Methods and software program product for mutual authentication in a communications network
Abstract
A method for mutual authentication between a user and a communication network. In the above method, a random number is generated at the user's terminal (1, 1'). The random number, for example, together with the user identifier, is sent to the authentication subsystem (6, 6') that manages the authentication of users who want to access the network. In the verification subsystem, the identifier is used to check the user's credentials. In the verification process, the verification subsystem generates parameters related to the user identifier, and the random number is encrypted by a session key formed using these parameters. Then, the encrypted random number, together with the information required by the terminal to reconstruct the session key, is sent back to the user terminal. After the session key has been reconstructed, the user terminal decrypts the random number and checks for a match with the random number it generates. The match between these two numbers allows the user to verify that the access point (2) with which he/she is connecting is not a counterfeit access point.

Term
Term ended
Projected expiry passed 5 March 2024, 2.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
27 claims: 4 independent, 23 dependent
- 1一种用于用户和通信网络之间的相互验证的方法,向所述用户提供一个终端(1),对其可操作地连接用户身份模块(1’),所述用户身份模块存储与所述用户有关的至少一个标识符和唯一密钥的第一副本,所述网络包括一个验证子系统(6,6’),该验证子系统至少包括第一验证装置(6’),存储与所述用户标识符有关的所述唯一密钥的第二副本,所述方法包括:—从所述用户身份模块(1’)向所述终端(1)发送所述用户标识符;—在所述终端(1)生成第一数;—通过所述网络的一个接入点(2),从所述终端(1)向所述验证子系统(6,6’)发送所述标识符和至少部分所述第一数;—在所述验证子系统(6,6’),使用所述标识符来识别所述唯一密钥的所述第二副本,至少生成第二数,并且用所述唯一密钥的所述第二副本来查询所述第二数,以便至少生成第一会话密钥和第一签名响应;—在所述验证子系统(6,6’),根据第一规则,使用至少所述第一会话密钥来形成第二会话密钥,并且使用所述第二会话密钥来至少加密所述第一数部分;—从所述验证子系统(6,6’)向所述终端(1)至少发送所述加密的第一数部分和所述第二数;—将所述第二数从所述终端(1)送往所述用户身份模块(1’),并且在用户身份模块(1’),用所述唯一密钥的所述第一副本来查询所述第二数,以便至少生成第三会话密钥和第二签名响应;—从所述用户身份模块(1’)向所述终端(1)发送所述第三会话密钥和所述第二签名响应;—在所述终端(1),根据对应于所述第一规则的第二规则,使用至少所述第三会话密钥来形成第四会话密钥,并使用所述第四会话密钥来解密从所述验证子系统(6,6’)接收的第一数部分;—在所述终端(1),检查所述解密的第一数部分与所述生成的第一数的对应部分之间的匹配,以便允许从所述网络向所述终端(1)通信;—从所述终端(1)向所述验证子系统(6,6’)至少发送所述第二签名响应;—在所述验证子系统(6,6’),检查所述第一签名响应与所述第二签名响应之间的匹配,以便允许从所述终端(1)到所述网络的通信。
- 2根据权利要求1的方法,其特征在于,它还包括在从所述终端(1)向所述验证子系统(6,6’)发送之前,在所述终端(1)加密所述标识符和所述第一数部分,利用存储在所述终端(1)上的预定公钥来进行所述加密。
- 3根据权利要求2的方法,其特征在于,它还包括在验证子系统(6,6’)解密所述标识符和所述第一数部分,利用与所述预定公钥有关的私钥来进行所述解密。
- 4根据权利要求1至3中任何一项的方法,其特征在于,用于形成所述第二会话密钥的所述第一规则包括连接所述第一会话密钥和所述第一签名响应。
- 5根据权利要求4的方法,其特征在于,用于形成所述第四会话密钥的所述第二规则包括连接所述第三会话密钥和所述第二签名响应。
- 6根据权利要求1至5中任何一项的方法,其特征在于,在所述验证子系统(6,6’)中使用所述第二会话密钥至少加密所述第一数部分的步骤包括:还加密在所述验证子系统(6,6’)生成的事务标识符。
- 7根据权利要求6的方法,其特征在于,在所述终端(1)使用所述第四会话密钥来解密从所述验证子系统(6,6’)接收的所述第一数部分的步骤还包括:解密所述事务标识符。
