Primary provisioning of a validation procedure for a terminal
7 claims: 4 independent, 3 dependent
- 1Procédé de validation de données envoyées par une source (4) à un terminal (2) sur un médium (6), comprenant les étapes de:- envoi (20) de données par la source au terminal, sur le dit médium ;- calcul (22) d'une signature dans le terminal à partir des données envoyées par la source ;caractérisé en ce que le procédé comprend aussi les étapes de : - affichage (24) sur le terminal d'une invite d'entrée d'une signature ;- réception (28) sur le terminal d'une signature entrée par l'utilisateur du terminal, cette signature ayant été reçue par l'utilisateur par l'intermédiaire d'un autre médium;- comparaison (30) dans le terminal de la signature calculée et de la signature entrée par l'utilisateur, et - validation (32) des données en fonction des résultats de l'étape de comparaison.
- 2Le procédé de la revendication 1, caractérisé en ce que les données sont un certificat contenant une clé publique d'authentification.
- 3Le procédé de la revendication 2, caractérisé en ce que la clé publique d'authentification est la clé publique de la dite source.
- 4Le procédé de la revendication 1, 2 ou 3, caractérisé en ce que l'étape de calcul d'une signature s'effectue par hachage.
- 5Le procédé de l'une des revendications 1 à 4, caractérisée en ce que les données sont des données de provisionnement primaire.
- 6Le procédé de l'une des revendications 1 à 4, caractérisée en ce que les données sont des données de provisionnement d'application.
- 7Le procédé de l'une des revendications 1 à 6, caractérisé par l'étape d'envoi de la signature à l'utilisateur du terminal par la source par l'intermédiaire d'un autre médium.
Independent claims7
29 paragraphs, as filed
The present invention relates to establishing connections to an Internet type network for terminals, including mobile, especially authentication provisioning data needed to establish a connection.
As is well known, making connections through a network such as the Internet involves the allocation of an address on the network. The address allocation is for most users a dynamic address allocation, performed by a service provider with which the user is referenced. primary provisioning is called, or provisioning of primary data, the step of providing a user with data for establishing a first connection to an ISP. This data includes all the parameters of all the layers necessary to connect to the ISP, for example the telephone number, the transmission medium used, a user ID, password etc. In the case of connections to an ISP using a computer, the primary provisioning is often done by providing the user with a CD containing the provisioning data, with a temporary address. It is also known to provide the primary provisioning data by mail; the data is then copied by the user at the prompt, using appropriate software.
Appear currently mobile terminals, which also have a terminal function for telephone network. For these devices is the problem of primary provisioning, provided that the known solutions for computers or landlines can not easily be transposed.
It is also known to use for identification or verification of the integrity of messages asymmetric algorithms; such asymmetric algorithm uses a public key and a private key, and may especially be used for authentication on the Internet. A user is assigned a private key and a public key is distributed and certified by an organizer for this user. Knowing the public key does not help to get the private key, however, the knowledge of the public key to verify a signature by the private key. RSA is a known example of asymmetric algorithm. Such an algorithm does not apply to primary provisioning, as a public key has value for certification or authentication that insofar as it emanates from an authority that can certify. The primary provisioning is a situation in which such authority does not exist yet.
EP 944 203 describes sending a security key and authentication data to a terminal.
It has been proposed to use a key inserted in the terminal during manufacturing, when buying, or a key provided in a plug of the type chip card. These solutions are not satisfactory. In fact, for the first two, the key may change after the manufacture or sale of the terminal, for example if the user takes out a subscription with a new service provider; Moreover, the Domain owner and recipient provisioning data can be different from the owner of the terminal. For the third solution is the problem of the cost of the smart card; Furthermore, the domain owner can be different from the owner of the smart card terminal.
EP 889 660 discloses the authentication of a terminal by an access point.
ETSI / SMG4 / MExE offers a manual provisioning process from a first certificate to a mobile terminal. The certificate is a special certificate of the terminal administrator. The procedure proposed in this standard is as follows. The mobile terminal and the provisioning entity establish a first contact. The user initiates the primary terminal provisioning certificate request. The provisioning entity sends the certificate of primary provisioning, in a signed package; as just explained, the device can not verify the signature of the received packet, due to the lack of an authenticated public key. The terminal therefore calculates and displays the signature of the received packet, and prompts the user to validate the signature. The user establishes a separate contact with the provisioning entity, by mail, telephone or other secure link, and obtains from the signature provisioning entity that should be displayed on the terminal. The user confirms the proposed signature terminal, if it proves that the signature proposed elsewhere by the provisioning entity is the same. The validation of the terminal equals the received authentication certificate.
This procedure has the following disadvantage. The user can validate the signature on the proposed terminal, either inadvertently or by mistake, even if different from the signature also proposed by the provisioning entity.
