The disclosure relates to the field of wireless applications.
The disclosure relates in particular, but not exclusively, to access by a stationary or mobile client terminal to a mobile server terminal, in order to use services and/or consult or update data, made available by the mobile server terminal.
Today, mobile server terminals, such as mobile telephones or other portable radiocommunication terminals, are increasingly being used. The use of such mobile server terminals is, however, significantly limited by the fact that they must necessarily be connected to a private mobile network and that they can therefore be accessed only by stationary or mobile client terminals also connected to the same private network.
Indeed, it should be specified that any mobile communication network is made highly secure by means of one or more firewalls. Therefore, it is not possible to directly access a mobile server terminal that is connected to such a mobile communication network protected by this or these firewalls, from a stationary or mobile client terminal that does not belong to this same mobile network.
More specifically, and as shown in
An embodiment of the present invention is directed to a method for access, by at least one client terminal connected to a first communication network, to the data and/or services of a server terminal connected to a second communication network, wherein the first and second networks can cohabit or form a single network. One of the problems solved by an embodiment lies in particular in the fact that the server terminal is a mobile server terminal. Thus, such a method according to an embodiment of the invention advantageously includes at least the following steps:
The second communication network to which the mobile server terminal belongs is advantageously a wireless mobile communication network accessible via a security firewall.
The step of initialization of the communication preferably includes at least the following steps:
Thus, the successive sequence of these various steps advantageously makes it possible to initiate a communication session and to establish the opening of the direct communication tunnel between the client terminal and the mobile server terminal, wherein the tunnel passes through the security firewall(s) of the network on which the mobile server terminal is connected.
The access request signal transmitted by the client terminal is preferably of the type belonging to the group including at least:
The list of predetermined parameters advantageously includes at least parameters of the type belonging to the group including at least:
In a preferred embodiment of the invention, the list of predetermined parameters also advantageously includes at least one additional parameter corresponding to a unique call number of the second server terminal, when the access request signal is an SMS message, and/or corresponding to the type of the communication tunnel security protocol.
In an alternative of the preferred embodiment of the invention, the list of predetermined parameters also includes at least one additional parameter corresponding to an e-mail address of the second server terminal, when the access request signal is of the e-mail message type.
The security key is preferably a negotiation and/or encryption key.
In a preferred embodiment of the invention, the communication tunnel established between the client terminal and the mobile server terminal advantageously includes HTTP-type authentication means.
The communication tunnel established between the client terminal and the mobile server terminal advantageously includes secure data transmission means of the type using at least:
Another embodiment of the invention advantageously relates to a device for communication and/or radiocommunication between at least one client terminal and one mobile server terminal, characterised in that it implements the aforementioned method for access, by at least one client terminal connected to a first communication network, to the data and/or services of a server terminal connected to a second communication network, wherein the first and second networks can cohabit or form a single network.
Also advantageously, the method according to an embodiment of the invention is applied to a variety of fields belonging to the group including at least:
Other features and advantages will become more clear from the following description of a preferred embodiment, given by way of a simple illustrative and non-limiting example, and the appended drawings.
The term wireless application refers, according to a commonly accepted definition, to any type of real-time on-board applications requiring, for communication, a connection to a wireless and/or mobile network, such as a GSM, GPRS, and/or UMTS network, for example, other than mobile telephone and “hands-free” applications.
One or more embodiments of the invention relate to mobile server terminals executing such wireless applications intended to make various types of information and/or different types of service accessible to other stationary and/or remote mobile clients. These different types of services can either be specific and relate to only a restricted group of individuals, or be general and/or public, and thus be potentially accessible to any individual (Web page consultation on the Internet, for example).
Thus, an embodiment of the invention relates in particular, but not exclusively, to access by a stationary or mobile client terminal to a mobile server terminal, in order to use services and/or consult or update data, made available by the mobile server terminal.
By way of an illustrative and non-limiting example, an embodiment thus applies in particular but not exclusively to fields as varied as:
An embodiment of the invention provides a method for access to the services or data of a mobile server terminal of a public land network by means of a client terminal (stationary or mobile) connected to a different communication network, such as the Internet. Such a method is based in particular on the use of an SMS (Short Message Service) message or an e-mail message by the client terminal, in order to request the initialization of a communication session with said mobile server terminal. The initialization of such a session results in particular in the establishment of a communication tunnel between the client terminal and the mobile server terminal, which securely passes through the firewall and the network address translator (NAT).