- 8根据权利要求7的方法,其特征在于,它还包括从所述终端(1)向所述验证子系统(6,6’)发送解密的事务标识符。
- 9根据权利要求1至8中任何一项的方法,其特征在于,它还包括在所述验证子系统(6,6’)至少生成第三数,并且通过所述唯一密钥的所述第二副本来查询所述第三数,以便至少生成第五会话密钥和第三签名响应。
- 10根据权利要求9的方法,其特征在于,用于形成所述第二会话密钥的所述第一规则包括:连接所述第一会话密钥和所述第一签名响应中的至少一个和所述第五会话密钥和所述第三签名响应中的至少一个。
- 11根据权利要求9或10的方法,其特征在于,从所述验证子系统(6,6’)向所述终端(1)至少发送所述加密的第一数部分和所述第二数的步骤还包括:向所述终端(1)发送所述第三数。
- 12根据权利要求11的方法,其特征在于,它还包括在所述用户身份模块(1’)通过所述唯一密钥的所述第一副本来查询所述第三数,以便至少生成第六会话密钥和第四签名响应。
- 13根据权利要求12的方法,其特征在于,所述用于形成所述第四会话密钥的所述第二规则包括:连接所述第三会话密钥和所述第二签名响应中的至少一个和所述第六会话密钥和所述第四签名响应中的至少一个。
- 14一种允许用户验证一个通信网络的可信度的方法,向所述用户提供一个终端(1),对其可操作地连接一个用户身份模块(1’),所述用户身份模块存储与所述用户有关的至少一个标识符和至少一个唯一密钥,所述网络包括一个验证子系统(6,6’),所述方法包括,在所述终端(1):—从所述用户身份模块(1’)接收所述用户标识符;—生成第一数;—通过所述网络的接入点(2),向所述验证子系统(6,6’)发送所述标识符和至少部分所述第一数;—通过接入点(2)从所述验证子系统(6,6’)接收在所述验证子系统(6,6’)生成的一个加密的数和至少第二数;—将所述第二数送往所述用户身份模块(1’);—从所述用户身份模块(1’)至少接收通过用所述唯一密钥查询所述第二数而在所述用户身份模块(1’)获得的第一会话密钥和第一签名响应;—根据预定规则,使用所述第一会话密钥和第一签名响应中的至少一个来生成第二会话密钥;—使用所述第二会话密钥,解密从所述验证子系统(6,6’)接收的所述加密的数;—检查所述第一数的所述部分与所述解密的数的对应第一部分之间的匹配,以便允许所述网络的可信度验证。
- 15根据权利要求14的方法,其特征在于,它还包括在从所述终端(1)向所述验证子系统(6,6’)发送的所述步骤之前,在所述终端(1)加密所述标识符和所述第一数部分,使用存储在所述终端(1)上的预定公钥来进行所述加密。
- 16根据权利要求14或15的方法,其特征在于,用于形成所述第二会话密钥的预定规则包括连接所述第一会话密钥和所述第一签名响应。
- 17根据权利要求14至16中任何一项的方法,还包括向所述验证子系统(6,6’)发送所述第一签名响应。
- 18根据权利要求17的方法,还包括向所述验证子系统(6,6,)发送所述已解密数的第二部分。
- 19根据权利要求14至18中任何一项的方法,其特征在于,它还包括从所述验证子系统(6,6’)至少接收在所述验证子系统(6,6’)生成的第三数。
- 20根据权利要求19的方法,其特征在于,它还包括将所述第三数送往所述用户身份模块(1’)。
- 21根据权利要求20的方法,其特征在于,它还包括从所述用户身份模块(1’)至少接收通过用所述唯一密钥查询所述第三数而在所述用户身份模块(1’)获得的第三会话密钥和第二签名响应。
- 22根据权利要求21的方法,其特征在于,所述用于形成所述第二会话密钥的所述预定规则包括连接所述第一会话密钥和所述第一签名响应中的至少一个和所述第三会话密钥和所述第二签名响应中的至少一个。
- 23一种可装入计算机的存储器的软件程序,包括用于执行权利要求14至22中任何一项的各个步骤的软件代码部分,当在计算机上运行时,所述计算机程序产品适于输出允许用户验证所述用户正在与之连接的一个通信网络的可信度的信息。
- 24一种软件程序产品,包括从用户的终端可访问的载体,在其上存储根据权利要求23的软件程序。
- 25一种在通信网络中用于验证用户的终端(1)的验证套件,包括根据权利要求24的软件程序产品和用户身份模块(1’)。
- 26根据权利要求25的套件,其特征在于,所述用户身份模块(1’)是在移动通信网络中用于验证移动通信终端所采用的类型。
- 27一种允许用户验证一个通信网络的可信度的方法,向所述用户提供一个终端(1),具有标识符和共享秘密,所述网络包括一个验证子系统(6,6’),其中存储与所述共享秘密的副本有关的所述用户标识符,所述方法包括,在所述终端(1)的控制下:—生成第一数;—通过所述网络的一个接入点(2),向所述验证子系统(6,6’)发送所述用户标识符和至少部分所述第一数;—通过接入点(2)从所述验证子系统(6,6’)接收一个加密的数,通过基于所述共享秘密的所述副本以及在所述验证子系统(6,6’)生成的第二数而在所述验证子系统(6,6’)生成的会话密钥来加密所述加密的数;—通过所述接入点(2)从所述验证子系统(6,6’)接收所述第二数;—处理所述第二数和所述共享秘密,以便获得所述会话密钥的副本;—使用所述会话密钥的所述副本,解密从所述验证子系统(6,6’)接收的所述加密的数;—检查所述第一数的所述部分与所述解密的数的对应部分之间的匹配,以便允许所述网络的可信度验证。
Independent claims27
44 paragraphs, as filed
Method and software program product for mutual verification in communication network
Technical field
The present invention relates to an authentication method in a communication network, especially in a packet (for example, Internet Protocol IP) network.
Background technique