The invention proposes a solution to the problem of authentication of the primary provisioning for mobile devices. It allows provisioning of primary data, which is simple for the user, and avoids any untimely validation.
More specifically, the invention provides a data validation process sent from a source to a terminal on a medium, comprising the steps of:<ul><li>sending data from the source to the terminal, on the said medium;</li><li>calculating a signature in the terminal;</li><li>display on the terminal of a prompt entry of a signature;</li><li>receiving at the terminal a signature input by the terminal user;</li><li>comparison in signing the terminal calculated and signature input by the user, and</li><li>data validation based on the results of the step of comparaison.Dans one embodiment, the data is a certificate containing a public key authentication. In this case, it is advantageous that the public key authentication is the public key of said source.</li></ul>
In another embodiment, the step of calculating a signature is performed by hashing.
Preferably, the data is primary provisioning data. It may also include application provisioning data.
In yet one embodiment, the method comprises the steps of:<ul><li>computing a signature in the source data sent from;</li><li>sending the signature to the terminal user by another medium.</li></ul>
Other characteristics and advantages of the invention will appear on reading the following description of the invention embodiments, given by way of example and with reference to the accompanying drawings, in which:<ul><li>1, a diagram of a mobile terminal and a data source;</li><li>Figure 2 is a flowchart of the inventive method.</li></ul>
For authentication data, the invention proposes, instead of displaying the data to be compared by asking a simple validation by the user, asking the user to enter data to compare. The effective user input data for comparison, or information representative of the data, allows the terminal to perform the comparison. The invention avoids accidental data validation, and ensures that certification is successful. The invention also provides certification on the initiative of the source, and not only to the user's initiative.
In the following description, the invention is described with reference to an example. The terminal is a mobile terminal, the source is a service provider, and the data is primary provisioning data.
FIG 1 shows a diagram of the mobile terminal and a data source. the mobile terminal 2, and a data source 4. This data source is in such a provider to the Internet is plotted in Fig. The mobile terminal and the data source can communicate through a telecommunications network 6, for example a GSM network.
As indicated above, the invention is applicable to the authentication of data from the source and sent to the mobile terminal. This data can be of primary provisioning data, or just a certificate for authentication of primary provisioning data sent later. These data are in any case developed in the source, and are sent to the mobile terminal.
The arrow in Figure 8 symbolizes the sending data from the source 4 to Terminal 2 via the GSM network. These data can be sent at the initiative of the source, or on request from the terminal. In the first case, the provisioning data can be sent at the initiative of the source, without the terminal solicits sending data. In the latter case, the user can initiate as in the process mentioned above MExE a motion for a provisioning certificate; the request is received by the source, and the data is transmitted. This step is referenced 20 in Figure 2
The data is received by the terminal 2, and is processed by the terminal to calculate a signature. The term "computing a signature" any position to combine the data received a signature, that is to say a number or an alphanumeric string of generally shorter length that data; the function is injective, or at least the likelihood separate data have the same signature is weak. The signature for the purposes of this definition covers a signature in the classical sense, require a key, as a simple impression obtained by chopping. In the mode of the simplest embodiment, the signature is transmitted by the source, and the computing step is to isolate the signature in the data.
To calculate the signature, one can use a hash function, for example that of SHA-1 algorithms, MD5 or MD2. The SHA-1 hash algorithm outputs a 20 byte footprint. One can use a key-based signature algorithm such as RSA algorithm ECDSA. One can also combine a hash function and the calculation of a signature on the fingerprint obtained by hashing; this solution reduces the time of calculation, due to the smaller volume of data. This step of receiving the data and signature calculation, referenced 22 in the flow chart of Figure 2, following the step 20 of sending data by the source.
After calculating the signature, the terminal 2 displays a prompt to the user 12, so that the user enters the terminal a signature. In the case of a conventional mobile terminal equipped with a screen and a keyboard, the term "display" is the print on the screen of a prompt that tells the user that it must enter a signature. This prompt can also be displayed by an acoustic signal, or other means. This display a prompt to the user is represented in Figure 1 by the arrow 10, and corresponds to the flowchart of Figure 2 in step 24, following step 22.
The terminal then waits for user input of a signature, as shown in the flow chart of Figure 2 by step 26. This step may be limited in time; the terminal may also offer the user to interrupt the validation process; this is not shown in Figure 2. In a case as in the other, validation may be resumed later at the initiative of the source. It is also possible, as in the manual procedure described in the standard MExE validation to the user's initiative; However, contrary to this solution, the invention makes possible a validation on the initiative of the source.
In the diagram of Figure 1, the arrow 14 shows the reception of a signature by the user from the source, and via another medium. here refers to another medium, as in the procedure MExE any communication channel between the source and the user to be considered reliable. It may be a letter, a transmission by telephone, or other. The signature thus provided by the source is a signature calculated from the transmitted data to the terminal, knowing the function of calculating the signature implemented in the terminal. It is also to provide the signature the user to use a third party other than the source, with which the user has established a trusted relationship.
