Method, system and subscriber equipment for manipulation-proof separation of message flows
9 claims: 9 independent, 0 dependent
- 1Method of manipulation-proof separation of message flows which are transmitted in the local loop area (3) of a communication network via a medium (30) which is common to multiple subscribers, characterized in that for transmission via the common medium, first actions (22, 43) for manipulation-proof separation of message flows are taken, and are the same for all message flows, and that between at least one subscriber (4) who is connected to the communication network via the common medium and another subscriber, additional actions (111, 112, ..., 11n;42), which are agreed between these subscribers for these calls, are taken from end to end. Procédé pour la séparation protégée contre la manipulation de flux de messages, qui sont transmis dans la zone de raccordement d'abonnés (3) d'un réseau de communication au moyen d'un support (30) commun à plusieurs abonnés, caractérisé en ce que, pour la transmission au moyen du support commun, des premières mesures (22, 43) sont prises pour la séparation protégée contre la manipulation de flux de messages qui sont de même nature pour tous les flux de messages, et en ce que entre au moins un abonné (4) relié par le support commun avec le réseau de communication et un autre abonné, on prend des mesures complémentaires (111, 112, ..., 11n ;42) de bout en bout qui ont été convenues entre ces abonnés pour ces liaisons. Verfahren zum manipulationssicheren Trennen von Nachrichtenströmen, die im Teilnehmeranschlußbereich (3) eines Kommunikationsnetzes über ein mehreren Teilnehmern gemeinsames Medium (30) übertragen werden, dadurch gekennzeichnet, daß zur Übertragung über das gemeinsame Medium erste Maßnahmen (22, 43) zum manipulationssicheren Trennen von Nachrichtenströmen ergriffen werden, die für alle Nachrichtenströme gleichartig sind und daß zwischen mindestens einem über das gemeinsame Medium mit dem Kommunikationsnetz verbundenen Teilnehmer (4) und einem weiteren Teilnehmer von Ende zu Ende ergänzende Maßnahmen (111, 112, ..., 11n;42) ergriffen werden, die zwischen diesen Teilnehmern für diese Verbindungen vereinbart wurden.
- 2System for manipulation-proof separation of message flows which are transmitted in the local loop area (3) of a communication network via a medium (30) which is common to multiple subscribers, characterized in that for transmission via the common medium, first means (22, 43) for manipulation-proof separation of message flows are present, and are the same for all message flows, and that for calls between at least one subscriber (4) who is connected to the communication network via the common medium and another subscriber, additional means (111, 112, ..., 11n;42) are present on these subscribers' premises, to take actions which are agreed between these subscribers for these calls. System zum manipulationssicheren Trennen von Nachrichtenströmen, die im Teilnehmeranschlußbereich (3) eines Kommunikationsnetzes über ein mehreren Teilnehmern gemeinsames Medium (30) übertragen werden, dadurch gekenrszeichn daß zur Übertragung über das gemeinsame Medium erste Mittel (22, 43) zum manipulationssicheren Trennen von Nachrichtenströmen vorhanden sind, die für alle Nachrichtenströme gleichartig sind und daß für Verbindungen zwischen mindestens einem über das gemeinsame Medium mit dem Kommunikationsnetz verbundenen Teilnehmer (4) und einem weiteren Teilnehmer bei diesen Teilnehmern ergänzende Mittel (111, 112, ..., 11n;42) vorhanden sind, um Maßnahmen zu ergreifen, die zwischen diesen Teilnehmern für diese Verbindungen vereinbart sind. Système pour la séparation protégée contre la manipulation de flux de messages, qui sont transmis dans la zone de raccordement d'abonnés (3) d'un réseau de communication au moyen d'un support (30) commun à plusieurs abonnés, caractérisé en ce que, pour la transmission au moyen du support commun, des premiers moyens (22, 43) pour la séparation protégée contre la manipulation de flux de messages sont présents, qui sont du même type pour tous les flux de messages, et en ce que pour des liaisons entre au moins un abonné (4) relié au moyen du support commun au réseau de communication et un autre abonné, des moyens complémentaires (11, 112, ..., 11n ;42) sont présents chez ces abonnés pour prendre des mesures qui sont convenues entre ces abonnés pour ces liaisons.