In recent years, the strong growth in the number of Internet users has become one of the most striking phenomena in the communications field. The Internet has been born and has developed into an "open network" suitable for sharing information among users. Applications based on Internet communication protocols, such as Simple Mail Transfer Protocol (SMTP), File Transfer Protocol (FTP), or Hypertext Transfer Protocol (HTTP), such as e-mail, web browsing, and file downloading have now become common knowledge, and Used by a growing number of users. Internet technology is also used in environments that are not open to the public (such as within a company's local area network) to share information among employees in a so-called intranet environment. Recently, wireless local area network (W-LAN) technology has also been born and is being developed. By using wireless network terminal adapters and access points, users of the Internet or Intranet can be connected to the network without the use of cables.
In order to connect to the network, the known technology provides such a service: the user presents its credentials to an authentication server that may belong to a service provider in the form of a user identification and a related password. For example, Remote Authentication Dial-In User Service (RADIUS) is a known server for remote user authentication based on a user ID/password scheme.
In the PCT patent application No. 00/02406 filed under the name Nokia Networks OY, another proposed method for authentication in order to access a network, especially an IP network, is disclosed. In order to allow authentication of IP network users in a geographically wide area, the terminal of the IP network uses a subscriber identity module (SIM, subscriber identity module) as used in a separate mobile communication system. The query given to the identity module can confirm the response. The IP network includes a dedicated security server, and when a user connects to the IP network, a message about a new user is sent to the server. The users authentication information including at least one query and one response is taken from the mobile communication system and sent to the IP network, and the query is sent to the terminal through the IP network, and the terminal In the identity module of, a response is generated from the query, and verification is performed based on the verification information obtained from the mobile communication system by comparing the response with the response received from the mobile communication system. In fact, as disclosed in the same PCT patent application, the existing mobile communication network, especially the Global System for Mobile Communications (GSM) authentication method, is used in the IP network.
