System and method for location reporting in an untrusted network environment
    62.
    发明授权
    System and method for location reporting in an untrusted network environment 有权
    不信任网络环境中位置报告的系统和方法

    公开(公告)号:US09179436B1

    公开(公告)日:2015-11-03

    申请号:US14466747

    申请日:2014-08-22

    IPC分类号: H04W64/00

    摘要: An example method is provided and may include retrieving by a user equipment (UE) an access point (AP) Media Access Control (MAC) address for an AP to which the UE is connected; reporting location information for the UE to an evolved Packet Data Gateway over an SWu interface using Internet Key Exchange version 2 (IKEv2) protocol, wherein the location information includes, at least in part, a UE location in GPS coordinates, a service set identifier, the retrieved AP MAC address and cell identity information for the UE; and populating a location database with the location information. The method can include embedding the location information in an identity initiator (Idi) of an IKE Authentication Request (IKE_AUTH_REQ) message using a Network Access Identifier (NAI) and communicating the location information from the ePDG to a PGW over an S2b interface using a private extension information element of GPRS Tunneling Protocol version 2 (GTPv2).

    摘要翻译: 提供了一种示例性方法,并且可以包括由用户设备(UE)检索用于所述UE所连接的AP的接入点(AP)媒体接入控制(MAC)地址; 通过使用互联网密钥交换版本2(IKEv2)协议的SWu接口将UE的位置信息报告给演进的分组数据网关,其中所述位置信息至少部分地至少部分地包括GPS坐标中的UE位置,服务集标识符, 检索到的用于UE的AP MAC地址和小区标识信息; 并使用位置信息填充位置数据库。 该方法可以包括使用网络接入标识符(NAI)将位置信息嵌入在IKE认证请求(IKE_AUTH_REQ)消息的身份启动器(Idi)中,并且通过使用私有的通过S2b接口将位置信息从ePDG传送到PGW GPRS隧道协议版本2(GTPv2)的扩展信息元素。

    System and Method to Associate a Private User Identity with a Public User Identity
    63.
    发明申请
    System and Method to Associate a Private User Identity with a Public User Identity 有权
    将私人用户身份与公共用户身份相关联的系统和方法

    公开(公告)号:US20150312237A1

    公开(公告)日:2015-10-29

    申请号:US14720012

    申请日:2015-05-22

    IPC分类号: H04L29/06 H04L29/12 H04L29/08

    摘要: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time, To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record, if they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.

    摘要翻译: 本发明的系统包括主机,包括安全网关的网络和公共应用。 建立在网络和主机之间的访问会话以及公共应用程序和网络之间的应用程序会话。 为应用程序会话创建应用程序会话记录,并且包括用于访问公共应用程序的用户的公共用户身份,用于访问网络的用户的私人用户身份,主机身份和应用程序会话时间。要确定私人 应用程序会话的用户身份,安全网关发送具有主机身份和应用程序会话时间的查询。 将这些与访问会话记录中的主机身份和访问会话时间进行比较,如果匹配,则返回访问会话记录中的私有用户身份,并将其作为私有用户身份存储在应用程序会话记录中。

    Mobile radio access information validation
    64.
    发明授权
    Mobile radio access information validation 有权
    移动无线电接入信息验证

    公开(公告)号:US09166960B2

    公开(公告)日:2015-10-20

    申请号:US13127335

    申请日:2008-11-04

    摘要: A validation method for validating IP information header in data packets from user equipment connected to a mobile telecommunications network (1) and accessing an IP network (5) through a proxy. In the method trusted location information of the user equipment (2) from a trusted source of the telecommunications network is requested (109). Then, the trusted location information is inserted into the IP information header of a message (112) to be sent to a location based function (17).