- 3Equipement d'abonné (40) avec des moyens pour la séparation protégée contre la manipulation des flux de messages de cet abonné de flux de messages d'autres abonnés, si cet équipement d'abonné (40) est utilisé pour le raccordement d'un abonné (4) à un réseau de communication au moyen d'un support (30), qui sert dans la zone de raccordement d'abonnés (3) conjointement à plusieurs abonnés pour le raccordement, caractérisé en ce que des premiers moyens (22, 43) pour la séparation protégée contre la manipulation de flux de messages et des moyens complémentaires (111, 112, ... 11n ;42) sont présents, les fonctions des moyens complémentaires étant convenues entre l'abonné et un autre abonné pour des liaisons entre ces abonnés. Subscriber equipment (40) with means for manipulation-proof separation of message flows of this subscriber from message flows of other subscribers, if this subscriber equipment (40) is used to connect a subscriber (4) to a communication network via a medium (30) which is used in common to connect multiple subscribers in the local loop area (3), characterized in that first means (22, 43) for manipulation-proof separation of message flows and additional means (111, 112, ..., 11n;42) are present, the functions of the additional means being agreed between the subscriber and another subscriber for calls between these subscribers. Teilnehmereinrichtung (40) mit Mitteln zum manipulationssicheren Trennen der Nachrichtenströme dieses Teilnehmers von Nachrichtenströmen anderer Teilnehmer, wenn diese Teilnehmereinrichtung (40) verwendet wird zum Anschluß eines Teilnehmers (4) an ein Kommunikationsnetz, über ein Medium (30), das im Teilnehmeranschlußbereich (3) mehreren Teilnehmern gemeinsam zum Anschluß dient, dadurch gekennzeichnet, daß erste Mittel (22, 43) zum manipulationssicheren Trennen von Nachrichtenströmen und ergänzende Mittel (111, 112, ..., 11n;42), vorhanden sind wobei die Funktionen der ergänzenden Mittel zwischen dem Teilnehmer und einem weiteren Teilnehmer für Verbindungen zwischen diesen Teilnehmern vereinbart sind.
- 4Method according to Claim 1, characterized in that the first and additional actions are those for authentication. Procédé selon la revendication 1, caractérisé en ce que les premières mesures et les mesures complémentaires sont des mesures pour l'authentification. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die ersten und die ergänzenden Maßnahmen solche zur Authentisierung sind.
- 5Method according to Claim 1, characterized in that the first and additional actions are those for encryption and decryption. Procédé selon la revendication 1, caractérisé en ce que les premières mesures et les mesures complémentaires sont des mesures pour le codage et le décodage. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die ersten und die ergänzenden Maßnahmen solche zur Verschlüsselung und Entschlüsselung sind.
- 6Equipement d'abonné selon la revendication 3, caractérisé en ce que les premiers moyens (43) et les moyens (42) complémentaires sont des moyens pour le codage et le décodage. Subscriber equipment according to Claim 3, characterized in that the first means (43) and additional means (42) are those for encryption and decryption. Teilnehmereinrichtung nach Anspruch 3, dadurch gekennzeichnet, daß die ersten Mittel (43) und die ergänzenden Mittel (42) Mittel solche zur Verschlüsselung und Entschlüsselung sind.
- 7Method according to Claim 5, characterized in that the first and additional actions are synchronised with each other. Procédé selon la revendication 5, caractérisé en ce que les premiers moyens (43) et les moyens (42) complémentaires sont synchronisés entre eux. Verfahren nach Anspruch 5, dadurch gekennzeichnet, daß die ersten und die ergänzenden Maßnahmen aufeinander synchronisiert sind.
- 8Equipement d'abonné selon la revendication 6, caractérisé en ce que les premiers moyens (43) et les moyens (42) complémentaires sont conçus de telle sorte que leurs fonctions sont exécutées ensemble. Subscriber equipment according to Claim 6, characterized in that the first means (43) and additional means (42) are in such a form that their functions are carried out in common. Teilnehmereinrichtung nach Anspruch 6, dadurch gekennzeichnet, daß die ersten Mittel (43) und die ergänzenden Mittel (42)so ausgebildet sind, daß ihre Funktionen gemeinsam ausgeführt werden.
- 9Equipement d'abonné selon la revendication 3 ou 8, caractérisé en ce que les moyens (42) complémentaires peuvent être déconnectés ou commutés. Subscriber equipment according to Claim 3 or 8, characterized in that the additional means (42) can be switched off or over. Teilnehmereinrichtung nach Anspruch 3 oder 8, dadurch gekennzeichnet, daß die ergänzenden Mittel (42) ab- oder umschaltbar sind.