Various embodiments of the invention can be technically envisaged, one of which is described in greater detail below.
A preferred embodiment of the invention is based on an original approach making it possible to authorise, for the purpose of security, the initialization of a communication session between a mobile server terminal of a public land network (PLMN) and a client terminal of another network, as if the client terminal belonged to said public land network.
This approach is based in particular on a relevant and original use of SMS (Short Message Service) messages including a set of parameters, in order to directly transmit to the proxy server of said public land network a request for initialization of communication with a previously identified mobile server terminal, which thus makes it possible to overcome the problem according to the prior art associated with the transmission of a TCP/IP request. Indeed, any request of this type for initialization of a communication session with a mobile terminal of a PLMN would in every case be blocked by the firewall and the network address translator of said PLMN.
The method according to an embodiment of the invention advantageously relates to the initialization of a communication session by the client terminal with the mobile server terminal, and the establishment of a communication session by opening a direct communication tunnel between the client terminal and the server terminal. The opening of such a direct tunnel thus enables the client terminal to consult information made available by the server terminal and/or to use and interact with all or some of the services of the server terminal.
As shown in
Thus, as shown in
It is understood that, in
Such a method according to an embodiment of the invention thus makes it possible for any client terminal of a communication network, such as the Internet, for example, to connect to a mobile client terminal of a PLMN public land network, as if it actually belonged to this public land network secured by firewalls and network address translators (NAT).
Moreover, it is important to emphasise that the sequence of steps for initialization of a communication session can be secured by encryption means with one or more public and private keys. Indeed, it is technically possible to consider encapsulating and encrypting predetermined parameters contained in the SMS message making it possible to establish the opening of a communication session and the associated communication tunnel.
In an alternative of the preferred embodiment mentioned above, the client terminal does not transmit an SMS directly to the private proxy server of the PLMN public land network, but transmits, to this private proxy server, an e-mail message secured by encryption means, which contains at least the same information for requesting the establishment of the communication session as that contained in the SMS message of the aforementioned preferred embodiment:
In the two embodiments of the invention mentioned above, the list of predetermined parameters also includes at least one additional parameter corresponding to a unique call number of the second server terminal, when the access request signal is an SMS message, and/or corresponding to the communication tunnel security protocol.
The method and device for access, by at least one client terminal connected to a first communication network, to the data and/or services of a mobile server terminal connected to a second highly-secure communication network, as proposed by an embodiment of the invention, have a number of advantages, of which a non-exhaustive list is provided below:
One or more embodiments of the invention provide a technique making it possible to communicate with a mobile server terminal from a first public land network (PLMN), from a stationary or mobile client terminal of a second public land network, in spite of the aforementioned technical security constraints of said first network.
In other words, an embodiment of the invention provides a technique making it possible to access the services and/or information of a mobile server terminal of a first public land mobile network of an operator, from a stationary or mobile client terminal not necessarily belonging to the same first network. It should be noted that the formulation of this problem, which also is contrary to the conventional practice of a person skilled in the art, is, per se, a part of an embodiment of the invention.
An embodiment of the invention provides such a technique that does not use the conventional connection methods of the prior art essentially based on TCP/IP request exchanges in order to establish a communication session with a mobile server terminal, from a client terminal.
An embodiment of the invention provides such a technique that can integrate various levels of security, in terms of initialization of a communication session with a mobile server terminal of a first land communication network, and in terms of access to the services and/or information of said mobile server terminal, from another stationary or mobile terminal not belonging to the same first network.
An embodiment of the invention further provides such a technique that also makes it possible to overcome the technical security constraints of the prior art mentioned above in the establishment of a communication session between a mobile server terminal belonging to a first public land network (PLMN) and a client terminal belonging to another network, but wanting to access or use the data and/or services of said mobile server terminal.
An embodiment of the invention yet further provides such a technique that promotes the technical convergence between wireless or mobile M2M applications and Internet services.
An embodiment of invention provides such a technique that is simple and inexpensive to implement.
Although the present invention have been described with reference to preferred embodiments, workers skilled in the art will recognize that changes may be made in form and detail without departing from the spirit and scope of the invention.
Number | Date | Country | Kind |
---|---|---|---|
0312766 | Oct 2003 | FR | national |
This Application is a Section 371 National Stage Application of International Application No. PCT/FR2004/002786, filed Oct. 28, 2004 and published as WO 2005/043847 on May 12, 2005, not in English.
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/FR04/02786 | 10/28/2004 | WO | 12/27/2006 |