No specific details are involved. The typical authentication process used in mobile communication networks (such as GSM networks) provides such a service: when a mobile terminal needs to connect to the mobile network, it first sends a message to the network and stores it with the mobile terminal. The International Mobile Subscriber Identifier (IMSI) in the relevant SIM. The verification center (AuC) receives the IMSI number and generates a random number RAND to be input to an algorithm dedicated to verification (the so-called A3 algorithm). The algorithm is parameterized with the encryption key ki uniquely related to the IMSI number and applied to the random number RAND to give a so-called signed response SRES 1 result. The random number RAND is also sent to the mobile terminal, especially to the SIM related to the mobile terminal, in order to query the generation of the signature response SRES 2, which may be derived from the SIM storing the same encryption key ki and algorithm. A3 facts. Subsequently, SRES2 is sent to AuC, which checks the match between SRES 1 and SRES 2 in order to authorize the mobile terminal to access the mobile network. If the match between SRES 1 and SRES 2 cannot be confirmed, then access to the mobile network is denied.
The use of the authentication process described above for connecting to a communication network other than a mobile network (such as the Internet or a company intranet) improves the security with respect to the process, and only requires a user ID and password. For example, the service provider can basically be guaranteed that the credentials given by the user requesting the connection are genuine, that is, the user is really one of its users.
However, the applicant has observed that using the above verification process cannot guarantee the user in the same way as the service provider, that is, it cannot assure the user that he/she has not passed the service pretending to be the user. A counterfeit access point provided by a malicious entity of the provider gives his/her confidential data to a "counterfeit" network. In particular, the applicant has observed that the user cannot verify that he/she is accessing correctly due to the matching between the signature response SRES1 generated by AuC and the signature response SRES2 generated by the users SIM only on the network side. Its trusted network.
The applicant has also observed that since the counterfeit access point of the wireless local area network is relatively easy to implement, such a problem is particularly important for using the wireless local area network technology to access the network.
The applicant has faced the problem of implementing a verification method, especially a verification method suitable for accessing a communication network, especially a packet-based (for example, IP) network, in which, between the user and the service provider It can ensure two-way mutual recognition.
Summary of the invention
The applicant has found that this problem can be solved by a verification method, in which a random number is generated on the user's terminal. The random number, for example, together with an identifier of a user, is sent to an authentication subsystem that manages authentication of users who want to access the network. In the verification subsystem, the identifier is used to check the user's credentials. In the verification process, various parameters related to the user identifier are generated in the verification subsystem, and the random number is encrypted by a session key formed using these parameters. Then, the encrypted random number, together with the information required by the terminal to reconstruct the session key, is sent back to the user terminal. After the session key has been reconstructed, the user terminal decrypts the random number and checks the match with the random number generated by it. The match between these two numbers allows the user to verify that the access point he/she is connecting to is not a counterfeit access point.
In a first aspect, the present invention relates to a mutual authentication method between a user and a communication network as disclosed in claim 1. In claims 2 to 13, various preferred forms of the method of the first aspect are disclosed.
In a second aspect, the present invention relates to a method for allowing a user to verify the credibility of a communication network as disclosed in claim 14. In claims 15 to 22, various preferred forms of the method of the second aspect are disclosed.
In a third aspect, the present invention relates to a software program as disclosed in claim 23.
In the fourth aspect, the present invention relates to a software program product as disclosed in claim 24.
In a fifth aspect, the present invention relates to a verification kit as disclosed in claim 25. In claim 26, a preferred embodiment of the verification kit of the fifth aspect is disclosed.
In a sixth aspect, the present invention relates to a method for allowing a user to verify the credibility of a communication network as disclosed in claim 27.
Description of the drawings
Through the following detailed description of certain embodiments of the present invention provided only by means of non-limiting examples and with reference to the accompanying drawings, the features and advantages of the present invention will become more apparent. In the accompanying drawings:-Figure 1 shows A schematic diagram of the communication network architecture used in the present invention
detailed description
Fig. 1 shows an exemplary embodiment of a communication network architecture in which a remote user is connected to an access point 2 in order to access an IP network 7, such as the Internet. The service provider may provide different access points 2 so that different remote users located in different geographical locations can realize network access.
