CA2264809C

Method and apparatus for encrypting radio traffic in a telecommunications network

Abstract

A generic communicationsnetwork (100) provides anencrypted communicationsinterface between service networks(130, 132, 134) and theirsubscribers. When communicationsare initiated between a subscribingcommunications terminal (118)and the generic network (100),the terminal (118) compares astored network identifier associatedwith a stored public key, witha unique identifier broadcast bythe generic network (100). If amatch is found, the terminal (118)generates a random secret key,encrypts the secret key with thestored public key, and transmitsthe encrypted secret key. Thegeneric communications network(100) decrypts the secret key usinga private key associated with thepublic key. The secret key is usedthereafter by the terminal (118)and the generic network (100) toencrypt and decrypt the ensuingradio traffic. Consequently, thenetwork (100) can maintain securecommunications with the terminal(118) without ever knowing the terminal's identity.

CA2264809C, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 26 August 2017, 9.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

44 claims: 6 independent, 38 dependent

  1. 1
    CA 02264809 2006-04-25 The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:1. A method for encrypting communications traffic between a mobile communications network and a communications terminal, the method comprising the steps of: storing a public key and a first identifier associated with said mobile communications network at said communications terminal;comparing said first identifier stored at said communications terminal with a second identifier received from said mobile communications network and producing a first predetermined result;generating a secret key at said communications terminal;encrypting said secret key with said stored public key at said communications terminal;and transmitting said encrypted secret key from said communications terminal.
  2. 6
    The method according to any one of claims 1 to 5, wherein the step of storing a public key comprises the step of priori pre-storing the public key.
  3. 7
    The method according to any one of claims 1 to 6, further comprising the step of transmitting said public key from said mobile communications network upon receiving a public key request from said communications terminal.
  4. 10
    The method according to any one of claims 1 to 9, wherein said mobile communications network comprises a generic communications network.
  5. 11
    The method according to any one of claims 1 to 9, wherein said mobile communications network comprises a cellular phone network.
  6. 12
    The method according to any one of claims 1 to 11, wherein said communications terminal comprises a mobile terminal.
  7. 13
    The method according to any one of claims 1 to 11, wherein said communications terminal comprises a fixed terminal.
  8. 14
    The method according to any one of claims 1 to 11, wherein said communications terminal comprises an unidentified communications terminal.
  9. 15
    The method according to any one of claims 1 to 14, further comprising the steps of:CA 02264809 2006-04-25 connecting a plurality of service networks to said mobile communications network, a user of said communications terminal being a subscriber to at least one of said plurality of service networks;and providing a communications path between said communications terminal and said at least one of said plurality of service networks.
  10. 16
    The method according to any one of claims 1 to 15, wherein said secret key comprises a symmetric encryption key.
  11. 17
    The method according to any one of claims 1 to 16, wherein the step of generating a secret key comprises the step of generating a naturally occurring random number.
  12. 18
    The method according to any one of claims 1 to 16, wherein the step of generating a secret key comprises the steps of:detecting a received signal in digital form at said communications terminal;and extracting at least one low order bit from said detected received signal.
  13. 19
    The method according to any one of claims 1 to 16, wherein the step of generating a secret key comprises the steps of:detecting a signal at an output of a microphone A/D converter;and extracting at least one low order bit from said detected output signal.
  14. 20
    The method according to any one of claims 1 to 16, wherein the step of generating a secret key comprises the steps of:detecting a signal at an output of a speech codec;and extracting at least one low order bit from said detected output signal.
  15. 21
    The method according to any one of claims 1 to 16, wherein the step of generating a secret key comprises the steps of:generating a seed for a pseudorandom number;and generating a pseudorandom number from said seed. CA 02264809 2006-04-25
  16. 22
    The method according to any one of claims 1 to 21, wherein a length of said secret key is predetermined at said communications terminal.
  17. 23
    The method according to any one of claims 1 to 22, wherein said secret key further comprises a plurality of concatenated numbers.
  18. 24
    The method according to any one of claims 1 to 23, wherein the step of storing said public key and said first identifier further comprises storing an expiration date associated with said public key.
  19. 26
    The method according to any one of claims 1 to 25, further comprising the steps of;changing said public key at said mobile communications network;and storing said changed public key at said communications terminal.
  20. 28
    A method for encrypting traffic between a generic communications network and a first communications terminal, the method comprising the steps of:broadcasting a public key from said generic communications network to a plurality of communications terminals, said plurality of communications terminals including said first communications terminal;generating a secret key at said first communications terminal;encrypting said secret key with said public key at said first communications terminal;transmitting said encrypted secret key from said first communications terminal;receiving said encrypted secret key at said generic communications network;CA 02264809 2006-04-25 decrypting said received encrypted secret key with a private key, said private key associated with said public key;and encrypting said traffic with said secret key.
  21. 31
    The method according to any one of claims 28 to 30, wherein said first communications terminal comprises an unidentified communications terminal.
  22. 34
    A method for encrypting communications traffic between a mobile communications network and a communications terminal, the method comprising the steps of:storing two numbers associated with a Diffie-Hellman exponential key exchange i algorithm and a first identifier associated with said mobile communications network at said communications terminal;CA 02264809 2006-04-25 comparing said first identifier stored at said communications terminal with a second identifier received from said mobile communications network and producing a first predetermined result;generating a first random number at said communications terminal;generating a second random number at said mobile communications network;and using said first and second random numbers as inputs to said Diffie-Hellman exponential key exchange algorithm, generating a third number to be used as a secret key by said communications terminal and said mobile communications network.
  23. 40
    The method according to any one of claims 34 to 39, further comprising the steps of:changing said two numbers associated with the Diffie-Hellman exponential key exchange algorithm at said mobile communications network;and storing said changed two numbers at said communications terminal. CA 02264809 2006-04-25
  24. 42
    A method for encrypting traffic between a generic communications network and a first communications terminal, the method comprising the steps of:broadcasting two numbers associated with an exponential key exchange algorithm from said generic communications network to a plurality of communications terminals, said plurality of communications terminals including said first communications terminal;generating a first random number at said first communications terminal;generating a second random number at said generic communications network;using said first and second random numbers as inputs to said exponential key exchange algorithm, generating a third number to be used as a secret key by said first communications terminal and said generic communications network;and encrypting said traffic with said secret key.
  25. 43
    A system for use in encrypting traffic between a generic communications network and a communications terminal, the system comprising:an access network included in said generic communications network;and access network means coupled to said communications terminal and associated with said access network, for storing a public encryption key associated with said generic communications network, generating a secret key, encrypting said secret key with said stored public encryption key, and transmitting said encrypted secret key to said generic communications network.
  26. 44
    A system for use in encrypting traffic between a generic communications network and a communications terminal, the system comprising:first network means for storing a private encryption key, distributing a public encryption key, and decrypting an encrypted secret session key;second network means connected to said first network means, for broadcasting said distributed public encryption key, said first and second network means associated with an access network of said generic communications network;and CA 02264809 2006-04-25 access network means coupled to said communications terminal and associated with said access network of said generic communications network, for receiving said broadcast public encryption key, generating a secret key, encrypting said secret key with said received public encryption key, and transmitting said encrypted secret key to said generic communications network.
Independent claims26