Method for the cryptographically verifiable identification of a physical unit in a public, wireless telecommunications network
7 claims: 7 independent, 0 dependent
- 1Method for identifying a physical unit (M) in an open wireless telecommunications network by means of a testing device (P), having the steps of:a) storing a secret identity (SIMEI) and an open identity (IMEI) in the physical unit (M), wherein a one-way representation F1 generates the secret identity (SIMEI) from the open identity (IMEI) and a manufacturer key (MIGK), and storing an open key (EMIGK) on an open Internet homepage OMHP belonging to the manufacturer of the device M to be identified, which key is generated from a first secret key (SMMK) of the manufacturer and the second secret key (MIGK, Master Identity Generator Key) by means of a cryptographic function F2;b) generating a first parameter (CHv) in the testing device (P);c) transmitting an identification request (IR) containing the first parameter (CHv) from the testing device (P) to the physical unit (M);d) generating an electronic signature (SIGt) in the physical unit (M), by means of a first cryptographic function (F3), from the secret identity (SIMEI), the first parameter (CHv) and a second parameter (CHt) which is generated by the physical unit (M), wherein the first and second parameters (CHv;CHt) are multiplexed and are then linked to the output (SIGt) of the first cryptographic function (F3) by means of an exclusive OR function (+), and transmitting the generated electronic signature (SIGt), the open identity (IMEI) and the second parameter (CHt) to the testing device (P);e) generating the secret identity (SIMEI) from an open key (EMIGK) downloaded from the open directory (OR) of the manufacturer and the received open identity (IMEI) in the testing device (P), wherein the secret identity (SIMEI) is generated by using the manufacturer key (MIGK) and the open identity (IMEI) via the third function F1, wherein the second secret manufacturer key (MIGK) is generated from the open key (EMIGK) and the first secret manufacturer key (SMMK) by means of the inverse of the second cryptographic function F2-1;f) generating a corresponding electronic signature (SIGv), by means of the first cryptographic function (F3), from the generated first secret identity (SIMEI), the first parameter (CHv) and the second parameter (CHt) which is received from the physical unit (M) in the testing device (P), wherein the first and second parameters (CHv;CHt) are multiplexed and are then linked to the output (SIGv) of the first cryptographic function (F3) by means of an exclusive OR function (+);andg) identifying the physical unit (M) by comparing the transmitted electronic signature (SIGt) and the generated corresponding electronic signature (SIGv) in the testing device (P). Procédé d'identification d'une unité physique (M) dans un réseau de télécommunication sans fil ouvert, par un dispositif de contrôle (P), comprenant les étapes suivantes : a) mémorisation d'une identité secrète (SIMEI) et d'une identité ouverte (IMEI) dans l'unité physique (M), une image unidirectionnelle F1 générant l'identité secrète (SIMEI) à partir de l'identité ouverte (IMEI) et d'une clé de fabricant (MIGK), et mémorisation d'une clé ouverte (EMIGK) sur une page d'accueil internet ouverte OMHP du fabricant de l'appareil à identifier M-, laquelle clé ouverte est générée par une fonction de cryptage F2 à partir d'une première clé secrète (SMMK) du fabricant et de la deuxième clé secrète (MIGK, Master Identity Generator Key) ;b) génération d'un premier paramètre (CHv) dans le dispositif de contrôle (P) ;c) envoi d'une demande d'identification (IR) avec le premier paramètre (CHv) par le dispositif de contrôle (P) à l'unité physique (M) ;d) génération d'une signature électronique (SIGt) par une première fonction cryptographique (F3) dans l'unité physique (M), à partir de l'identité secrète (SIMEI), du premier paramètre (CHv) et d'un deuxième paramètre (CHt) qui est généré par l'unité physique (M), les premier et deuxième paramètres (CHv ;CHt) étant multiplexés puis combinés par une fonction OU exclusif (+) avec la sortie (SIGt) de la première fonction cryptographique (F3), et envoi de la signature électronique (SIGt) générée, de l'identité ouverte (IMEI) et du second paramètre (CHt) au dispositif de contrôle (P) ;e) génération de l'identité secrète (SIMEI) à partir d'une clé ouverte (EMIGK) téléchargée depuis le répertoire ouvert (OR) du fabricant et de l'identité ouverte (IMEI) reçue dans le dispositif de contrôle (P), l'identité secrète (SIMEI) étant générée par utilisation de la clé de fabricant (MIGK) et de l'identité ouverte (IMEI) par l'intermédiaire de la troisième fonction F1, la deuxième clé de fabricant secrète (MIGK) étant générée par l'inverse de la deuxième fonction cryptographique F2-1 à partir de la clé ouverte (EMIGK) et de la première clé de fabricant secrète (SMMK),f) génération d'une signature électronique correspondante (SIGv) par la première fonction cryptographique (F3), à partir de la première identité secrète (SIMEI) générée, du premier