The remote user has a terminal 1, such as a personal computer, for example a portable computer, which carries appropriate client software (for example a RADIUS-based software program) and hardware suitable for connecting to the network 7 through the access point 2. For this purpose, the computer 1 is for example connected to a modem (for example, an ISDN modem) and uses a dial-up connection, or an xDSL modem and uses an xDSL connection, or a GPRS modem and uses a wireless connection, or a wireless local area network (WLAN) terminal adapter And use W-LAN connection (such as wireless fidelity-WI FI-connection, a kind of Internet access that is increasingly popular in hotels and airports) to access point 2.
In order to access the network 7, the user is authenticated by the service provider. For verification purposes, remote users are provided with a user identity module 1', especially (though not restrictively) Digital Cellular Telephone System (DCS) or Public Land Mobile Networks (PLMN, Public Land Mobile Networks), such as the widely popular Global Mobile Communication system (GSM) mobile phone networks, or extensions of them, such as the General Packet Radio Service (GPRS) network (which is actually a sub-network of the GSM network), or the Universal Mobile Telecommunications System (UMTS) network (a A broadband third-generation cellular communication system), or a subscriber identity module (SIM) for authentication purposes in a satellite-based mobile telecommunications network.
As known in the art, SIM usually takes the form of a card with embedded integrated circuit components (the size of a credit card or smaller, depending on the size of the user terminal's miniaturization), and especially stores that support SIM verification and encryption and decryption. Personal data. At least so far, the use of SIM (and the SIM-based verification process) to identify the mobile communication terminal connected to it has proven to be a reliable method for making it impossible for other devices to counterfeit the terminal, thereby for example corresponding to the specific The user's account provides secure and authenticated access.
The user's SIM 1'is operatively, and preferably detachably connected to the remote user's computer 1; for example, the SIM 1'is embedded in a computer peripheral device that can be operatively connected to the computer 1, In order to be functionally accessible by the computer 1, for example, a hardware key that can be connected to a port of the computer 1 (for example, a universal serial bus (USB) port, not explicitly shown in Figure 1); alternatively The SIM 1 can be operatively connected to the computer 1 via a PCMCIA port, or by means of a peripheral device of the smart card reader type adapted to interact with the SIM and connected to, for example, the serial port of the computer 1, or the SIM 1'can be Embedded in a memory card, the card can be operatively connected to the computer 1 by means of a memory card reader. It should be pointed out that the specific method by which the SIM 1'is operatively connected to the computer 1 is not limited to the present invention. Generally speaking, by means of any type of adapter/readout connected to the computer 1 through any type of peripheral port. The method of operatively connecting the SIM 1'to the computer 1 (in a method suitable for establishing communication between the computer 1 and the SIM 1') is sufficient. The client software installed in the user's personal computer 1 and adapted to connect to the network 7 is also adapted to communicate with the SIM 1'connected to the personal computer 1.
The access point 2 is connected to an access node 5, which may include a network access server (NAS) 3 and a gateway 4. The access node 5 is operatively connected to an authentication server 6. As shown in FIG. 1, the authentication server 6 may be part of a mobile network 8 of a mobile operator. The access node 5 may also be connected to the network 7 to which remote users require access through a proxy server 9, such as a firewall, especially if the network 7 is a private network such as a company intranet.
With reference to the access node 5, it remains to be understood that even though Figure 1 shows the NAS 3 and the gateway 4 as separate functional entities within the access node 5, in fact, they can correspond to appropriate Software Products. The NAS 3 may be a router suitable for routing traffic to and from the access point 2. The gateway 4 can be used to select where the service from the access point 2 should be sent: in particular, the service from the access point 2 should be sent during the authentication process of the remote user connected to the access point 2 To the authentication server 6 (and vice versa), and once the remote users authentication has been confirmed, the traffic from the access point is sent to the network 7 (and vice versa).
