Method and system for authentication number protection in a mobile telephone unit
Abstract
The unit has a protection system with an encryption part which ensures an authentication number is stored in memory (54) in an encrypted form. A program (61) encrypts the authentication number while the mobile radio telephone is in service and is used to place the encrypted authentication number in memory. A second program (62) allows the authentication number to be de-encrypted when authentication has been successfully performed.

Term
Term ended
Projected expiry passed 6 January 2018, 8.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
5 claims: 4 independent, 1 dependent
- 1mobile station radio telephone comprising identification means and encryption of traffic, a system of protection for at least one authentication number, and storage means for storing said number authentication, characterized in that said system protection comprises means for encrypting at commissioning of the mobile station, said authentication number presented in clear, said identification encryption means and traffic, and for storing it in this single encrypted form in said storing means, and for decrypting in accordance with said identification encryption means and said traffic number authentication when its use is clear necessary in the mobile station.
- 2mobile station radiotelephone according to claim 1 wherein said authentication nupméro is the authentication key or A-key in English.
- 3mobile station radiotelephone according to Claim 2 wherein a second number of protected authentication is the SSD or Shared Secret Data in English.
Independent claims4
26 paragraphs, as filed
The invention relates to a mobile station radiotelephone comprising identification encryption means and traffic, a protection system for at least a number authentication, and storage means for storing said authentication number.
The invention also relates to a method for protecting an authentication number contained in a mobile station radiotéléhone of the kind mentioned above.
Such protection is important applications particularly in the field of radio mobile gender (AMPS or TACS and ETACS) and also the CDMA genre. Important issues in this area, in particular, Identification Numbers (ESN and MIN) devices that can connect with the AMPS network numbers that correspond respectively to the serial number of the device and the number identification of the latter. These numbers are the prey of pirates trying to capture a code that their belongs not, so the billing communications be imputed to any one but themselves.
To protect themselves from this kind of maneuvers dishonest discloses a protection system which is described in the preamble of the patent of the United States of America No. 5,392,356. According to this known system the or the code (s) of identification is (Are) encrypted (s) in the mobile station before they are registered in the mobile EEPROM, the codes are then decrypted then issued at the time of communication. Such trick prevents the identification codes to be extracted from EEPROM by hardware means and thus to be acquired simply.
However, identification codes such as MIN and ESN can always be acquired by interception of a communication between the mobile station and the base station, which makes that fraud still possible.
To preserve the integrity of the mobile stations and prevent their piracy was gradually brought to introduce more sophisticated authentication procedures As the piracy of mobile increased. Now, in many networks, an authentication number is assigned to each mobile station; it is the key authentication and A-key, and a second number authentication, the SSD (Shared Secret Data in English), is calculated by encryption from the A-key.
An object of the present invention is to prevent the reading by key electronic means (s) Authentication contained (s) in a radio mobile station.
Another object of the invention is to provide a mobile radio station whose illegal use is prevented.
These objects are achieved and the disadvantages of the art former is mitigated by the fact that the mobile station radiotelephone defined in the first paragraph is noteworthy in that said protection system comprises means for encrypt at the service of the mobile station, said number presented to clear authentication by said means Encryption identification and traffic, and to store it in this single encrypted form in said storage means, and for decrypting in accordance with said identification encryption means and said authentication number when its traffic clear in use is necessary in the mobile station.
Thus, a malicious person would happen to read the content of the EEPROM of a mobile well protected and isolating authentication keys such as the A-key and SSD under encoded form, would not be able to decode these key for trespassing clear in a mobile station conventional. Furthermore, the authentication keys do are used for encryption and can not be issued by radio, which completely prevents anyone other than the manufacturer or the operator and possibly the subscriber, for there have access.
Note also that the encryption and decryption authentication keys by encryption means already in the transmission system (mobile and base) simplify operations and allow to obtain the desired protection to little of charges. In this case, the CAS encryption system is imposed by the standards for ETACS networks and the CAVE system meanwhile used by the AMPS and CDMA networks.
The description which follows, with reference to the drawings attached, all given by way of example do well how the invention can be achieved.
Figure 1 shows a device according to the invention.
Figure 2 is an encryption scheme of a number authentication.
Figure 3 is a diagram of a decryption number authentication.
Figure 4 shows the update, by encryption From the A-key, the authentication number SSD.
The device shown in Figure 1 is a station mobile radios (mobile station) to be connected to a network the ETACS or AMPS type. It consists of the usual elements that kind of device, namely an antenna 5, a microphone 12, a earpiece 10, a keypad 15, a screen 17 and a set 20. This electronic electronic assembly includes a portion 40 emission and reception portion 42 that allow traffic radio using the antennne 5 and therefore the exchange of word using the earphone 10 and the microphone 12 without forget the traffic exchanges that are involved in the use of the keyboard 15. While this electronic system is governed by a control assembly 50 formed from at least one microcomputer 51 to which are attached in conventional manner, a program memory 52 of the flash memory type, RAM 53 and a writable memory 54 of the EEPROM type. It's in this memory 54 that various authentication numbers can be stored. The focus here is, in the suite herein, the number designated by A-key is a key which allows the mobile station to identify as being unique compared to other mobile stations. It is confidential and should only be known to the operator, respectively manufacturer, and possibly the subscriber user of the station mobile. To protect themselves from fraudulent practices such as those described in the aforementioned American patent No. 5,392,356 there should take steps to ensure the integrity of this number.
