IP Library Granted Patent US 7,458,095
Granted Patent B2
US 7,458,095 · App. 10/714,638 · Granted Nov 25, 2008

Faster authentication with parallel message processing

Assignee: Nokia Siemens Networks Oy
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,458,095
App. No.
10/714,638
Granted
Nov 25, 2008
Kind
B2
Abstract

The invention is a method of connecting user equipment to at least one network, a communication system, and a user equipment. In a communication system comprising at least one network, including network entities which provide connectivity to user equipment, a method of connecting the user equipment to the at least one network in accordance with the invention includes establishing a secure tunnel which provides connection between the user equipment and one of the network entities; and authenticating the user equipment with another of the network entities; and wherein the authenticating of the user equipment with the another of the network entities occurs at least partially simultaneously with the establishing of the secure tunnel.

Claims (45)

1. In a communication system comprising at least one network, including network entities which provide connectivity to user equipment, a method of connecting the user equipment to the at least one network comprising:

establishing a secure tunnel which provides connection between the user equipment and one of the network entities; and

authenticating the user equipment with another of the network entities, wherein

the authenticating of the user equipment with the another of the network entities occurs at least partially simultaneously with a phase of the establishing of the secure tunnel, wherein the phase is determined based on a protocol or authentication method,

wherein establishing the secure tunnel begins before authenticating the user and wherein during a time between a beginning of establishing the secure tunnel with one of the network entities and a beginning of authenticating the user equipment with another of the network entities, the at least one network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack, and wherein

communication during the time includes at least one of a request for an identification of the user equipment and a request for capability of the user equipment to support at least one data protocol.

2. A method in accordance with claim 1 wherein:

the one network entity comprises a server and the another network entity comprises a server.

3. A method in accordance with claim 1 comprising:

an access network which provides connection of the user equipment to the network, the secure tunnel is established between the user equipment and the access network and the one network entity is part of the access network.

4. A method in accordance with claim 1 wherein:

the user equipment is wirelessly connected to the at least one network.

5. A method in accordance with claim 3 wherein:

the access network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack.

6. A method in accordance with claim 5 wherein:

communication during the time includes at least one of a request for an identification of the user equipment and a request for capability of the user equipment to support at least one data protocol.

7. A method in accordance with claim 1 wherein:

the at least one network comprises a home network.

8. A method in accordance with claim 1 wherein:

the at least one network comprises a visited network.

9. A communication system comprising at least one network including network entities which provide connectivity to user equipment and wherein:

a secure tunnel is established which provides connection between the user equipment and one of the network entities, the user equipment is authenticated with another of the network entities, and the authenticating of the user equipment with the another of the network entities occurs at least partially simultaneously with a phase of the establishing of the secure tunnel,

wherein the phase is determined based on protocol or authentication method,

wherein the establishing the secure tunnel begins before authenticating the user equipment with the network and wherein during a time between a beginning of establishing the secure tunnel with one of the network entities and a beginning of authenticating the user equipment with another of the network entities, the at least one network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack, and

wherein communication during the time includes at least one of a request for an identification of the user equipment and a request for capability of the user equipment to support at least one data protocol.

10. A system in accordance with claim 9 wherein:

the one network entity comprises a server and the another network entity comprises a server.

11. A system in accordance with claim 9 comprising:

an access network which provides connection of the user equipment to the network, the secure tunnel is established between the user equipment and the access network and the one network entity is part of the access network.

12. A system in accordance with claim 9 wherein:

the user equipment is wirelessly connected to the at least one network.

13. A system in accordance with claim 9 wherein:

the access network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack.

14. A user equipment in a communication system comprising at least one network, including network entities which provide connectivity to the user equipment and wherein:

a secure tunnel is established which provides connection between the user equipment and one of the network entities, the user equipment is authenticated with another of the network entities, and the authenticating of the user equipment with the another of the network entities occurs at least partially simultaneously with a phase of the establishing of the secure tunnel, wherein the phase is determined based on a protocol or authentication method,

wherein the establishing the secure tunnel begins before the authenticating the user equipment with the network and wherein during a time between a beginning of establishing the secure tunnel with one of the network entities and a beginning of authenticating the user equipment with another of the network entities, the at least one network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack, and

wherein communication during the time includes at least one of a request for an identification of the user equipment and a request for capability of the user equipment to support at least one data protocol.

15. A user equipment in accordance with claim 14 wherein:

the one network entity comprises a server and the another network entity comprises a server.

16. A user equipment in accordance with claim 14 comprising:

an access network which provides connection of the user equipment to the network, the secure tunnel is established between the user equipment and the access network and the one network entity is part of the access network.

17. A user equipment in accordance with claim 14 wherein:

the user equipment is wirelessly connected to the at least one network.

18. A user equipment in accordance with claim 14 wherein:

the access network communicates with the user equipment to confirm that the request from the user equipment to establish a secure tunnel is not part of a denial of service attack.

Assignments (4)
CHANGE OF NAME Recorded Feb 19, 2019
From: NOKIA SOLUTIONS AND NETWORKS OY
To: PIECE FUTURE PTE LTD
Reel/Frame 048376/0521 →
CHANGE OF NAME Recorded Nov 19, 2014
From: NOKIA SIEMENS NETWORKS OY
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 034294/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2008
From: NOKIA CORPORATION
To: NOKIA SIEMENS NETWORKS OY
Reel/Frame 020550/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2004
From: FORSBERG, DAN
To: NOKIA CORPORATION
Reel/Frame 015213/0664 →
Continuity (2)
Provisional Application 6042679400 · Nov 18, 2002
Related Publication 20040148504A1 · Jul 29, 2004