The authentication server 6 is used to receive the identification information of the remote user, so as to verify that the remote user is a trusted user of the network access service provider. Moreover, the authentication server 6 is also used to provide the remote user with information suitable for the remote user to verify that the network he/she is connected to is not a counterfeit network provided by an entity that pretends to be his/her service provider. Therefore, the entire verification process, which will be detailed below, allows mutual verification between the remote user and the service provider. In a preferred embodiment, the authentication server 6 is located in the mobile network operators premises and is adapted to communicate with the mobile network operators home location register (HLR) 6'in order to follow the mobile terminal requesting access to the mobile network. The well-known verification process is used for the verification of remote users. In particular, the HLR 6'of the mobile network operator includes a database in which identifiers and keys uniquely related to the remote user are stored. Such identifiers and keys are also stored on the SIM 1'of the remote user. In other words, the authentication server 6 performs a function similar to the visitor location register (VLR) contained in the mobile network operators network in order to authorize or deny the remote users access to the IP network 7: therefore, in the following, the authentication The server 6 will be referred to as I-VLR 6. I-VLR 6 can run standard software, such as RADIUS, to control at least some steps of the authentication process.
When requesting access to the network 7, the remote user runs client software dedicated to controlling the connection with the access point 2. Fig. 2 shows a preferred embodiment of the message flow exchanged between various devices of the network architecture shown in Fig. 1.
Referring to Figure 2, the software client communicates with the SIM (100) to recover the user's identifier (101), such as the International Mobile Subscriber Identifier (IMSI) or Temporary Mobile Subscriber Identifier (TMSI) stored on the SIM. Moreover, the software client generates a number, preferably a random number Ra, which, as will be explained below, plays a required role in each step of the authentication process in order to allow the user to connect the access point 2 and Network 7 is verified as "trusted". Here and in the following, the noun "number" can be interpreted as any binary, octal, decimal, or hexadecimal number, or even as a universal alphanumeric string.
The software client also controls the connection to the NAS 3 through the access point 2. In the step marked 102 in FIG. 2, the software client sends the identifier recovered from the SIM and at least a part of the random number Ra to the NAS 3. For example, referring specifically to RADIUS-based connections, the identifier IMSI and the random number Ra can be connected together in the RADIUS username field, and the RADIUS password field can be filled with any fixed character string (for example, "SIM Auth Subs"). In order to increase privacy, the identifier and random number Ra can be sent in encrypted form. For the purpose of encryption, the user's software client may include a public key, such as an RSA-based key provided in advance by the service provider, and then retain the related private key. In a preferred embodiment, the public key has a length of at least 1024 bits. The connection agreement between the personal computer 1 and the NAS 3 from the remote user may also include sending a domain field, for example to allow the NAS 3 to recognize different types of connection requests, such as dial-up requests, xDSL requests, or W-LAN requests. Advantageously, a single NAS 3 can manage different types of connections from various types of access points 2 in this way, and can also manage connection requests from an access point of another service provider. For example, you can fill in the domain field "@wl" to identify the wireless local area network connection, or "@ia" to identify the dial-up connection.
NAS 3 sends the identifier and random number Ra to I-VLR 6 (shown as 103 in Fig. 2). The decryption of the identifier and the random number Ra can be performed in NAS 3, or, preferably, in I-VLR 6. The I-VLR extracts the user's identifier, such as IMSI, and sends it to the HLR 6'(shown as 104 in FIG. 2). The HLR 6'(or the authentication center AuC connected to the HLR 6') includes a database in which a unique key ki is associated with the IMSI. The unique key ki is also stored on the SIM 1'of the remote user. In other words, the unique key ki represents a secret shared between the SIM 1'and the authentication subsystem of the network (including I-VLR 6 and HLR 6'or AuC). Following the process usually used in the verification of mobile phones in mobile phone networks, HLR 6'(or AuC) generates a random number Rand 1, and applies the first algorithm parameterized with a unique key ki, such as the well-known A3. Algorithm in order to get the signature response SRES 1. Furthermore, a second algorithm parameterized with a unique key ki, such as the well-known A8 algorithm, is applied to the random number Rand 1, so as to obtain the session key kc1. In other words, the HLR 6'is adapted to obtain at least one triplet parameter related to the identifier of the remote user, the triplet parameter being composed of Rand 1, kc1, and SRES 1. In a preferred embodiment, the HLR 6'requires at least one second triplet. The second triplet is generated starting with yet another random number Rand 2, and the same process as described above is applied. The second triplet is composed of another random number Rand 2, another related session key kc2, and another signature response SRES 2. Then, the (each) triplet is sent from HLR 6'to I-VLR 6 (105).
