Management of authentication keys in a mobile communication system
Abstract
A method and mobile communication system for managing authentication keys, the system having at least one authentication center, base stations and mobile stations to which subscriber identity modules may be coupled and which communicate with the base stations. The authentication keys are managed by: generating authentication keys and identifiers corresponding thereto, each of which identifiers is independent of a mobile subscriber identity, which allow authentication keys corresponding to the identifiers to be found in the authentication center, storing the authentication keys in the authentication center so that the authentication keys may be found in the authentication center on the basis of the identifiers, and storing the authentication keys and the identifiers corresponding to the authentication keys to the subscriber identity modules.

Term
Term ended
Expired 23 January 2017, 9.7 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
13 claims: 2 independent, 11 dependent
- 1A method for managing authentication keys in a mobile communication system comprising at least one authentication centre (102, AUC), base stations (BS) and mobile stations (301, 500) to which subscriber identity modules (101, 509, SIM) are arranged to be coupled and which communicate with said base stations, characterized by the method comprising:generating (601) authentication keys and corresponding identifiers (202), which identifiers are independent of any mobile subscriber identity, and which identifiers serve as pointers to their corresponding authentication keys in said authentication centre (102, AUC), storing said authentication keys with an index to their corresponding identifiers in said authentication centre (102, AUC), whereby said authentication keys are arranged to be retrieved from said authentication centre on the basis of said identifiers (202), and storing at least said authentication keys in said subscriber identity modules (101, 509, SIM) and said identifiers corresponding to the authentication keys in said subscriber identity modules (SIM) or in a subscriber database (DB) accessible upon authentication.
- 13A mobile communication system comprising at least one authentication centre (102, AUC) containing authentication keys, base stations (BS) and mobile stations (301, 500) which communicate with said base stations and to which subscriber identity modules (101, 509, SIM) are arranged to be coupled, characterized in that the mobile communication system comprises generating means (601) for generating identifiers (202) which correspond to the authentication keys required in the authentication, which identifiers are independent of any mobile subscriber identity and on the basis of which identifiers (202) said authentication keys are arranged to be retrieved from said authentication centre (102, AUC) when authentication is being carried out.
Independent claims2
63 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
0001The invention relates to a method for managing authentication keys in a mobile communication system comprising at least one authentication centre, base stations and mobile stations to which subscriber identity modules may be coupled and which communicate with said base stations.
0002The invention is intended to be applied in mobile communication systems in which subscribers may be identified by means of a subscriber identity module which is either in the mobile station or may be coupled to it. An example of such a mobile communication system is represented by the GSM system (Global System for Mobiles). Another example of such a mobile communication system is the TETRA radio telephone system (TETRA = Trans European Trunked Radio). The TETRA radio telephone system is an example of the PMR (= Private Mobile Radio) radio telephone system.
BACKGROUND OF THE INVENTION
0003The network checks a subscriber's identity by carrying out an Authentication Procedure to be sure that the subscriber identity given by the mobile station is correct. By checking the subscriber identity, the network makes it sure that only such subscribers who have the right to use the network services are able to use them. At the same time it is ascertained that an unauthorized user will not cause any extra costs to authorized subscribers or be able to impersonate another subscriber.
0004In the following, the method of checking a subscriber's identity will be described in more detail by means of a GSM related example. Similar principles are also applicable to other systems of the GSM type and to the Tetra system. The mobile communication system always checks a subscriber's identity in conjunction with registration, call set-up stage and when activating or deactivating certain supplementary services. The subscriber identity is also checked at Location Area (LA) updating when the subscriber's roaming number, i.e. MSRN (Mobile Station Roaming Number), changes. In other location area (LA) updating instances, the network operator may decide whether to check a subscriber's identity or not.
0005A subscriber's identity is checked according to the following steps:
0006Having obtained information on the above situation, which initiates checking of the subscriber's identity, the mobile communication system, for example its Authentication Centre (AUC), transmits a random number RAND to the mobile station, the RAND being generated in the system. Having received the RAND, the mobile station computes a value for an acknowledgment parameter SRES by a specific algorithm, the received RAND, and an Authentication Key K previously stored in the mobile station. Hence, the key K is stored at least in the authentication centre and the mobile station so that they are both able to compute the same reference numbers. The mobile station sends the acknowledgment parameter SRES to the mobile communication network, in particular to its authentication centre, which checks the parameter SRES value, computed in the mobile station, i.e. compares it to the value it has computed, and as a result of this comparison deducts whether the subscriber who transmitted the acknowledgment parameter, is an authorized subscriber.