According to the invention, to ensure the integrity of the A-key number, the latter is introduced in the clear in the mobile station, when put into service by a person authorized, the operator preferably in the same way as he is in the base station. The program memory 52 contains a 61 program to encrypt at least the A-key and to introduce and encrypted in an A1 location in the EEPROM memory 54. The algorithm used for encryption is the CAVE algorithm or CAS depending on the type of radio network in question, algorithm already used for encryption purposes for identification or traffic, as dictated by the standards governing the operation of networks mobile radio AMP and ETACS. The CAVE algorithm is as described in Appendix A of EIA / TIA (Electronics Industry Association / Telecommunications Industry Association) Interim Standard IS-54 Revision B, and more particularly, TR45.0.A, Common Cryptographic Algorithms, Revision B, June 21, 1995.
Encrypting the A-key is as shown in Figure 2.
The A-key is encrypted by the program 61, using a manufacturer key Kc by the CAVE algorithm. The result, A-key is then stored at the location A1 to the EEPROM 54 (figure 1). The manufacturer key Kc is secret, not being contained in the EEPROM 54 but in the program memory 52 which is tamper-proof, and is not transmitted over the air.
When the A-key in clear need in the mobile to perform an authentication procedure, it is provided according to the invention, a program in memory 62 progoramme 52, which extracts the encrypted key A-key 'of the EEPROM 54, decrypts, as shown in Figure 3, again using Key manufacturer Kc and the CAVE algorithm, as shown in Figure 3, and provides in its decrypted form, A-key, the mobile station identification purposes, of a tamper evident manner.
Note that the SSD authentication number is the most often used for authentication procedures. The SSD is itself obtained by encryption from the A-key and NSE particular, so as to hand it to date by the through a random number is also used in this particular encryption, shown in Figure 4.
The base station (to the right of the figure) provides by radio a random number RANDSSD, the station mobile (left of the figure). In each station, the same following encryption operations are then performed:<ul><li>encryption by the CAVE algorithm of the association: A-key-ESN-RANDSSD, which results in the SSD authentication key;</li><li>supply by radio a random number RANDBS of the mobile station to the base station;</li><li>Then, to verify that the two numbers are calculated identical between the two stations, the encryption algorithm CAVE association: ESN-MIN-SSD-RANDBS resulting in a AUTHBS number;</li><li>AUTHBS the numbers are exchanged between mobile station and base station and compared, identity also involving the identity of the SSD numbers.</li></ul>
The number SSD thus obtained is then encrypted to through the program 62 (Figure 1) and stored in a location A2 Memory 54.
Preferably, the 61 memory program 52 program is designed to encrypt and provide the memory EEPROM 54 all the data it is to contain and symmetrically, the program is designed to decrypt 62 each these data before providing, on request, to the station mobile.
In addition, the manufacturer may of periodically modify his secret key Kc used to perform data encryption in the mobile station and in the station based.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO0011835A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO0193275A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US6330311B1 | Cited by | United States of America | – | Applicant | – |
| US6201871B1 | Cited by | United States of America | – | Search report | – |
| EP0455135A2 | Cites | European Patent Office (EPO) | A | Search report | 1,2,4 |
| EP0532227A2 | Cites | European Patent Office (EPO) | A | Search report | 1-3 |
| US5384847A | Cites | United States of America | X | Search report | 1-5 |
| US5392356A | Cites | United States of America | DX | Search report | 1-5 |
4 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 9700153 | France | A | |
| 9700153 | France | – | |
| 9700153 | – | – | – |
| FR19970000153 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| EP0853438A1This record | European Patent Office (EPO) | A1 | |
| JPH10210535A | Japan | A | |
| KR19980070367A | Republic of Korea | A | |
| US6108424A | United States of America | A |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Designation fees paidDE FR GB ITAKX | AKX | |
| Designated contracting states (corrected)RBV | RBV | |
| Request for examination filed17P | 17P | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0853438
- Publication, DOCDB
- 0853438
- Publication, EPODOC
- EP0853438
- Application
- 98200015
- Application, DOCDB
- 98200015
- Application, EPODOC
- EP19980200015
Titles3
- German
- Verfahren und System zum Schutz der Authentifikationsnummer in einem Mobiltelefon
- English
- Method and system for authentication number protection in a mobile telephone unit
- French
- Station mobile de radiotéléphone comportant un système de protection pour au moins un numéro d'authentification et procédé de protection d'un numéro d'authentification
Classification
- CPC, 4
- H04W12/04
- H04W12/06
- H04W12/0609
- H04W88/02
- IPC, 3
- H04L9 32
- H04W12 04
- H04W88 02
Designated states3
- Contracting states, 2
- Italy
- Sweden
- Extension states, 1
- Slovenia