriber profile parameter data. 17. The method of claim 14 , wherein the restriction comprises at least one of a restriction to access of the terminal to parts of the data network, a restriction to access of the terminal to services offered by the data network, a restriction to a time that the terminal is permitted to access at least parts of the data network, and a restriction to a time that the terminal is permitted to access at least services offered by the data network. 18. A mobility management entity (MME) arranged to provide access of a terminal to a network via a wireless communication system, the MME comprising: a controller configured to: set a subscriber profile parameter data indicating whether the limited connection is allowed in the subscription profile, wherein the subscription profile includes at least one access point identifier, receive
Entity profiles · CPC title
Profiles · CPC title
Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data · CPC title
Discovering, processing access restriction or access information · CPC title
User profiles · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.