EP0903887A2

Cellular telephony authentication arrangement

Abstract

A secure cellular telephony arrangement where the mobile unit maintains a secret that is assigned to it by the service provider, and which is known to the provider (home cellular geographic service are -- CGSA) but not to any other base station. A shared secret datum is generated by the home CGSA with the aid of the secret and some other data. That data is transmitted to the mobile unit to enable it to also generate the shared secret datum. A mobile unit wishing to communicate with a base station creates an authentication string with the aid of the shared secret datum and sends it and the unit's identity to the base station. A base station which does not have the shared secret datum is unable to immediately authenticate the mobile unit. It therefore contacts the home CGSA, receives the shared secret datum and the other data, and proceeds to authenticate the mobile unit's authentication string. With the information received from the home CGSA the base station can direct the mobile unit to regenerate the shared secret datum or even create a new one.

EP0903887A2, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 3 September 2012, 14.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 2 independent, 8 dependent

  1. 1
    A method for authenticating a mobile station (22) for use in an arrangement including a home station (14), a base station (40) and said mobile station (22), wherein the mobile station (22) sharing with the home station (14) a key code that is not known to the base station (40) while refraining from divulging the key code to the base station (40); the method comprising the steps of:the base station (40) receiving from the mobile station (22) the identity of the mobile station (22) and an authentication signal constructed with the aid of a "shared-secret-datum" signal derived at the mobile station (22) from the said key code via a transformation of the key code and additional data;the base station (40) transmitting to the home station (14) the identity of the mobile station;and establishing a call with the mobile station (22) when an evaluation of the authentication signal determines that the authentication signal sent by the mobile station (22) is valid, said evaluation is performed with the aid of a "shared-secret-datum" signal derived at the home station (14) from said key code via a transformation of the key code and additional data.
  2. 2
    A method for authenticating a mobile station (22) for use in an arrangement including a home station (14), a base station (40) and said mobile station (22), wherein the mobile station (22) transmits to the base station (40) the identity of the mobile station (22) and constructs an authentication signal constructed with the aid of a "shared-secret-datum" signal derived at the mobile station (22) from a key code via a transformation of the key code and additional data, the method comprising the steps of:the home station (14) sharing with the mobile station (14) the key code that is not known to the base station (40) while refraining from divulging the key code to the base station (40);the home station (14) receiving the identity of the mobile station (22) from the base station (40);and the home station deriving a "shared secret datum" signal from the key code via a transformation of the key code and additional data for establishing a call between the base station (40) and the mobile station (22) when an evaluation (40) of the authentication signal determines that the authentication signal sent by the mobile station (22) is valid, said evaluation is performed with the aid of the "shared-secret-datum" signal derived at the home station (14) from said key code via a transformation of the key code and additional data.