Abstract:
본 발명은 RADIUS 서버를 이용한 인터넷 서비스 프로바이더 가입자의 아이피 주소 관리 시스템 및 그 방법에 관한 것이다. 이를 위하여 본 발명에 따른 시스템 및 그 방법은 홈 ISP 망 내에 인증 및 과금을 관리하는 RADIUS 서버에 IP 주소의 동적 할당을 위한 주소할당 기능을 내장하거나, 또는 주소 관리 전용의 DHCP 서버와 자체 연동이 가능토록 DHCP 클라이언트 기능을 내장함으로써 이동 ISP 가입자가 무선 이동 패킷망을 통한 RADIUS 서버의 접속만으로도 가입자 인증 및 동적 IP 주소의 할당, 사용 갱신, 사용 종료 서비스를 제공받을 수 있다. 따라서, 본 발명은 ISP 가입자가 GPRS 망을 경유하여 홈 ISP 망 접속을 통해 무선 인터넷 및 이동 패킷 데이터 서비스 지원을 제공받을 수 있도록 하고, 또한 ISP 가입자에 대한 홈 ISP 망의 동적 IP 주소 할당과 관리가 용이하고, GPRS 망과 홈 ISP 망과의 연동이 용이하며, GPRS 망 게이트웨이 노드는 홈 ISP 망의 DHCP 릴레이 및 서버에 대한 정보를 파악할 필요가 없으며 홈 ISP 망의 DHCP 서버와의 접속을 필요하지 않는다는 효과를 제공하여 준다.
Abstract:
PURPOSE: An AAA(Authentication, Authorization and Accounting) server system having an integrated information management function in an interworking system between wireless LANs is provided to present and manage information elements required for an interworking system between wireless LANs. CONSTITUTION: An AAA server(200) comprises an MIP(Mobile IP) server control part, an NASREQ(Network Access Server Requirements) server control part(202), an information management part(203), a charging control part(204), an authentication part(205), a key management part(206), an inter-network protocol conversion part(207), a diameter protocol processing part(208), an address management part(209), an operation and management part(210), a UDP(220), an SCTP(230), and an IP(240). The MIP server control part(201) executes an MIP user session management function related to a mobile IP and a handoff processing function. The NASREQ server control part(202) executes a wireless LAN session management function for wireless LAN access users. The information management part(203) executes a user information management function, a system configuration information management function, a user address information management function, and a billing information storage function. The charging control part(204) executes a wireless LAN charging collection function and an MIP charging collection function. The authentication part(205) processes a user authentication function. The key management part(206) creates a session key necessary for authentication, and covers SA(Security Association) management. The inter-network protocol conversion part(207) executes interworking with an existing radius system. The diameter protocol processing part(208) processes a diameter message, and executes routing. The address management part(209) executes a user IP address allocation/release function, an HA(Home Agent) address allocation/release function, etc. The operation and management part(210) covers an SNMP-associated MIB(Management Information Base) contents and message processing function.
Abstract:
PURPOSE: A method for authenticating and managing a subscriber connected to other network within a diameter server is provided to receive a wireless LAN service by using the diameter server to authenticate the subscriber connected to other network. CONSTITUTION: A method for authenticating and managing a subscriber connected to other network within a diameter server include an authentication process, a service process, and a reset process. The authentication process is to generate and manage necessary data corresponding to a subscriber according to the subscriber's request connected to other network(301-306). The service process is to provide a service to the subscriber after the authentication process is performed(307-314). The reset process is to finish each session and perform an initialization process when the subscriber requires a session end(315).
Abstract:
PURPOSE: A method for assigning/canceling a dynamic IP address by a diameter server is provided to enable a diameter server to authenticate a terminal subscriber when a dynamic IP address assign request is received, and to request a dynamic IP address assignment of a DHCP server, thereby preventing the address from being assigned to an unauthorized user. CONSTITUTION: A mobile terminal(114) transmits a DHCP server retrieval message(301). If an address manager(204) transmits the DHCP server retrieval message(302), a DHCP server(112) transmits a DHCP address transmit message(303). The address manager(204) transmits the DHCP address transmit message to the terminal(114)(304). The terminal(114) transmits a DHCP request message(305), and the address manager(204) transmits an address assign authentication request message to a protocol converter(201)(306). The converter(201) transmits an address assign authentication result message(307). If a dynamic IP address right is not included, an address assign failure message is transmitted to the terminal(114)(308). A dynamic IP address assignment is requested(309). The DHCP server(112) transmits a dynamic IP address(310). The address manager(204) transmits an address assign notice message(311,313). If an address assign result message is transmitted(312,314), the address manager(204) transmits an address assign complete message to the terminal(114)(315).