0007The mobile stations used in mobile communication systems have a subscriber identity and an authentication key stored in a subscriber identity module, which may be attached to the mobile station detachably or integrated therein. The subscriber identity modules which are coupled detachably to the mobile station contain the identifiers of the subscribers, and, when necessary, they may be connected to a terminal equipment to form a mobile station. Such subscriber identity modules and mobile stations to which the subscriber identity module is integrated are usually subscriber-specific and they are identified by a subscriber's secure identifier (IMSI = International Mobile Subscriber identity or ITSI = Individual Tetra Subscriber Identity). Detachable subscriber identity modules include e.g. SIM cards (SIM = Subscriber Identity Module).
0008The subscriber identity module described above, such as a SIM card, is subscriber specific, which means that subscriber equipments are not confined to a specific subscriber. The subscriber identity module, such as a SIM card, is a smart card which is placed in the mobile station and which contains information, e.g. an authentication key K, needed for identifying a subscriber and for encrypting radio traffic. In this application a subscriber identity module, such as a SIM card, refers to a functional card that can be removed from a mobile station and by means of which a subscriber is able to use a card controlled mobile station.
0009If a subscriber identity module e.g. a SIM card is employed, the user need not have a mobile station of his own, but a subscriber identity module e.g. a SIM card issued to him by the operator of the mobile communication system is all he needs. Such a subscriber identity module is, in a way, a phone card by means of which the subscriber can make (and receive) calls from any mobile station of the system. The functions of the SIM card include on the one hand providing the mobile station with data identifying the user in a well protected manner and on the other hand providing services to the mobile station. Such services include e.g. maintaining (inputting, changing) a Personal Identification Number (PIN), maintaining the data protection key i.e. the authentication key K, and unblocking by e.g. a PUK code, Personal Unblocking Key, a SIM card blocked by too many attempts of inputting a wrong PIN.
0010To incorporate a SIM card in hand-held phones, a so-called plug-in-SIM has been introduced as an alternative way of implementing a subscriber identity module. A plug-in-SIM is approximately a coin-sized part containing the electronics of a credit card sized SIM card, and it is placed in a phone so that the user is not able to replace it easily. The phone may also have an incorporated plug-in-SIM and, in addition, a card reader. If the card reader contains a card, the phone is identified on the basis of the external card, otherwise on the basis of the incorporated plug-in-SIM. Unless the context gives reason to some other interpretation, the term subscriber identity module, such as a SIM card, here refers to the plug-in-SIM, the credit card sized smart card SIM, and the subscriber identity module which is incorporated in the mobile station and which contains the subscriber identity and the authentication key K. In addition to mobile communication systems according to the GSM mobile communication system, the method of the invention is also intended for use in PMR (Private or Professional Mobile Radio) networks, i.e. trunked networks which are typically company networks or private mobile radio networks used by authorities, in which all the channels are used by one or more companies or organizations. The networks used by the authorities have even stricter security demands than the normal GSM network.
0011In the following, the management of the authentication key K is described in normal operation according to the GSM system. When a subscriber acquires a subscriber identity module, for example a SIM card (SIM = Subscriber Identity Module), the subscriber's IMSI, authentication key K and encryption algorithms are stored in the SIM card. The IMSI and the authentication key K are additionally stored in the authentication centre AUC of the subscriber's home PLMN (Public Land Mobile Network). Each PLMN comprises one or more authentication centres.
0012In the GSM system, two key managing methods are defined. When the one which is protected better is used, there is no need to transfer the key from one place to another. When the less well protected method is employed, the key is transferred within the network, which results in that the method is allowed to be used only when it is not necessary to transfer encrypted information between PLMNs. At other times, the network operator may decide which one of the methods to employ.
0013In the following, the safer one of these methods is described, i.e. the one in which the subscriber identity is confirmed without transferring the authentication key K. In this method, a suitable network element, e.g. a Base Station (BS) or a Mobile Switching Centre (MSC) per each mobile station may request secret subscriber-specific information from the AUC in the home PLMN of the mobile station. The authentication centre is either a separate unit or a part of a HLR (Home Location Register). The secret information in this case includes a table of RAND/SRES pairs, which have been obtained by using an algorithm with known values of the parameters RAND and the authentication keys K. The pairs are normally stored in a visitor location register VLR.
