Apparatus to secure operations in a mobile radio network.
Abstract
For persons with operating authorisation in addition to the subscriber possessing an authorisation card, a smart card is provided as evidence of authorisation. On this card, the telephone number has a notional authentication centre as a home location, which is connected to all the EDP installations of the network operation. The EDP installations are thus made able, through comparison of a response code (SRES) which is produced when a booking order is despatched from the authentication centre to a local exchange by transmitting a random number as an inquiry word and subsequent calculation with a subscriber-specific code, and a further response code (SRES) which is produced upon the inquiry of the subscriber by a random number through the local exchange and calculation in the SIM (Subscriber Identity Module) of the subscriber, to check the identity of the authorised person and provide the code to be used to set up a connection.
Term
Term ended
Projected expiry passed 28 February 2012, 14.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
6 claims: 3 independent, 3 dependent
- c-de-0001Means for securing operation processes in a mobile radio network, characterized, that using elements for securing the wireless transmission for addition to an authorization card (SIM Subscriber Identity Module) having subscriber to service authorized persons (third parties) a chip card is provided as an authorization, on the phone number as origin a fictional authentication center (AUC), which is connected to all the computer equipment of the network operator and those in a position, by comparing a response code (SRES), which when sending a log-on request from the authentication center to a local exchange by sending a random number as a search word and it the following calculation with a subscriber-specific key results, and a further response code (SRES), the results from the query of the user with a random number by the local exchange and calculation in the SIM (subscriber identity module) of the subscriber to check the identity of the authorized person and to a voice connection to be used key (KC) provides for the use by the terminal of the person authorized to carry out the preparation by their transactions.
- c-de-0002Device according Anpruch 1, characterized, that the management of all access permissions to computerized systems and the subscriber-specific key of the authorized persons is carried out in the authentication center (operating AUC).
- c-de-0003Device according Anpruch 1 or 2, characterized, that the authentication center (operating AUC) is accommodated centrally and secured.
Independent claims3
12 paragraphs, as filed
The invention relates to a device for securing operations are performed in a cellular network. It is to ensure the calls or data connections that are made by the participants over the radio path, provided in newer mobile radio systems a subscriber-specific key in two secure areas, namely the authentication center (AUC) at the home of the subscriber and the SIM of the subscriber, an intelligent module (SIM = subscriber Identity module), which can use the subscriber in any mobile device. the subscriber-specific key can not be removed, read or otherwise determined from both areas. Another feature of this system is a log-on request by the subscriber at any location (possibly abroad) stating its international subscriber number, stating the origin and carried out its forwarding to the authentication center via the signaling network.
The dispatch from the authentication center to the local exchange (MSC / VLR) is carried out in such a way at any location of the subscriber, that of a random number RAND (as challenge response) by means of user-specific key, a response code (SRES) and also from the random number and the subscriber-specific key optionally for the call-to-use key (KC) is calculated. The next steps are the query of the participant with the random number (RAND) by the local exchange and the calculation of the response code (SRES) and the key (KC) in the Subscriber Identity Module, the sending of the response code to the local exchange and delivery of the key ( KC) on its own mobile device, comparing the two resulting response codes in the exchange and in accordance approval of the log-on as well as the encryption of radio calls of the subscriber with the key (KC), which is in the exchange and the mobile device is known independently.
So Such system serves to secure interviews or data connections that are made by the participants via the radio link. However, it should also be achieved to secure the operations in a wireless network. This is for example required for sales outlets (distributors), provide the services of a mobile network operator to subscribers get the opportunity to create these participants themselves and with immediate effect in the exchanges of the operator. For this purpose it is necessary to the participant serving as electronic authorization card Subscriber Identity Module (SIM) to personalize, electronically to obtain from the network operator, if necessary by credit check approval of the new participant and to transmit its data to the accounting system of the network operator and the subscriber technically, d . h with his phone number and his or her individual rights in the competent local administration (HLR) to set up and release.
Because of the significant economic importance of this occurring over a public switched network operation appropriate safety precautions must be taken. and also to provide security within the internal operation of the network operator, in which accesses to databases by staff also subject to approval, this to improve, is the task of the invention.
This object is achieved according to the invention with a device in which using elements for securing the wireless transmission for addition to an authorization card (SIM Subscriber Identity Module) having subscriber to service authorized persons (third parties) a smart card as an authorization is provided on the phone number as origin a fictional authentication center (AUC), which is connected to all the computer equipment of the network operator and those in a position, by comparing a response code SRES, which is in itself when sending a log-on request from the authentication center a local exchange by sending a random number as a search word and the resulting calculation with a subscriber-specific key results, and a further response code SRES, which is formed during the interrogation of the subscriber with a random number by the local exchange and calculation in the SIM (subscriber Identity module) of the subscriber, to verify the identity of authorized person and to be used for a call connection key (KC) provides for the use by the terminal of the person authorized to carry out the preparation by their transactions.
Advantageous refinements and developments of the subject invention are disclosed in the dependent claims.
The invention will be explained in more detail.