The user, having procured from the source or third signature expected by the terminal, returns this signature in the terminal. In the simplest case, this entry is made through the terminal keyboard, but other solutions are possible, depending on the data input device available to the terminal. This data input is symbolized by the arrow 16 in Figure 1. In Figure 2, step 28, which follows step 26 corresponds to the reception data.
The terminal, after receiving the signature input by the user, compares the signature calculated from data received from the source and the signature input by the user; this appears in the flow chart of Figure 2 to the comparison step 30. In the simplest case, the signature provided to the user by the other medium is identical to the signature calculated by the terminal. It is also possible that the signature provided to the user by the source or the third party is not identical to the calculated signature: that is the comparison function implemented in the terminal is not limited necessarily to a term by term comparison but can include calculations on the signature input by the user. In all cases, it should be noted that according to the invention a simple user validation is not enough to validate the data received from the source. Comparison by the terminal enables the terminal to determine whether the signature calculated from the data received from the source matches the signature input by the user. If that is the case, the terminal concludes that the data is valid, as shown in step 32 of the flowchart in Figure 2. If this is not the case, the terminal can display a new prompt, c ' is to say, as shown in Figure 2, back to step 24. it is also possible to interrupt the validation process, or limit the number of signature introductory essay.
Of course, the invention is not limited to the preferred embodiments described above. It applies to other types of terminals, for other types of data, and other authentication algorithms. We might as well use both the invention for authenticating keys to a symmetric algorithm. The invention has been described in the particular case of primary provisioning data; we could still use the invention for application data provisioning. For example, in a banking application, the invention could be used to confirm the transmission of a customer or account number, a password, and application options, etc.
In all cases, the invention allows to validate the data transmitted by the source, avoiding inadvertent validation by mere acquiescence of the user.
2 sheets
Sheet 1 Sheet 2
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office |
|---|---|---|
| EP0889660A | Cites | European Patent Office (EPO) |
| EP0944203A | Cites | European Patent Office (EPO) |
| EP0951191A | Cites | European Patent Office (EPO) |
| WO9907173A | Cites | World Intellectual Property Organization (WIPO) |
| US5371794A | Cites | United States of America |
| "DIGITAL CELLULAR TELECOMMUNICATIONS SYSTEM (PHASE 2+);MOBILE STATION EXECUTION ENVIRONMENT (MExE); SERVICE DESCRIPTION; Stage 1 (GSM 02.57 version 7.1.0 Release 1998) ETSI TS 101 741 v7.1.0" EUROPEAN TELECOMMUNICATION STANDARD, août 1999 (1999-08), pages 1-21, XP002145174 | Non-patent | – |
12 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 9914636 | France | A | |
| 9914636 | France | A | |
| 9914636 | France | – | |
| 9914636 | – | – | – |
| FR19990014636 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| HU0004641D0 | Hungary | D0 | |
| EP1102452A2 | European Patent Office (EPO) | A2 | |
| FR2801452A1 | France | A1 | |
| EP1102452A3 | European Patent Office (EPO) | A3 | |
| CN1302168A | China | A | |
| JP2001236015A | Japan | A | |
| FR2801452B1 | France | B1 | |
| CN1212744C | China | C | |
| EP1102452B1This record | European Patent Office (EPO) | B1 | |
| AT352158T | Austria | T | |
| ATE352158T1 | Austria | T1 | |
| DE60032998D1 | Germany | D1 |
52 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Change of addressCA | CA | FR | |
| Change of addressCA | CA | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Gb: ep patent (uk) treated as always having been void in accordance with gb section 77(7)/1977 [no translation filed]GBV | GBV | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Nl: modifications (of names), taken from the european patent patent bulletinNLT2 | NLT2 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Party data changed (patent owner data changed or rights of a patent transferred)RAP2 | RAP2 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: FRENCHFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designation fees paidAT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE TRAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1102452
- Publication, DOCDB
- 1102452
- Publication, EPODOC
- EP1102452
- Application
- 403201
- Application, DOCDB
- 00403201
- Application, EPODOC
- EP20000403201
Titles3
- German
- Freigabeverfahren für die erste Bereitstellung eines Endgerätes
- English
- Primary provisioning of a validation procedure for a terminal
- French
- Procédé de validation du provisionnement primaire d'un terminal
Classification
- CPC, 8
- H04L63/12
- G06F21/42
- G06F21/64
- H04L63/0823
- H04L63/18
- H04L63/0853
- H04W12/04
- H04W12/069
- IPC, 5
- H04L29 06
- G06F21 42
- G06F21 64
- G09C1 00
- H04W12 06
Designated states1
- Contracting states, 1
- Türkiye