Independent claims9
58 paragraphs, as filed
The invention relates to a method, system and a Participants means for manipulation-proof separation of Message flows, according to the preamble of claims 1, or 2, and 3 respectively.
The transition from conventional telephone network for future Telecommunications network has the most diverse changes to Episode. One of these changes involves the power structure in The subscriber area, another the addition of other Services and the associated separation of network operators and Service provider.
The US 5,311,593 B deals with the question of any Participants make only those news streams available, addressed to him, even if other participants certain message streams not be kept away from him can. It solves this problem by encrypting all News flows that are not addressed to this subscriber are.
A variety of reasons is in the future Subscriber area often use a network structure find, when several participants a common medium divide. Examples include both fiber or Coax broadband connections and the connection via radio. In order to the message streams of many participants at least physically also to the other participants available. About the purely physical separation of message flows, there are but further demands. Foremost among these is the to mention privacy, what essentially encryptions be used. Quite important is to prevent that someone at the expense of another, especially at its expense, active can be. For this purpose, various authentication concepts responsible. Even more demands, such as the right Assigning the fees after verified authorization include, here.
The level of security that is to be considered in each individual case to be correct, varies both from participant to participant as of Service to service. Therefore, at present the question is very timely, whether these Security from the network operator or by the service providers should be ensured and where in the network the relevant measures should be taken.
According to the invention this is achieved by a method according to the Teaching of claim 1, a system according to the teaching of claim 2 and a user equipment according to the teaching of claim. 3 Here is the network operator a certain basic security ensuring that service-specific supplemented by the service provider becomes.
Further embodiments of the invention are the claims to remove.
This solution is very flexible. It needs neither unilaterally a particular service, such as "video on demand" or "telephony" to be optimized, is an extreme "Worst-case" dimensioning required. Also there is a organizational unbundling for example, when key management and the authentication.
For example only some aspects are first called, the be important for the dimensioning of the individual case can:
When telephony generally sufficient simple Verschlüsselungsund Authentication measures at the network operator. A long-distance call is relatively short, as a rule, so that even a simple Key would be deciphered only with great effort, which has not in view of the generally low security level worth. Even accidental misallocation or Nichtzuordenbarkeit the fee could at a low charge level be accepted if at least the repetition practice is excluded. For higher fees could be a Nachauthentisierung at a higher level of security in the course of be provided conversation, as, for example, already for Credit calls is known. If the service "Telephony" is not made by the network operator, may at least the Nachauthentisierung by the service provider take place. at longer conversations can the network operator during the call the key to be changed. Discussions with higher Classification level can be offered as a separate service, in which case the purpose competent service provider in addition to the Keys used by the network operator yet another Key (and also has its own authentication) used. Nice can with two simple but independent keys thereby a high safety can be achieved.
There will also be a service provider that certain services, such as Leaves the mail order catalog as a bias for the fact Offer intended sale business for free and for everyone. Out therefore view this service provider requires it no Safety. The customer may, however, be interested in to remain anonymous. It would be otherwise, for example, Possibility of automated interception and analysis Address lists for targeted advertising or targeted donations to create.
Now go a participant from the leaves in the mail-order catalog for Order, as is the issue of authentication in the foreground.
When subscription television (pay-TV, perhaps on even with video Demand) is especially the information content by a key to encrypt, the longer term is difficult to decipher is.
The examples mentioned that expanded or combined arbitrarily can show that at least the participants a little greater effort may be required.
At least for those participating institutions, whether the Terminal itself or as a network termination, which can be used for multiple services, has also an adjustment these services be possible. There must be first means at the level of the network operator the functions meet, which are identical for all message flows and with where basic security is ensured. Variations that for example, by the respective claimed Transmission capacity, shall be adopted here not considered. About this first means also have complementary Agent be present, the various services on the level fulfill functions. used are different services or The same service through various service providers, so must the Functions of supplementary funds be disengaged or switched.
The functions that run on the service level, must, since they are effective from end to end, between the participants concerned be agreed. This is usually by agreement with the each provider take place, often even one of will be two participants. A change of this agreement (eg Key Exchange) can be part of these functions.
In order to keep the effort involved in user equipment smaller, , a synchronization between the means and measures of Network operator and that of a service provider's done. In the Subscriber device, it is then possible, for example, a combined form key and with only one means by this combined key both at the network level as well as on to encrypt and decrypt services level. The same applies for authentication.
