EP0898397A2

Method for sending a secure communication in a telecommunications system

Abstract

A method for sending a secure comunication in a telecommunications system using public encryption keys. A secure communication may be sent from a first transceiver to a second transceiver through the system. The method allows authentication of each transceiver by the other, provides an integrity check on the communication, and disallows repudiation of the communication by the sending party. Authentication of the communication may be proven at each of the first and second transceivers, through the use of a authentication certificate for each of the first and second transceivers that is generated and stored at a security center in the system, such as a short message service center. As the communication is sent through the system, each user of a transceiver may authenticate the other transceiver by authenticating the certificate of the other transceiver, upon receiving the certificate from the system. Integrity and nonrepudiation for the communication is achieved by utilizing the public encryption and private decryption keys of the security center at the first and second transceivers.

EP0898397A2, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 18 August 2018, 8.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

12 claims: 1 independent, 11 dependent

  1. 1
    A method for sending a secure message in a telecommunications system having a plurality of transceivers, said method comprising the steps of:assigning a first decryption key and a first encryption key to a first transceiver, and assigning a second decryption key and a second encryption key to a second transceiver;assigning a third decryption key and a third encryption key to a message center;forming a first and a second certificate within said message center, said first certificate including said first encryption key and a first authentication value, and said second certificate including said second encryption key and a second authentication value, wherein said first and second authentication values are calculated using said third decryption key on a first and second authentication parameter, respectively;transmitting a first message from said first transceiver to said message center, said first message including information indicating a request to transmit a communication from said first transceiver to said second transceiver;transmitting a second message from said message center to said first transceiver, said second message including said second certificate;authenticating said second certificate at said first transceiver by using said third encryption key on said second authentication value to generate a first result and comparing said first result with said second authentication parameter as known in said first transceiver;selecting a session key at said first transceiver;forming a third message, at said first transceiver, said third message comprising a first message portion comprising said session key encrypted using said second encryption key, a second message portion comprising said communication encrypted using said session key, and an integrity value computed by using said first decryption key on an integrity parameter;transmitting said third message to said message center, said third message including said first and second message portions and said integrity value;transmitting said first certificate and said third message from said message center to said second transceiver;authenticating said first certificate at said second transceiver by using said third encryption key on said first authentication value to generate a second result and comparing said result with said first authentication parameter as known in said second transceiver;calculating said session key from said first message portion using said second decryption key and decrypting said communication from said second message portion using said session key;and checking the integrity of said third message using said first encryption key on said integrity value to generate a third result and comparing said third result with said integrity parameter as known in said second transceiver.
  2. 5
    The method of any of claims 1 to 4, wherein said step of authenticating said first certificate at said second transceiver comprises applying said authentication function to said first identifying information and said first encryption key received from said message center in said first certificate to generate said first authentication parameter, applying said third encryption key to said first authentication value to generate said second result, and comparing said second result and said first authentication parameter.