paramètre (CHv) et du deuxième paramètre (CHt), qui est reçu de l'unité physique (M), dans le dispositif de contrôle (P), les premier et deuxième paramètres (CHv ;CHt) étant multiplexés puis combinés par une fonction OU exclusif (+) avec la sortie (SIGv) de la première fonction cryptographique (F3) ;etg) identification de l'unité physique (M) par comparaison de la signature électronique (SIGt) envoyée et de la signature électronique (SIGv) correspondante générée, dans le dispositif de contrôle (P). Verfahren zur Identifikation einer physikalischen Einheit (M) in einem offenen, drahtlosen Telekommunikationsnetzwerk durch eine Prüfeinrichtung (P) mit den Schritten: a) Speichern einer geheimen Identität (SIMEI) und einer offenen Identität (IMEI) in der physikalischen Einheit (M), wobei eine Einwegabbildung F1 die geheime Identität (SIMEI) aus der offenen Identität (IMEI) und einem Herstellerschlüssel (MIGK) generiert, und Ablegen eines offenen Schlüssels (EMIGK) in einer offenen Internet-Homepage OMHP des Herstellers des zu identifizierenden Gerätes M -, welcher durch eine Krypto-Funktion F2 aus einem ersten geheimen Schlüssel (SMMK) des Herstellers und dem zweiten geheimen Schlüssel (MIGK, Master Identity Generator Key) erzeugt wird;b) Erzeugen eines ersten Parameters (CHv) in der Prüfeinrichtung (P);c) Senden einer Identifikationsaufforderung (IR) mit dem ersten Parameter (CHv) von der Prüfeinrichtung (P) an die physikalische Einheit (M);d) Erzeugen einer elektronischen Unterschrift (SIGt) in der physikalischen Einheit (M) durch eine erste Krypto-Funktion (F3) aus der geheimen Identität (SIMEI), dem ersten Parameter (CHv) und einem zweiten Parameter (CHt), welcher durch die physikalische Einheit (M) generiert wird, wobei der erste und der zweite Parameter (CHv;CHt) multiplexiert und anschließend durch eine exklusive ODER-Funktion (+) mit dem Ausgang (SIGt) der ersten Krypto-Funktion (F3) verknüpft werden, und Senden der erzeugten elektronischen Unterschrift (SIGt), der offenen Identität (IMEI) und des zweiten Parameters (CHt) an die Prüfeinrichtung (P);e) Erzeugen der geheimen Identität (SIMEI) aus einem vom offenen Verzeichnis (OR) des Herstellers heruntergeladenen offenen Schlüssel (EMIGK) und der empfangenen offenen Identität (IMEI) in der Prüfeinrichtung (P), wobei die geheime Identität (SIMEI) durch die Verwendung von dem Herstellerschlüssel (MIGK) und der offenen Identität (IMEI) über die dritte Funktion F1 erzeugt wird, wobei der zweite geheime Herstellerschlüssel (MIGK) durch die Inverse der 2. Krypto-Funktion F2-1 aus dem offenen Schlüssel (EMIGK) und dem ersten geheimen Herstellerschlüssel (SMMK) generiert wird.f) Erzeugen einer entsprechenden elektronischen Unterschrift (SIGv) durch die erste Krypto-Funktion (F3) aus der erzeugten ersten geheimen Identität (SIMEI), dem ersten Parameter (CHv) und dem zweiten Parameter (CHt), welcher von der physikalischen Einheit (M) empfangen wird, in der Prüfeinrichtung (P), wobei der erste und der zweite Parameter (CHv;CHt) multiplexiert und anschließend durch eine exklusive ODER-Funktion (+) mit dem Ausgang (SIGv) der ersten Krypto-Funktion (F3) verknüpft werden;undg) Identifizieren der physikalischen Einheit (M) durch einen Vergleich der gesendeten elektronischen Unterschrift (SIGt) und der erzeugten entsprechenden elektronischen Unterschrift (SIGv) in der Prüfeinrichtung (P).
- 2Method according to Claim 1, characterized in that the open key (EMIGK) is transmitted to the testing device (P) via the Internet. Procédé selon la revendication 1, caractérisé en ce que la clé ouverte (EMIGK) est envoyée au dispositif de contrôle (P) par l'intermédiaire de l'Internet. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der offene Schlüssel (EMIGK) über das Internet an die Prüfeinrichtung (P) gesendet wird.
- 3Method according to one of the preceding claims, characterized in that the first and/or second parameter (CHv;CHt) is/are provided as random variables. Procédé selon l'une des revendications précédentes, caractérisé en ce que les premier et/ou deuxième paramètres (CHv ;CHt) sont prévus en tant que variables aléatoires. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der erste und/oder zweite Parameter (CHv;CHt) als Zufallsgrößen vorgesehen werden.
- 4Method according to one of the preceding claims, characterized in that the telecommunications network is a mobile telephone system. Procédé selon l'une des revendications précédentes, caractérisé en ce que le réseau de télécommunication est un système de téléphonie mobile. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass das Telekommunikationsnetzwerk ein Mobiltelefonsystem ist.
- 5Method according to one of the preceding claims, characterized in that the first, second and third cryptographic functions (F1;F2;F3) are the same function. Procédé selon l'une des revendications précédentes, caractérisé en ce que les première, deuxième et troisième fonctions cryptographiques (F1 ;F2 ;F3) sont une même fonction. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die erste, zweite und dritte Krypto-Funktion (F1;F2;F3) die gleiche Funktion sind.