    摘要翻译: 一种用于验证来自连接到移动电信网络(1)的用户设备的数据分组中的IP信息头并通过代理访问IP网络(5)的验证方法。 在该方法中,请求来自电信网络的信任源的用户设备(2)的可信位置信息(109)。 然后,将信任位置信息插入到要发送到基于位置的功能(17)的消息(112)的IP信息头中。

    IPV6 ADDRESS TRACING METHOD, APPARATUS, AND SYSTEM
    65.
    发明申请
    IPV6 ADDRESS TRACING METHOD, APPARATUS, AND SYSTEM 有权
    IPV6地址追踪方法,装置和系统

    公开(公告)号:US20150288581A1

    公开(公告)日:2015-10-08

    申请号:US14747559

    申请日:2015-06-23

    IPC分类号: H04L12/26 H04L29/12

    摘要: The present application provides an IPv6 address tracing method, apparatus, and system, where the method includes: receiving a to-be-traced target IPv6 address; selecting, in a longest match manner, IPv6 address information that matches the target IPv6 address, where the IPv6 address information includes an IPv6 address or IPv6 prefix information; and acquiring a user identifier corresponding to the IPv6 address information. The present application implements IPv6 address tracing.

    摘要翻译: 本申请提供了IPv6地址跟踪方法,装置和系统,其中所述方法包括:接收待跟踪的目标IPv6地址; 以最长匹配方式选择与目标IPv6地址匹配的IPv6地址信息,其中IPv6地址信息包括IPv6地址或IPv6前缀信息; 并获取与IPv6地址信息相对应的用户标识符。 本应用程序实现IPv6地址跟踪。

    TELECOMMUNICATION SYSTEM
    66.
    发明申请
    TELECOMMUNICATION SYSTEM 审中-公开
    电信系统

    公开(公告)号:US20150230084A1

    公开(公告)日:2015-08-13

    申请号:US14419006

    申请日:2013-07-17

    发明人: Dean Parsons

    IPC分类号: H04W12/04 H04W76/02

    摘要: A wireless communication system comprises: a first communication device (110); a second communication device (190) and; a target device (150), wherein the target device (150) is operable to establish a first connection over a first network with the first communication device (110) and a second connection over a second network with the second communication device (190), characterised in that first data which is exchanged between the first communication device (110) and the target device (150) is encrypted by an encryption means, and in that second data which is exchanged between the second communication device (190) and the target device (150) is unencrypted, such that a first user of the first communication device (110) can communicate with a second user of the second communication device (190).

    摘要翻译: 一种无线通信系统包括:第一通信设备(110); 第二通信设备(190)和 目标设备(150),其中所述目标设备(150)可操作以通过第一通信设备(110)在第一网络上建立第一连接,以及通过第二网络与所述第二通信设备(190)建立第二连接, 其特征在于,在所述第一通信设备(110)和所述目标设备(150)之间交换的第一数据由加密装置加密,并且所述第二数据在所述第二通信设备(190)和所述目标设备 (150)未被加密,使得第一通信设备(110)的第一用户可以与第二通信设备(190)的第二用户通信。

    LAWFUL INTERCEPTION FOR 2G/3G EQUIPMENT INTERWORKING WITH EVOLVED PACKET SYSTEM
    67.
    发明申请
    LAWFUL INTERCEPTION FOR 2G/3G EQUIPMENT INTERWORKING WITH EVOLVED PACKET SYSTEM 有权
    2G / 3G设备与演示分组系统的合法隔离

    公开(公告)号:US20150229675A1

    公开(公告)日:2015-08-13

    申请号:US14691749

    申请日:2015-04-21

    摘要: A method, system, and a computer program product for reducing consumption of resources for lawful interception or retention data related to traffic concerning a 2G/3G target mobile connected to a telecommunications network interworking with Evolved Packet System is provided. A first parameter value in traffic for which lawful interception or data retention has been activated is detected at a first node. Based on at least the first parameter value, whether the traffic will be intercepted or retained at a second node crossed by the traffic is evaluated. If the second node will intercept or retain the traffic, the first node foregoes a lawful interception request or retention of intercepted data.