After receiving the triplet(s), the I-VLR 6 adopts another algorithm (such as the well-known 3DES algorithm) parameterized by using at least the authentication session key generated by the triplet parameters according to predetermined rules. Encrypt the random number Ra. More specifically, the authentication session key may be the key kc1 or kc2, or their connection, or the connection of the keys kc1 and/or kc2 and the signature response SRES 1 and/or SRES 2. In a preferred embodiment, at least a part of the random number Ra received from the software client can also be connected with the triplet parameter in order to generate the authentication session key. The connection of different parameters obtained from more than one triplet allows to obtain a longer authentication session key, thus a more secure connection between the I-VLR 6 and the users personal computer 1. In the case of a wireless LAN connection, this Is particularly important. For example, the authentication session key formed by the connection of kc1, SRES 2, kc2, and Ra 8 can be used to encrypt the random number Ra, where Ra 8 is the first 8 bits of the random number Ra. It is also possible to use the authentication session key together with the random number Ra to encrypt another random number TID (or a part of it) generated by the I-VLR 6. Such another random number TID can be in I-VLR 6 Identifies the transaction identifier of the specific connection session initiated by the remote user's personal computer 1. After encrypting the random number Ra (and possibly the random number TID), the encrypted frame is sent to the personal computer along with the random numbers Rand 1 and Rand 2 (the latter appears when the HLR 6'obtains two triples) 1(106), that is, sent to the software client that controls the network connection.
Then, the two random numbers Rand 1 and Rand 2 obtained by the HLR 6'are sent from the client software to the SIM (107) in order to query the SIM to use the stored unique key ki to generate the related keys kc1, kc2, and Signature response SRES 1, SRES 2.
Then, the SIM provides the obtained parameters to the software client (108). Using the parameters obtained by the SIM, the software client can reconstruct the authentication session key in a manner corresponding to that used by the I-VLR in order to decrypt the encrypted frame received from the I-VLR 6. The rules used by the software client to reconstruct and verify the session key are the same as those used by the I-VLR. After the authentication session key has been reconstructed, the software client can extract the random number Ra received from the I-VLR 6 and compare it with the random number Ra generated by itself at the beginning of the process. The matching of the two random numbers Ra will allow the software client (ie, the user) to verify that the connection service used by the personal computer 1 to connect to the network 7 is authentic. in other words. It is possible for the user to "verify" the connection service.
In order to complete the verification process, the software client sends at least one of the signature response SRES 1 or SRES 2 generated by the SIM and possibly encrypted with the verification session key to the I-VLR 6 (109). The transaction identifier TID can also be encrypted along with the signed response(s) and sent to the I-VLR 6. The I-VLR 6 then checks whether there is a match between the signature response(s) generated locally and the signature response(s) generated by the SIM 1'.
If the matching between the signature responses is confirmed, an acceptance request message is sent to the software client (110), allowing access to the network 7. It is possible to send a registration message to the proxy server 9 in order to allow remote users to use IP services (such as HTTP, FTP, SMPT, etc.). In this way, the service provider that provides the connection service to the user authenticates the user.
On the other hand, if the matching between the signature responses cannot be confirmed, a rejection request is sent from the I-VLR6 to the software client (112). It is also possible to send a stop billing message (113) from the I-VLR 6 to the NAS 3 in order to instruct the NAS 3 to interrupt the communication with the personal computer 1.