0014Subscriber identification in the Tetra system is described in "prETS 300 392-7, September 1995, Radio Equipment and Systems (RES); Trans-European Trunked Radio (TETRA); Voice plus Data (V+D); Part 7: Security, ETSI, pp. 8-10, and pp. 28-32". in Tetra systems, the authentication key is stored in the mobile communication network in a safe database of a subscriber's home network. In the terminal equipment, in turn, the authentication key may be generated in three different ways, which are described in the aforementioned document. One of the methods for generating the authentication key in the terminal equipment is to use in the generation a User Authentication Key (UAK) stored in the subscriber equipment.
0015The higher the level of security to be achieved in the mobile communication system/network, the more important the secure carrying out of the authentication of mobile subscribers. This matter is also influenced by other solutions of the network: if, for example, the network-intemal subscriber number IMSI and the subscriber number MSISDN (Mobile Subscriber Intemational ISDN number) employed by the users are separate, as is the GSM system, flexible use is possible so that the actual subscriber number MSISDN and subscriber data corresponding thereto can be defined afterwards for the pair constituted by the allocated IMSI and the authentication key K. This means that it is possible to store in advance the same subscriber identifiers IMSI and the same authentication keys K in the subscriber identity module and the authentication centre of the mobile communication system without having to transfer them on a radio path, which is liable to jamming and unauthorized listening.
0016Naturally, it is also possible to define subscriber numbers, such as MSISDN or ITSI numbers, for the subscriber identity modules, e.g. SIM cards, in conjunction with programming the keys. In such a case, distributors would be given cards which have subscriber numbers entered in them, whereas the other subscriber data would only be fed in the system when a new subscriber is defined. A problem here is that subscribers would not have any chance to choose or form a suitable subscriber number which the user would find easy to remember or which would identify that user in some other way, for example by name. Further, this solution does not allow the different levels and fleets of a public authority organization to be described in a systematic manner by means of subscriber numbers of the members of these organizations as it is not possible to know in advance how many new members there will be in the organization and what hierarchical identifiers to give afterwards to each member of the organization.
0017A way to solve the problems set forth would be to centralize the generation, subscriber definition and the system authentication, or key, database (AUC) of subscriber identity modules e.g. SIM cards to one place. Such centralization of all the key and subscriber management in one location is not, however, a sensible solution from the users' point of view. It must be possible to define new subscribers and to give out SIM cards in several places, for example in networks used by authorities at police stations and alarm receiving stations and in commercial networks at distributor agencies.
0018Therefore, the above type of operation would be problematic since in normal mobile communication systems a number of different organizations, e.g. operators, retail dealers of mobile stations as well as service providers wish to provide their clients promptly with subscriber identity modules incorporated in or connected detachably to the mobile station, and with subscriber numbers suitable for the subscribers.
0019A method in which subscriber numbers have been pre-stored in SIM cards is then not useful due to its inflexibility. Consequently, a number could not be issued to a police patrol, for example, in conjunction with the defining, but a number pre-stored on a SIM card somewhere in the distribution chain would have to be chosen.
0020This feature is particularly manifest in networks used by authorities, because e.g. the TETRA standard does not allow a separate MSISDN number used by subscribers (MSISDN = mobile subscriber international ISDN number) and an IMSI (international mobile subscriber identity) number used internally to the network.
0021In addition, in e.g. networks used by authorities, a network may have several groups of authorities as users, such as the police, fire brigade, customs, etc., each group desiring to distribute and define separate subscriber identity modules for their respective users, the subscriber identifiers in these modules being hierarchically organizable, for example fleet by fleet, even after the authentication keys have been stored in them.
0022The authentication keys should not be readily readable by people at any stage, and they should be stored only in connection with the subscriber data of the system and on the SIM card, and they should not be transferred in the network. This means that the keys will have to be generated in a centralized manner in one location both to the system and to the subscriber identity module, such as a SIM card.
0023Document D1: US 5 303 285 discloses a mechanism for providing authentication and ciphering keys in the wireless communication system, wherein an intelligent network is involved. An access method is developed, which offers increased protection against fraudulent misuse and also enables the authorisation or rejection of access based on the called number. In D1, subscription-dependent identification words are used to identify the authentication keys.
