TECHNIQUE FOR PROVIDING SECURED TUNNELS IN A PUBLIC NETWORK FOR TELECOMMUNICATION SUBSCRIBERS
A secured OTT architecture for Triple-Play services as well as for OTT based cellular service. Any access networks to which customers of the OTT based services belong, form a so-called last mile access segment which is less prone to security attacks than a public network such as the Internet. The customers' equipment (broadband CPEs, say in the form of modems or Femtocell CPEs) can be freed from securing traffic within the non-public access network, while an access node being a border node between the two networks aggregates the traffic from the access terminals and generates one or more secured communication tunnels via the public network for transmitting the aggregated traffic.
1 - 20 . (canceled)
21 . A method of providing secured communication tunnels via a public network for access terminals situated in a non-public access network and subscribed to OTT based telecommunication services, wherein said OTT based services are provided by an OTT service operator's network via the public network and via an access node being a border node between the public network and the non-public access network; the method comprises:
establishing communication between said access terminals and the border node, to carry traffic of communication sessions of the access terminals, related to the OTT based telecommunication services;
at the border node, aggregating said traffic from the access terminals,
at the border node, generating one or more secured communication tunnels via the public network between the border node and the OTT service operator's network, wherein each of said secured tunnels is capable of serving communication sessions generated by two or more access terminals, and
transmitting the aggregated traffic via the public network through said one or more secured tunnels.
22 . The method according to claim 21 , wherein the public network is the public Internet.
23 . The method according to claim 21 , wherein the secured communication tunnels via the public network are IPSec tunnels.
24 . The method according to claim 21 , wherein the secured communication tunnels are bidirectional.
25 . The method according to claim 21 , wherein said access terminals form, in the non-public access network, a group of access terminals subscribed to secured OTT-based telecommunication services.
26 . The method according to claim 21 , further comprising:
recognizing traffic arriving to the border node in communication sessions from the public network via any of said one or more secured tunnels as communication sessions related to OTT-based services and intended for said access terminals of the access network;
for each of the communication sessions recognized as intended for said access terminals of the access network, identifying an intended access terminal, and forwarding said recognized communication sessions to respective identified intended access terminals.
27 . The method according to claim 21 , wherein some or all of the access terminals of the non-public access network are Customer Premises Equipment units CPEs, and wherein the OTT service operator's network is a Triple-Play service provider's network.
28 . The method according to claim 21 , wherein some or all of the access terminals of the non-public access network are femtocell access terminals in the form of femtocell Customer Premises Equipment units CPEs, and wherein the OTT service operator's network is a Mobile or Femto operator's network.
29 . An access node for operating as a border node between a non-public access network and a public network conveying OTT-based services to access terminals of the access network from an OTT operator's network, the border node being provided with:
means for aggregating traffic of communication sessions established between the border node and the access terminals of the access network, wherein said communication sessions being related to the OTT-based services,
a hardware and/or software unit for
generating one or more secured communication tunnels via the public network between the border node and the OTT operator's network, wherein each of said secured tunnels is adapted to serve communication sessions of more than one of the access terminals;
transmitting the aggregated traffic via said one or more secured tunnels.
30 . A software product comprising computer implementable instructions and/or data for carrying out the method according to claim 21 , stored on an appropriate computer readable non-transitory storage medium so that the software is capable of enabling operations of said method when used in an access node.
31 . A network system comprising a public network, a non-public broadband access network with a number of OTT service access terminals, one or more OTT service operator's networks and an access node according to claim 29 , the access node ensuring communication between the public network and the non-public broadband access network; the network system being capable of securely providing OTT-based services to said OTT service access terminals through secured tunnels via the public network, so that each secured tunnel is adapted to serve communication sessions established between two or more of said OTT service access terminals and one of the OTT operator's networks.
32 . The network system according to claim 31 , wherein at least some of the OTT service access terminals are Femtocell access terminals in the form of Femtocell Customers Premises Equipment units CPEs, one of said OTT service Operator's networks is a Femto Operator network, and the access node is a Digital Signal Line Access Multiplexer DSLAM or a Multiservice Access Node MSAN enabling communication between the public network being the Internet and the non-public broadband access network.
33 . The network system according tot claim 31 , wherein at least some of the OTT service access terminals are triple-service access terminals implemented as broadband Customers Premises Equipment units CPEs, one of the OTT service Operator's network is a Triple-service provider network, and the access node is a Digital Signal Line Access Multiplexer DSLAM or a Multiservice Access Node MSAN enabling communication between the public network being the Internet and the non-public broadband access network.
34 . The network system according to claim 31 , comprising more than one different OTT service operator's networks, the network system being configured to provide secured transmission of OTT-based services to said OTT service access terminals from said different OTT service operator's networks by respective different sets of the secured tunnels via the public network.