The above-disclosed verification process for the remote user terminal to access the network service thus allows mutual authentication between the remote user and the network service. Advantageously, such mutual authentication improves the security of all connections, including connections containing parts that use wireless connection paths, such as wireless local area network connections. Such mutual authentication allows the service provider to identify the remote user, and also allows the remote user to identify the service provider, so that confidential information from the remote user cannot be captured by hackers who set up counterfeit services through a counterfeit access point. Moreover, as described above, the authentication process can be advantageously set up so as to use the same protocol for different connection types, and even for managing connection requests from access points belonging to different service providers.
It should be understood that, as those skilled in the art will see, the actual operations determined in the above process can be implemented by appropriate software code portions of a computer program and executed by any well-known general-purpose computer with appropriate processing capabilities. In particular, the description of the processing steps enables those skilled in the art to implement computer program codes suitable for specific environments and equipment, such as specific machines, computer languages, operating systems, and the like.
The software program implemented in accordance with the teachings of the present invention may be included in one or more executable files, for example, and the above-mentioned executable files reside in a suitable carrier accessible by the computer's memory, such as a hard disk, a floppy disk, a CD-ROM or DVD-ROM, or an external disk that can be read through a local area network. For the purpose of the present invention, the term "software (or computer) program suitable for loading into the memory of a computer" also includes files required to execute the executable file(s), such as various library files, initialization files, etc. Etc., the above-mentioned files may reside in a suitable carrier accessible to the memory of the computer, such as a hard disk, a floppy disk, a CD-ROM or a DVD-ROM, or an external disk that can be read through a local area network. Moreover, for the purpose of the present invention, the term "software program" also includes files that may be different from the executable file(s) and/or from the files needed to execute the executable file. When running on a computer, the above-mentioned files are included in Installable software suitable for installing executable file(s) and files required to execute the executable file. Such installable software can reside on an appropriate support (media), such as a disk or CD-ROM, or it can be downloaded from a network resource, such as included in a local area network or through an external network (such as the Internet). The server that arrived.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2011054232A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN104811936A | Cited by | China | Search report |
| CN106571927A | Cited by | China | Search report |
| CN111431717A | Cited by | China | Search report |
| US9160717B2 | Cited by | United States of America | Applicant |
| CN104239942A | Cited by | China | Search report |
| US10681151B2 | Cited by | United States of America | Applicant |
| US8943322B2 | Cited by | United States of America | Applicant |
| CN106714156A | Cited by | China | Search report |
| CN101605333A | Cited by | China | Search report |
| CN102792630A | Cited by | China | Search report |
20 members in 10 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| RM2003A000100 | Italy | – | |
| RM20030100 | Italy | A |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| ITRM20030100A0 | Italy | A0 | |
| ITRM20030100D0 | Italy | D0 | |
| ITRM20030100A1 | Italy | A1 | |
| CA2518032A1 | Canada | A1 | |
| WO2004079985A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1602194A1 | European Patent Office (EPO) | A1 | |
| BRPI0408069A | Brazil | A | |
| CN1757195AThis record | China | A | |
| US2006189298A1 | United States of America | A1 | |
| JP2006522514A | Japan | A | |
| US7231203B2 | United States of America | B2 | |
| IT1343350B1 | Italy | B1 | |
| EP1602194B1 | European Patent Office (EPO) | B1 | |
| AT402533T | Austria | T | |
| ATE402533T1 | Austria | T1 | |
| DE602004015259D1 | Germany | D1 | |
| CN100568799C | China | C | |
| JP4898427B2 | Japan | B2 | |
| CA2518032C | Canada | C | |
| BRPI0408069B1 | Brazil | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1757195
- Application
- 800061368
Titles3
- Chinese
- 用于通信网络中的相互验证的方法和软件程序产品
- English
- Method and software program product for mutual verification in communication network
- Chinese
- 用于通信网络中的相互验证 的方法和软件程序产品
Classification
- CPC, 5
- H04L63/0869
- H04L63/0428
- H04W80/00
- H04W12/068
- H04W12/122
- IPC, 6
- H04L9 06
- G06F21 34
- G06F21 44
- H04L12 28
- H04L12 56
- H04L29 06