0024Document D2: EP 506 637 discloses a system for validation and verification of base stations and mobile stations within a mobile communication system. The authentication algorithm uses a fixed key and a changeable key as inputs and generates key-dependent responses. The responses generated by a particular mobile station are compared to responses generated by the network and the presence of fraudulent users may be detected.
BRIEF DESCRIPTION OF THE INVENTION
0025It is an object of the invention to alleviate the problems of the prior art solutions.
0026The aim is to provide a method and a system by means of which authentication in mobile communication systems can be arranged as flexibly as possible but nevertheless securely. A further object is to be able, when need be to define, for the subscribers, identifiers that are independent of any previous definitions so that each subscriber may, when need be, choose an available subscriber identity without restrictions.
0027The new method for managing authentication keys in a mobile communication system is obtained by a method according to the invention, which is characterized by the steps of generating authentication keys and corresponding identifiers, which identifiers are independent of any mobile subscriber identity and which identifiers serve as pointers to their corresponding authentication keys in said authentication centre, storing said authentication keys with an index to their corresponding identifiers in said authentication centre, whereby said authentication keys are arranged to be retrieved from said authentication centre on the basis of said identifiers, and storing at least said authentication keys in said subscriber identity modules and said identifiers corresponding to the authentication keys in said subscriber identity modules (SIM) or in a subscriber database (DB)_accessible upon authentication.
0028As an embodiment of the invention a method for managing authentication keys in a mobile communication system is provided, wherein the mobile stations are provided with identifiers and the mobile communication system comprises at least one subscriber database which stores each subscriber's subscriber data.
0029The method according to the embodiment is characterized by further comprising: after generating authentication keys and corresponding identifiers, storing in each subscriber identity module an authentication key to which a specific identifier corresponds and, after storing said authentication keys in the authentication centre storing said identifier in said at least one subscriber database in association with the subscriber data of said mobile station.
0030As an embodiment of the invention a method for managing authentication keys in a mobile communication system is provided, wherein the mobile communication system further comprises at least one subscriber database for storing subscriber data of a mobile station.
0031The method according to the embodiment is characterized by further comprising the following steps: performing said generation of authentication keys required in the authentication and identifiers corresponding to the authentication keys in a centralized manner in one location of the mobile communication system, storing said authentication keys with an index to their corresponding identifiers in said authentication center, whereby said authentication keys are arranged to be retrieved from said authentication center on the basis of said identifiers, storing the authentication key in a subscriber identity module, storing the mobile subscriber identity in said subscriber identity module following the generating and storing of said authentication keys and said identifiers.
0032The invention further relates to a mobile communication system comprising at least one authentication centre containing authentication keys, base stations, and mobile stations to which subscriber identity modules are arranged to be coupled and which communicate with said base stations.
0033The mobile communication system of the invention is characterized in that it comprises generating means for generating the identifiers which correspond to the authentication keys required in the authentication, which identifiers are independent of any mobile subscriber identity and on the basis of which identifiers said authentication keys are arranged to be found in said authentication centre when authentication is being carried out.
0034The invention is based on the idea that according to the solution of the invention the cellular network employs an index or an identifier as a pointer to a subscriber's secret authentication key K. The pointer is needed in order to obtain correspondence between the secret authentication keys entered onto the cards and the ones defined in the network. According to the solution, the secret keys used for authentication are programmed simultaneously in the network databases and in the integrated or detachable subscriber identity modules, e.g. SIM cards, so as to prevent anyone seeing the secret keys. In association with the aforementioned programming, each key is in addition provided with an index or identifier by means of which the mobile communication system knows the location of the corresponding key in its databases, for example in an authentication database (AUC) connected to the Home Location Register (HLR). Hence, identifiers are generated for the authentication keys in the database of the mobile communication system. It is consequently enough that when the mobile stations or the network elements desired know these identifiers, the mobile stations may during authentication transmit these identifiers to the mobile communication system. In the mobile communication system, then, the authentication keys are stored in a separate unit which is able to e.g. generate pairs of numbers employed in the authentication process. This signifies that by means of the pointer transmitted by the mobile station or another network element, the authentication centre is able to search its database for an authentication key corresponding to each particular subscriber. This means that the authentication may be carried out without transmitting authentication keys on the radio path. The index or pointer given according to the invention may be in the subscriber identity module, e.g. on a SIM card, or it may be a piece of information stored otherwise, for example manually or on paper, to be entered in a subscriber's data, for example in his HLR, upon defining the subscriber.