In the following, the invention will by way of example further elucidated with reference to the accompanying drawing.<dl tsize="7"><dt>figure 1</dt><dd>shows an embodiment of an inventive Systems with a subscriber device according to the invention for performing a method according to the invention for manipulation-proof separation of message flows.</dd><dt>figure 2</dt><dd>shows a first embodiment of a scrambler for ATM message streams as a means for message streams inventively tamperproof to separate.</dd><dt>figure 3</dt><dd>shows a second embodiment of a scrambler for ATM message streams as a means for message streams inventively tamperproof to separate.</dd><dt>figure 4</dt><dd>shows an embodiment of a descrambler for ATM message streams as a means for message streams inventively tamperproof to separate.</dd></dl>
In Figure 1, four areas are differentiated, a Service providers range 1, a network area 2, a Subscriber area 3 and a user area. 4
In the service provider area 1 are the means of three located service providers, others are by points indicated.
The facilities of each service provider are here in two divided parts, namely into a unit referred to herein as Service provider unit 101, 102, ..., 10n will be referred to and another unit here as service provider side Tamper unit 111, 112, ..., 11n are referred should. Each service provider unit via the assigned Tamper unit connected to the network area. 2
In network area 2 is here a representative Switching device 21 shown. This is more symbolic vestehen. Service providers that here also represent other participants are, do not have the same Switching center to be connected as the given here Subscriber area 3. The service provider must not all connected to the same switch. Also is it is not necessary that the service provider via a Exchange the same network operator are connected, the the consideration here subscriber area 3 runs.
The switching device 21 is here with a network-side Tamper unit 22 to an exchange 20 combined.
The tamper resistant unit 22 is spatially and organizationally located in the central office 20, belongs but actually the subscriber area of 3, which is still here through a broadband distribution network 30 with tree and subscriber-end network termination unit tamper illustrated 43rd For subscriber area 3 are still other, unspecified considered here subscriber devices. These can be connected in the same manner, they can via distribution systems having different structure or via Individual lines be connected.
In the subscriber area 4 a subscriber terminal 41 and a subscriber-side service termination tamper unit 42 shown. They are together with the Subscriber loop 3 belonging to the subscriber side Network termination tamper unit 43 to a Subscriber device 40 combined.
The subscriber-end network termination unit tamper 43 is, together with several similar units in other Participants, the counterpart to the network side Tamper unit 22. The network side Tamper unit 22 must therefore, preferably in Time division, the corresponding functions for all these meet participants. but it is also conceivable that, for example, the Authentication for all participants in the time division by one and the same configuration is achieved while decrypting and Encrypt by several parallel working arrangements is achieved individual subscriber.
The same applies to the subscriber side Network termination units tamper 42 and the service provider side tamper units 111, 112, ..., 11n. But here is added that the Tamper functions to be performed by network provider to network provider may be different. It is therefore sufficient under Circumstances subscriber side not a record, in particular a code key exchange. It must sometimes between various devices are switched, for example, by changing a smart card. For individual services, about the telephony, these functions can also be dispensed with be and the means 42 therefore be switched off. on the other hand can service provider side for individual services may be greatly simplified. For example, a provider of waive subscription television on authentication and for all encrypt all subscribers with the same key.
By synchronizing one of the service provider side Tamper units 111, 112, ...., 11n with the network-based tamper resistant unit 22, a Summary of the subscriber side Network termination tamper unit 43 with the subscriber-service termination tamper unit 42 be achieved. But the overall network more Subscriber access areas are present, then the Synchronization of all network-side tamper units required.
should not be ruled by the present invention, that among individual service providers with pure distribution services Bypassing the network range 2 directly into the subscriber loop 3 is fed. In such cases, the subscriber side must then Network termination tamper unit are 43 bridges.
Finally, even more examples of encryptors and Descrambler of ATM data streams described:
An ATM data stream is usually cells (data packets) contain different message streams belong. Should the entire data stream, for example in the course of Microwave link encrypted, transmitted, this may carried out by conventional methods. On the other hand, for example in a distribution, the entire data stream of a plurality of Participants accessible, each of which in the relevant him can access news stream, so must each of these Message streams for itself with its own key encrypted. The respective key can then are determined from the transmitted in unencrypted packet header. In such data stream can also message streams be embedded, which are addressed to all, for example, broadcasting or television, or any other reasons Confidentiality require. These can remain unencrypted.
For the encryption of the packet headers following Messages parts themselves can for continuous or in self-contained messages known methods are used.
One known way of encryption is the Block coding, in which the data to be encrypted into blocks divided and each block as a whole by means of a Mapping rule is mapped to another block. A particularly simple division results when each one is treated packet header following message part as such block and if the mapping rule is designed so that a block before and after the figure has the same length.