    摘要翻译: 本发明提供了一种用于减少与涉及与演进分组系统相互作用的电信网络连接的2G / 3G目标移动业务的合法拦截或保留数据的资源消耗的方法,系统和计算机程序产品。 在第一个节点处检测到已启动合法拦截或数据保留的流量中的第一个参数值。 基于至少第一参数值,评估业务是否被被业务交叉的第二节点拦截或保留。 如果第二个节点将拦截或保留流量,则第一个节点放弃合法的拦截请求或保留拦截的数据。

    Network-based geo-location identification of an end-user device
    68.
    发明授权
    Network-based geo-location identification of an end-user device 有权
    基于网络的最终用户设备的地理位置识别

    公开(公告)号:US09077755B2

    公开(公告)日:2015-07-07

    申请号:US12481951

    申请日:2009-06-10

    摘要: A device receives a connection from a user device, and provides, to a database, connection information associated with the user device. The device receives, from the database, user device information based on the connection information, where the user device information includes a location associated with the user device. The device also receives a trigger instructing the device to provide the user device information to a content provider device, and provides the user device information to the content provider device when the trigger is received.

    摘要翻译: 设备从用户设备接收连接,并向数据库提供与用户设备相关联的连接信息。 该设备从数据库接收基于连接信息的用户设备信息,其中用户设备信息包括与用户设备相关联的位置。 设备还接收指示设备向内容提供商设备提供用户设备信息的触发器,并且在接收到触发器时将用户设备信息提供给内容提供商设备。

    Standard Telephone Equipment (STE) Based Deployable Secure Communication System
    69.
    发明申请
    Standard Telephone Equipment (STE) Based Deployable Secure Communication System 审中-公开
    标准电话设备(STE)基于部署的安全通信系统

    公开(公告)号:US20150163203A1

    公开(公告)日:2015-06-11

    申请号:US14596497

    申请日:2015-01-14

    发明人: Steven Anspach

    IPC分类号: H04L29/06

    摘要: Sensitive, Standard Telephone Equipment (STE) data is encapsulated into IP packets in a remotely deployed, secure communication system. The IP packets are addressed to a matching IP encapsulator/decapsulator device over the public Internet or other IP protocol network, that then passes it to a similar STE device over an ISDN link for decryption. The present invention is embodied in a system that provides secure Voice-Over-IP (VOIP), video and data network functionality in a single, small size deployable case, to a remote user. Most importantly, the embodiment allows for the routing of bulk encrypted (i.e., secure) data over a public network, e.g., the Internet.

    摘要翻译: 敏感的标准电话设备(STE)数据被封装在远程部署的安全通信系统中的IP数据包中。 IP分组通过公共因特网或其他IP协议网络寻址到匹配的IP封装/解封装器设备,然后通过ISDN链路将其传递到类似的STE设备以进行解密。 本发明体现在向远程用户提供单个小型可展开情况下的安全的IP语音(VOIP),视频和数据网络功能的系统中。 最重要的是,该实施例允许通过公共网络(例如因特网)路由批量加密(即,安全)数据。

    Lawful interception for 2G/3G equipment interworking with evolved packet system
    70.
    发明授权
    Lawful interception for 2G/3G equipment interworking with evolved packet system 有权
    合法拦截2G / 3G设备与演进分组系统互通

    公开(公告)号:US09042388B2

    公开(公告)日:2015-05-26

    申请号:US13055021

    申请日:2008-07-24

    IPC分类号: H04W12/02 H04W12/08 H04L29/06

    摘要: A method, system, and a computer program product for reducing consumption of resources for lawful interception or retention data related to traffic concerning a 2G/3G target mobile connected to a telecommunications network interworking with Evolved Packet System is provided. At least a first parameter value in data for which lawful interception or data retention has been activated is detected at a first node. Based on at least the first parameter value, whether the traffic is intercepted or retained at a second node crossed by the traffic in the same network is evaluated. If the second node is located downstream of the first node, lawful interception requests or intercepted data are filtered out.

    摘要翻译: 本发明提供了一种用于减少与涉及与演进分组系统相互作用的电信网络连接的2G / 3G目标移动业务的合法拦截或保留数据的资源消耗的方法,系统和计算机程序产品。 在第一个节点处检测到至少已经激活合法拦截或数据保留的数据中的第一个参数值。 基于至少第一参数值,评估是否在由相同网络中的业务越过的第二节点处拦截或保留业务。 如果第二个节点位于第一个节点的下游,那么合法的拦截请求或拦截的数据将被过滤掉。