0035The method of the invention relates to managing secret keys employed for authenticating subscribers of a radio network in a way in which the keys are generated in a centralized manner in the system and in the subscriber identity modules, for example in SIM cards or subscriber identity modules integrated in mobile stations.
0036According to the invention, the system employs an index for pointing to secret authentication keys in the system. The index may be located in the subscriber identity module, e.g. in a SIM card, or stored in the subscriber database, for example in the subscriber's HLR.
0037The invention provides the advantage that the authentication keys are not revealed at any stage to the user, and they are not transmitted over the radio path. Instead, they are used e.g. for computing pairs of identification numbers.
0038The invention provides the further advantage that it enables keeping the authentication keys secret and invisible, simultaneously enabling smooth distribution of SIM cards to subscribers.
0039Further still, the invention provides the advantage that subscribers may de defined in a decentralized manner, and also subscriber numbers may be defined in the system freely for the subscribers, and programmed on SIM cards. Nevertheless, the encryption keys will not have to be transferred without encryption in the system or with a SIM card. The method consequently combines flexible usability with high level of security.
0040The system or SIM cards need not have any functions by means of which the authentication key could be read. The key is only entered once both into the subscriber identity module and the authentication centre of the mobile communication system, and it is thereafter used in internal computing in the authentication centre and the subscriber identity module, such as a SIM card.
0041The index number in a mobile communication system of the invention only needs to be internal to the system, and therefore it does not have to be taken into account when numbering or air interface signalling is carried out.
0042The invention provides the advantage that divulging of the index number according to the invention in a subscriber identity module such as a SIM card does not constitute a threat to security as the divulging does not benefit an unauthorized user in any way in his unauthorized attempts to be authenticated and registered into the mobile communication system.
0043The invention provides the further advantage that the subscriber identity modules, e.g. SIM cards, and keys do not have to be programmed in the same place. The authentication keys may also be transferred in both directions via an intermediate device, a card or a computer. In such a case, it is possible to generate distribution cards containing several authentication keys, and to use the distribution cards to transfer keys to locations in which the actual distribution to subscribers is carried out. The data on such distribution cards must naturally be protected equally well as the data in the system and on the SIM card. The distribution cards are provided with index numbers of all the cards to be programmed from it.
0044It must further be taken into account that the method need not be used in association with SIM cards as a similar arrangement is also possible in a system with integral subscriber identity modules in the mobile stations and in systems in which the subscriber identity modules with their subscriber identities form an integral part of the mobile station or its memory.
LIST OF FIGURES
0045The invention is in the following described in more detail with reference to the attached drawings, in which <ul id="ul0001" list-style="none" compact="compact"><li>Figure 1 shows centralized generation of authentication keys according to the invention in a mobile communication system,</li><li>Figure 2 shows the method according to the invention for defining a subscriber in a mobile communication system,</li><li>Figure 3 shows an embodiment of the invention in which the identifier according to the invention is transmitted on the radio path, and</li><li>Figure 4 is a block diagram illustration of a mobile communication system according to the invention and a mobile station therein.</li></ul>
DETAILED DESCRIPTION OF THE INVENTION
0046Figure 1 shows generation according to the invention of an authentication key in a centralized place in the mobile communication system. According to the invention, the mobile communication system/network comprises a centralized place - a key generator 100 - in which the authentication keys are generated and programmed in the memories of authentication centres in the system and on the SIM cards. In practice, it is worth while, but not necessary, to generate a larger number of authentication keys at the same time. Each key will be provided with an identifier, such as an index number, which points to the location of the key in the system. The figure in addition shows a master authentication centre 102 in which the actual authentication takes place. The mobile communication system may additionally have another, back-up authentication centre 103.
0047According to the first embodiment of the invention, when a mobile station or its user is registered, an identifier stored in a subscriber identity module SIM, 101 according to the invention is transmitted from the mobile station concerned to a base station BS of the mobile communication system. After this, on the basis of said identifier, an authentication key corresponding to said identifier 202 will be retrieved from an authentication centre AUG,102. On the basis of the identifier 202, the authentication desired is carried out by means of the authentication key retrieved.