In the block coding, the security against unauthorized depends Decrypting the length and the number of encrypted blocks transferred from. In the present case, the length of the Blocks specified. One of the currently examined applications is the subscription television, where the length of the transmission is equal to the validity of the subscription and the number of transferred blocks is arbitrarily large. Moreover, precisely here the Incentive for unauthorized decryption very high. A Remedy will be here the frequent changes of key, ie the mapping rule. As in a secure manner can take place, is not the subject of the present invention.
Another possibility consists in the application of longer Key. but for this purpose has not more then the Block coding, but the stream encoding to. Here, a continuous data stream such treated by an algorithm as to constitute a new data stream, in the successive bits of a data stream and consecutive bits of other data stream match. On simple example is to be encrypted in both the Data stream such as to be decrypted by a Exclusive-OR function with a serving as a key bit sequence to connect. A "1" of the key does not impact on the corresponding inverted bit of the data stream unchanged, a "0" on the other hand this. Both the two-time consecutive inverting as the two-time unchanged disclosure arises as a result, original unencrypted bit sequence. The key can arbitrarily be long and thus any safe. The handling is But this difficult. A not too long sometimes changed hands, keys will also be located here.
In this type of encryption in which one beyond the borders encrypts a packet header following message portion of time or is decrypted, the process of encrypting and must Decrypting be interrupted at the end of a message portion, until the beginning of the next corresponding to the same connection message part present.
Here there is also the problem, the operations of encrypting synchronize and decrypting each other, especially to check the synchronization in the course of transmission. It are applications where in the packet header, the packets of a connection are numbered. This numbering may under certain circumstances to with synchronization used to encrypt and decrypt will.
If no such numbering available or such for purposes the synchronization is not suitable, as will the encrypted data stream suitable sync words inserted.
serving the synchronization of the decryption Synchronization words have been detected prior to the decryption may be because they are a prerequisite for the decryption. They may therefore not be with encrypted. also ongoing Numbers intended the numbering of the packages, may be excluded from the encryption if the course the transmission is to be accessed. same for for all other parts of the message, which in any way serve to secure the transfer. They are ultimately assigned to the packet header.
The encryptor according to Figure 2 comprises an input line 100, a Output line 200, a first and a second Encryption part 300 or 400 and a synchronization part 500 on.
The two encryption parts are equal to each other built up. Each encryption part for encrypting a News stream provided. The number of just two Encryption parts is therefore very symbolic to see. In typically will be multiple encryption parts available. But also scrambler with only one encryption part can be useful.
Each encryption part includes a filter 310 or 410, first switch 320 or 420, a scrambler 330 or 430, a Detour line 340 or 440, a second switch 350 or 450, an AND gate 360 and 460 and a delay element 370 or 470 on.
The incoming on input line 100 the data stream is Filters 310 and 410 and the synchronization part 500, respectively. Each filter is assigned the identifier of a message stream. It is referred to herein as VPI / VCI and denotes the virtual path (Virtual Path Identifier) and the virtual channel (Virtual Channel Identifier) that this message stream assigned. Each filter allows only the packets of the associated pass stream of messages and reports this same time the associated AND gate.
The synchronization part 500 derives from the incoming data stream a mask from which the those parts of the data stream, may be encrypted, masked over the other. These Mask all encryption parts over their AND gate offered. Decides if something is encrypted depends depends on whether the corresponding filter at all a message can happen.
The output of the AND gate 360 switches the first switch 320, activates the scrambler 330 and switches, on the Delay element 370, the second switch 350. The scrambler 330 a cycle clock, and a key key is further fed. The to encrypt parts of the message stream are on the Switch 320, the scrambler 330 and the switch 350 of the Output line 200 supplied. The not to be encrypted parts by means of the two switches 320 and 350 and the Bypass line 340 bypasses the scrambler.
The second encryption part 400 operates the same way as any any further. The respective identifier VPI / VCI and the respective Key key can be set in the course of a connection setup. The key key can be exchanged during the connection. Setting identifier and key and any key-exchange place as the setting and changing other parameters of a Connection. This is not the subject of the present invention. For certain cases could also immutable and fixed set parameters are used.
The use of a scrambler is done only by way of example. Here, each device can be used, the appropriate one Encryption mechanism implemented. The delay of the Delay element 370 has, as well as the duration of the Detour line 340, the processing time can be adjusted in the scrambler.