Abstract:
PURPOSE: A routing method for securing QoS(Quality of Service) in a wireless communication network is provided to perform routing through an interface securing QoS, when a GPRS(General Packet Radio System) performs packet communication between mobile stations in the wireless communication network. CONSTITUTION: If a T-PDU(Transport-Packet Data Unit) is received(901), a GGSN(Gateway GPRS Support Node) checks whether an incoming address of a packet in the T-PDU is included in a subnet address on a GGSN address table(902). If not, the T-PDU packet is routed through a conventional Gi interface to a wired host(906). And if included, the T-PDU checks a Gii session table to decide whether a preset pre-session exists between preset GGSNs(903). If so, the T-PDU packet is routed and transmitted to the other GGSN through a Gii interface(907). If a preset pre-session does not exist, a session setup procedure between GGSNs is attempted(904). Whether session setup is successful is decided(906). If successful, the T-PDU packet is routed to the other GGSN through the Gii interface(907). And if not successful, the T-PDU packet is routed through the conventional Gi interface(906).
Abstract:
PURPOSE: A device and method for controlling a power source of a computer system using a living body recognition is provided to reinforce authentication with respect to a user and enhance a security level of a computer system by supplying a system power source after authenticating a user using a fingerprint recognition. CONSTITUTION: A fingerprint recognition sensor(21) recognizes a fingerprint when a user touches one's finger thereon. A central processing unit(25) performs a fingerprint registration, a fingerprint edition, and a fingerprint deletion in accordance with a user's request on condition that a computer system is turned-on. The central processing unit(25) compares fingerprint information being inputted through the fingerprint recognition sensor(21) with a pre-registered fingerprint and performs a user authenticating process on condition that the computer system is turned-off. A ROM(24) includes the program performed by the central processing unit(25). A RAM(22) is controlled by the central processing unit(25) and stores data for performing the program. An EEPROM(23) stores the registered user fingerprint information. An input/output element(26) performs data input/output to the computer system.
Abstract:
PURPOSE: A method for authenticating CHAP(Challenge Handshake authentification Protocol) in connection of ISP(Internet Service Provider) mobile member with third generation GPRS(General Packet Radio Service) network is provided to offer an internet service through an authentification by presenting a relation between PPP(Point To Point) CHAP authentification information and RADIUS(Remote Access Dial In User Service) client information in a transport packet structure. CONSTITUTION: An authentification message structure performs an authentification between a packet mobile communication network and an ISP about an ISP mobile member who accesses the packet mobile communication network. A third generation GPRS network offers an internet service and a packet data service to the mobile member who uses a terminal element(TE) and a mobile terminal(MT). A CHAP message(410) which is transported from the terminal element(TE) to the mobile terminal(MT) includes a CHAP challenge size(411) and a CHAP challenge value(412).
Abstract:
본 발명은 3세대 이동통신 시스템인 IMT-2000시스템의 비동기 전송 모드(ATM) 기반 홈 위치등록기의 하부 물리계층을 이중화하는 방법에 관한 것으로 특히, 장애 감지를 위해 디바이스 드라이버가 수신한 하드웨어로부터 장애 메시지, 서비스 관련 연결형 프로토콜(SSCOP) 관리계층의 장애 메시지, 그리고 부가적으로 신호 연결 제어부(SCCP) 관리계층의 관리 메시지들을 종합적으로 분석하여 장애를 감지 및 복구하는 방법에 관한 것이다. 본 발명에서는 시스템 하드웨어 측면에서의 장애와 공통선 신호방식(CCS No.7) 소프트웨어에 의한 장애를 동시에 고려하며, 장애 복구 측면에서는 ATM API계층에 이중화 장애 관리자를 두어 장애 시 ATM 가상 경로를 변경하여 하드웨어 인터페이스 카드를 활성화 및 비활성 할 수 있는 용이한 장애 복구 기법을 제공한다. 본 발명에서 제안한 이중화 구조와 장애 감지 및 복구 기법을 통해 공통선 신호방식의 메시지전송부분-계층3(MTP-3)이상의 프로토콜 소프트웨어를 이중화하지 않고도 홈 위치등록기의 신뢰성(Reliability)을 제공할 수 있다.