0048According to a second embodiment of the invention, when a mobile station or its user is registered, an identifier in accordance with the invention, which is stored in a subscriber database DB, is transmitted during the authentication process to the authentication centre 102,AUC. After this, on the basis of said identifier, an authentication key corresponding to said identifier 202 will be retrieved from an authentication centre AUC,102. On the basis of the identifier 202, the authentication desired is then carried out by means of the authentication key retrieved.
0049It should be noted that by means of said authentication key it is possible to autheriticate either a mobile station or its user, or the mobile communication system.
0050Figure 2 shows a method according to the invention for defining a subscriber in a mobile communication system. The subscriber receives a SIM card, 101, and his subscriber data are defined in the system, for example in a subscriber database 201 of the system. The authentication key index i.e. the identifier 202 supplied with the card is defined in the subscriber data. According to this solution, then, information on the index i.e. the identifier 202 is external to the SIM card 101, for example on a separate piece of paper, e.g. in a letter 203.
0051Figure 3 shows an implementation according to an embodiment of the invention, in which the index in accordance with the invention is transmitted over the radio path RP from a mobile station 301 to the base station BS. According to this solution, the index i.e. identifier 202 of the invention is on a SIM card 101, and therefore it is transferred for example in conjunction with registration or authentication over the radio path RP to the base station BS and further to other parts of the mobile communication system, e.g. to its authentication centre 102 (Figure 1). The authentication may also be implemented so that it is provided with exchange of messages, in which said identifier is transferred to the mobile communication system and stored permanently in its database, from which it may be picked up when a subscriber later registers in the system and when authentication is carried out.
0052After the subscriber identities have been generated, the system knows the subscriber and is able, on the basis of the identifier, to employ the correct authentication key. The authentication centre AUC, 102 of the system, may be placed in connection with the Home Location Register (HLR) of the subscriber. When a subscriber is authenticated, the system is able to find the correct authentication centre on the basis of the identifier. Further, within the authentication centre, the system is able to request a pair of authentication numbers corresponding to said subscriber on the basis of the identifier. The mobile station, subscriber or mobile communication system in question may then be authenticated on the basis of said pair of numbers.
0053Figure 4 is a block diagram illustration of a radio unit according to the invention. The figure shows the network infrastructure (INFRA) 600 of the mobile communication system. The network infrastructure comprises e.g. base stations BS, exchanges and other telecommunication devices as well as subscriber databases DB, such as a Home Location Register (HLR) and a Visitor Location Register (VLR), and an authentication centre (AUC).
0054The mobile communication system of the invention further comprises generating means 601 for generating identifiers 202 which correspond to the authentication keys required in the authentication process and on the basis of which said authentication keys may be found in said authentication centre 102, AUC when authentication is being carried out.
0055Figure 4 shows a typical radio unit 500 communicating in the mobile communication system, such as a subscriber-operated mobile phone, a mobile station or a subscriber station. The function of the transceiver unit (TX/RX) 501 is to tune to the radio channel employed on any one occasion, by means of which the mobile station communicates with the network infrastructure, typically via the base station BS (Figure 3). An antenna 502 is connected to the transceiver 501, the antenna having connection to the radio path RP. Usually, radio frequencies in the range 60-1000 MHz (VHF and UHF bands) are used, although other frequencies can also be used. On the radio path RP, either analogue or digital modulation may be employed.
0056The user interface 505 comprises an electroacoustic transducing means, typically a loudspeaker 506 and a microphone 507, and possibly buttons relating to beginning, ending and dialling a call. In trunked systems, the subscriber unit typically contains a push to talk button (PTT) that must be pressed down for the duration of the speaking turn.
0057The function of a controller 503 is to control the operation of the radio unit. The controller 503 is connected to the user interface 505, from which it obtains impulses relating to, for example, the call initiation and termination. Through the user interface 505, the controller 503 may also provide the user with acoustic or visual signals relating to the operation of the mobile phone or the mobile radio system.
0058The controller 503 is connected to the transceiver TX/RX 501. The channel employed by the transceiver is defined by the controller 503, i.e. the transceiver 501 tunes to a channel, i.e. radio frequency and an appropriate time slot, allocated by the controller 503. The transceiver is also activated by the controller 503. The controller 503 receives and transmits signalling messages by means of the transceiver 501. A radio unit 500 according to the invention may be used, for example, in a radio system comprising a radio network which has at least one base station BS and subscriber stations, and possibly one or more repeater stations. Said radio unit contains a transceiver unit 501 for receiving transmissions transmitted by other radio units or base stations and for transmitting the transmissions to other radio units or base stations, a control unit 503 for controlling the radio unit functions, and a user interface 504.