If the key used and the non-package beginnings are synchronous with each other, still must appropriately a additional synchronization in scrambler done. To what extent the into acts synchronization part while in the scrambler, depends on the encryption from being used. This is so far not specific to the invention.
Are in the data stream on the input line 100 further containing data packets, such control packets or empty packets, so must these means of a further filter with the corresponding Delay are switched through to the output line 200th
The encryptor according to Figure 3 is constructed similarly to the Figure 2. Between the input line 100 and the output line 200 is here an encryption part 600 and the Synchronization part 500th
The encryption part 600 has in this example except a Filter 610, a first switch 620, a scrambler 630, a bypass line 640, a second switch 650 and a Delay element 670 still another delay element 680 and a key list 690.
The construction and the mode of action is largely the same as in However, the previous example, here is an encryption part in Time division for encrypting multiple message streams used.
The filter 610 filters here the packet headers as far from the Data stream, as required in each case for determining the is key required. The packet headers are also in normal data stream further carried. The from the packet headers filtered information are used to address the Key list 690, respectively corresponding to the correct key to the Scrambler 630 provides. The registration of the key into the Keylist done by way of setting a Connection parameter according to known methods. For control and Empty packets as well as not to be encrypted message streams may be entered a key which in no scrambler Change the message causes.
The further delay element 680 is similar with respect to the example according to Figure 2, the delay of the filter and of the AND gate off.
The decryptor 700 of Figure 4 has an input line 720, a filter 710, a descrambler 730, an output line 740 and a synchronization part 500 on.
The filter 710 displays a single message stream from the Data stream on the input line 720 and feeds it to the Descrambler 730, the key with the same key, the effect of associated scrambler cancels again.
In the example shown, it was assumed that the output on Descrambler just pure message stream is still needed. The filter 710 can therefore in this case only the message parts the selected packets. A redirection of the packet headers to the Descrambler is therefore not necessary. The synchronization part 500 serves only the synchronization and not the masking. Conversion of the hidden message parts in a continuous data stream will not be further described.
For other measures for manipulation-proof separation of Data streams, in particular with respect to the authenticating are, to no special rules when ATM as a bearer is used.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0629091A | Cites | European Patent Office (EPO) |
| US5311593A | Cites | United States of America |
| WO9501019A | Cites | World Intellectual Property Organization (WIPO) |
11 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19515681 | Germany | A | |
| 19515681 | Germany | A | |
| 19515681 | Germany | – | |
| 19515681 | – | – | – |
| DE1995115681 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| CA2175152A1 | Canada | A1 | |
| EP0740439A2 | European Patent Office (EPO) | A2 | |
| DE19515681A1 | Germany | A1 | |
| CN1144429A | China | A | |
| EP0740439A3 | European Patent Office (EPO) | A3 | |
| US5822433A | United States of America | A | |
| CN1143480C | China | C | |
| EP0740439B1This record | European Patent Office (EPO) | B1 | |
| AT271290T | Austria | T | |
| ATE271290T1 | Austria | T1 | |
| DE59611034D1 | Germany | D1 |
43 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Change of name or company nameCD | CD | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Corresponds to:REF | REF | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Title (correction)METHOD, SYSTEM AND SUBSCRIBER EQUIPMENT FOR MANIPULATION-PROOF SEPARATION OF MESSAGE FLOWSRTI1 | RTI1 | EP | |
| Title (correction)METHOD, SYSTEM AND SUBSCRIBER EQUIPMENT FOR MANIPULATION-PROOF SEPARATION OF MESSAGES FLOWSRTI1 | RTI1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0740439
- Publication, DOCDB
- 0740439
- Publication, EPODOC
- EP0740439
- Application
- 96105014
- Application, DOCDB
- 96105014
- Application, EPODOC
- EP19960105014
Titles3
- German
- Verfahren, System und Teilnehmereinrichtung zum manipulationssicheren Trennen von Nachrichtenströmen
- English
- Method, system and subscriber equipment for manipulation-proof separation of message flows
- French
- Méthode, système et équipement d'abonné pour séparation protégée contre la manipulation des circulations de messages
Classification
- CPC, 8
- H04L49/3081
- H04L12/22
- H04L63/0428
- H04L2012/561
- H04L2012/5615
- H04L2012/5616
- H04L2012/5673
- H04Q11/0478
- IPC, 3
- H04L12 22
- H04L49 111
- H04Q11 04
Designated states10
- Contracting states, 10
- Austria
- Belgium
- Switzerland
- Germany
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Sweden