The invention is based on the idea to use the funds earmarked for securing the radio transmission devices for securing operations are performed. For this, get employees, authorized dealers and other for operation authorized persons, each referred to as a third person, a smart card as an authorization, which corresponds exactly to a Subscriber Identity Module (SIM). The phone has a home a fictitious (logical) authentication center (AUC) of which is connected to all the computer equipment of the network operator and the authorization performs. In place of the local exchange (MSC / VLR) delivers the one data center or one data processing process of the network operator to which the third person trying to gain access. The logical authentication center (operating authentication center Bauc) added to the data center or the DV process in the situation, in the manner described above - by comparing the response code SRES -the identity of the third person to check and provides the key KC willing to the terminal the third person for the following transaction is used. The data center can hold for cooperating with him third parties sets of RAND (random number), SRES (response code) and KC (key) available, so that need not be asked back for each transaction during operation authentication center.
The operation authentication center (Bauc) manages all access privileges to computerized systems and the individual code KI of eligible persons (third parties). It can be housed centrally and secured while the individual computer systems are distributed in regional centers and the persons entitled to them from any location over any network, preferably also a public switched network such as the telephone network, the ISDM, the BTX put -Netz or the like. in conjunction.
The case of the accessibility of the operation authentication center via the signaling network results in that the authorization card of third person is also usable in a mobile device as a normal Subscriber Identity Module. The authentication request reaches correspondingly represents the number operating authentication center (BANC). The authorized person can lead a normal mobile phone call or reach the desired computer center via the mobile network. Here, criteria can be defined as the determined by the operating center authentication privilege of this special mobile subscriber is notified to the selected process (closed for example by membership of the subscriber to a user group).
To the electronic log-on or change of subscriber data to the authorized person (third person) has initially - as described above - to be shown, then the electronic device subscriber process is allowed. It is submitted then the Subscriber Identity Module of the respective participant. This may change over time, or - if the terminal used has two reading devices - also take place simultaneously with the proof of authorization of the authorized person. Thus it is guaranteed that the assignment to be personalized with new participants, pre-personalized Subsriber Identity Module (SIM) and the subscriber number (IMSI) contained therein to the permissions and is given free of errors person of the participant and that the case of changes in subscriber data subscriber has himself submitted his SIM for the change.
The verification of the subscriber SIM may be limited to reading the IMSI. In the presence of a signaling connection, it is also conceivable that the device process - again as a local exchange (MSC / VLR) agierend - by querying the authentication center of the participant performs a full authentication.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO9737508A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO9711548A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US6726098B2 | Cited by | United States of America | Applicant |
| US6047070A | Cited by | United States of America | Search report |
| US6964369B2 | Cited by | United States of America | Applicant |
| US7137548B2 | Cited by | United States of America | Applicant |
| AU745627B2 | Cited by | Australia | Search report |
| WO9711548A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP0743783A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0743783A2 | Cited by | European Patent Office (EPO) | Search report |
| US6170745B1 | Cited by | United States of America | Applicant |
| US6003770A | Cited by | United States of America | Search report |
| EP0602319A1 | Cited by | European Patent Office (EPO) | Search report |
| US6290127B1 | Cited by | United States of America | Applicant |
| AU708071B2 | Cited by | Australia | Search report |
| US5544322A | Cited by | United States of America | Search report |
| US6382507B2 | Cited by | United States of America | Applicant |
| CN1080071C | Cited by | China | Search report |
| WO9957689A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US6651883B2 | Cited by | United States of America | Applicant |
| WO9711548A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7708197B2 | Cited by | United States of America | Applicant |
6 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 4107005 | Germany | A | |
| 4107005 | Germany | – | |
| 4107005 | – | – | – |
| DE19914107005 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP0502446A2This record | European Patent Office (EPO) | A2 | |
| EP0502446A3 | European Patent Office (EPO) | A3 | |
| EP0502446B1 | European Patent Office (EPO) | B1 | |
| AT145511T | Austria | T | |
| DE59207527D1 | Germany | D1 | |
| ES2095339T3 | Spain | T3 |
48 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| European patent in force as of 2002-01-01IF02 | IF02 | GB | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Corresponds to:REF | REF | EP | |
| Fr: translation filedET | ET | EP | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0502446
- Publication, DOCDB
- 0502446
- Publication, EPODOC
- EP0502446
- Application
- 92103483
- Application, DOCDB
- 92103483
- Application, EPODOC
- EP19920103483
Titles3
- German
- Einrichtung zur Sicherung von Bedienungsvorgängen in einem Mobilfunknetz.
- English
- Apparatus to secure operations in a mobile radio network.
- French
- Dispositif pour sécuriser les traitements dans un réseau radio-mobile.
Classification
- CPC, 3
- H04W12/06
- H04W12/12
- H04W12/1206
- IPC, 4
- G07F7 08
- H04L9 32
- H04Q7 38
- H04W12 06
Designated states13
- Contracting states, 13
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Luxembourg
- Netherlands (Kingdom of the)
- Sweden