0059The mobile station 500 according to the invention comprises a subscriber equipment which may be provided with a subscriber identity module. The subscriber equipment consists of the transceiver unit 501, the controller 503 and the user interface 505. The mobile station further comprises a unique subscriber identity module 509, e.g. a SIM card, which is detachably connected to the subscriber equipment to form a mobile station.
0060The mobile station according to the invention comprises transmitting means 510 for transmitting identifiers, on the basis of which authentication keys used in the authentication process may be found in the authentication centre AUC, from the mobile station to the mobile communication system.
0061The drawings and the description related thereto are only intended to illustrate the idea of the present invention. The invention may vary in details within the scope of the claims. Although the invention is described above mainly in relation to the GSM and TETRA mobile communication systems, the invention is also applicable to other kinds of mobile communication systems, particularly in those based on the GSM and TETRA mobile communication systems.
0062The method may be implemented either by inserting the index i.e. the identifier in the subscriber identity module (the SIM card, 509), which is either integral to the mobile station or a removable SIM card, or by programming the identifier in the system in one of its databases in connection with the subscriber data. In the former method, the index must be transferred, if need be, over the radio interface to the system. In the latter method, information of the identifier must be somehow written down, e.g. on a piece of paper, in conjunction with storing the authentication key in the subscriber identity module, so that it can be associated with the subscriber data when entering the subscriber of the subscriber identity module, e.g. a SIM card, in the system.
0063Of the alternatives disclosed, the one employing SIM cards is the most useful. This results from the fact that to attach the subscriber identity module integrally to the mobile station would be rather difficult as it would require much co-operation between various manufacturers and operators.
Contents5
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0506637A | Cites | European Patent Office (EPO) |
| US5249230A | Cites | United States of America |
| US5303285A | Cites | United States of America |
| THE GSM SYSTEM FOR MOBILE COMMUNICATIONS, 1992, MICHEL MOULY et al., "ISBN 2-9507190-0-7", pages 478-489. | Non-patent | – |
20 members in 12 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 960325 | Finland | – | |
| 960325 | Finland | A | |
| 9700030 | Finland | W |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| FI960325A | Finland | A | |
| WO9727716A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU1446797A | Australia | A | |
| EP0872151A1 | European Patent Office (EPO) | A1 | |
| FI102235B | Finland | B | |
| FI102235B1 | Finland | B1 | |
| NZ326379A | New Zealand | A | |
| CN1209939A | China | A | |
| KR19990077193A | Republic of Korea | A | |
| AU716523B2 | Australia | B2 | |
| JP2000504156A | Japan | A | |
| US6199161B1 | United States of America | B1 | |
| EP0872151B1This record | European Patent Office (EPO) | B1 | |
| AT334562T | Austria | T | |
| ATE334562T1 | Austria | T1 | |
| DE69736384D1 | Germany | D1 | |
| ES2267128T3 | Spain | T3 | |
| DE69736384T2 | Germany | T2 | |
| CN101076190A | China | A | |
| CN101076190B | China | B |
53 legal events, as 8 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04Q0007380000R079 | R079 | DE | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04Q0007380000R079 | R079 | DE | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Ep patent has lapsedLapsedEUG | EUG | SE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Fr: translation filedET | ET | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0872151
- Application
- 979011038
Titles3
- German
- VERWALTUNG VON AUTHENTIFIZIERUNGSSCHLÜSSELN IN EINEM MOBILEN KOMMUNIKATIONSSYSTEM
- English
- MANAGEMENT OF AUTHENTICATION KEYS IN A MOBILE COMMUNICATION SYSTEM
- French
- GESTION DE CLEFS D'AUTHENTIFICATION DANS UN SYSTEME MOBILE DE COMMUNICATIONS
Classification
- CPC, 6
- H04L9/0836
- H04L9/321
- H04L2209/80
- H04W12/0433
- H04W12/041
- H04W12/069
- IPC, 3
- H04Q7 38
- H04L9 32
- H04W12 06
Designated states15
- Contracting states, 15
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Ireland
- Italy
- Liechtenstein
- Netherlands (Kingdom of the)
- Portugal
- Sweden