- 6Method according to Claim 5 in conjunction with Claim 3, characterized in that the same function is a standard function. Procédé selon la revendication 5 en relation avec la revendication 3, caractérisé en ce que ladite même fonction est une fonction standard. Verfahren nach Anspruch 5 in Verbindung mit Anspruch 3, dadurch gekennzeichnet, dass die gleiche Funktion eine Standardfunktion ist.
- 7Method according to one of the preceding claims, characterized in that steps e) and f) are carried out on a smart card (MSC) in the testing device (P). Procédé selon l'une des revendications précédentes, caractérisé en ce que les étapes e) et f) sont effectuées sur une carte à puce (MSC) dans le dispositif de contrôle (P). Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Schritte e) und f) auf einer Smart-Card (MSC) in der Prüfeinrichtung (P) durchgeführt werden.
Independent claims7
82 paragraphs in 4 sections, as filed
STATE OF THE ART
The present invention relates to a method for cryptographically verifiable identification of a physical unit in an open, wireless telecommunications network.
Although applicable to any telecommunications equipment, the present invention and the underlying problem with respect to mobile radio systems are explained.
GSM mobile radio systems and these cryptographic methods are for example in<nplcit id="ncit0001" npl-type="b"><text> Asha Mehrotra, "GSM System Engineering", Artech House Pub., 1996</text></nplcit>, or in <nplcit id="ncit0002" npl-type="b"><text>DR Stinson, "Cryptography Theory and Practice", CRC Press, 1995</text></nplcit>, described.
Out <patcit id="pcit0001" dnum="WO0001187A"><text>WO 00/01187</text></patcit>, Subscriber validation method in cellular communication system, is a dual mode communication system consisting of AMPS and GSM networks known for dual mode end devices that are equipped with a corresponding SIM card. The end devices store a device-related number (ESN) and the SIM card stores a SIM-based device-related number and a subscriber-related number (MIN). For key-based authentication purposes, however, only the SIM-based device-related number is used in the AMPS network.
<patcit id="pcit0002" dnum="EP0800293A"><text>EP 0 800 293</text></patcit>, Circuit and method for generating cryptographic keys, shows the generation of cryptographic keys in a communication unit. There are means for transmitting first character strings during a first communication session and for transmitting second character strings during a second communication session, which is separated in time from the first communication session. Additional means are available for generating a cryptographic key from the first and the second character strings of the time-separated communication sessions, in order to increase the security of the cryptographic key.
From the Bull CP8 document with the number XP-002185511, the smart card implementation CP8 is known, which includes memory and intelligence. These two properties combined in one technology make the smart card invulnerable and prevent it from being misused. For this reason, CP8 is a very secure and convenient means of transporting cryptographic keys or data.
The identity of a mobile terminal or (end) device is generally referred to as IMEI (International Mobile Equipment Identity). It defines a single device individually and provides a complete, clear specification.
<figref idref="f0004">Fig. 7</figref> is a schematic representation of a known identification mechanism of a mobile phone to a network operator.
In <figref idref="f0004">Fig. 7</figref> M denotes a mobile phone with a central processing unit 1 and an identity module 2, which has an access-secure area TA, in which the identity IMEI is stored.
The current detection of such a device M (Mobile Equipment) in the GSM system is based on the fact that the device M presents itself openly through its IMEI. It is required that the device manufacturers should ensure that IMEI cannot be modified in device M, and that the software of device M always only delivers the correct IMEI stored in the device when requested by the network.
The use in the dashed frame of <figref idref="f0001">Figure 1</figref> shows an illustration for the general implementation of this identification mechanism. After an identity request (IR), the device M delivers the parameter IMEI, which the manufacturer 10 has stamped into a protected memory cell, in response to the network operator.
This procedure is easy to forge. A software jump J in the software identification system SS can (as in<figref idref="f0001">Figure 1</figref> to see) provide any other identification IMEI 'instead of the correct identification IMEI. This is always possible if you can change the software of the device M, which is usually easy, or if you can change the identity IMEI, which is usually a little more difficult. The biggest problem, however, is that cloned devices can provide an IMEI identity at will. You only have to listen to the network once and find out a legal IMEI, since IMEI is always sent openly. But you can also generate legitimate IMEI identifications yourself, since the setting is known. This type of identification therefore does not offer a special security standard.
<figref idref="f0004">Fig. 8</figref> is a schematic representation of another known identification mechanism of a mobile phone against a network operator according to the Challenge & Response technique.
Secure identification using the so-called Challenge & Response technique is a well-known technique in crypto systems to determine the identity of a device.
The technology builds, as in <figref idref="f0004">Figure 8</figref> presented to the question and answer. The test station (for example a base station of the network operator) P sends to the device under test M an identification request AR with a random symbol sequence RAND "challenge pattern" of 128 bits generated in a random generator RG and requests a certain reaction ARE "response" from it 32-bit data word SRES, which proves that the device under test M has a certain secret value K<sub>i</sub> with 128 as well as the test station has P bits, which together with RAND can be linked by a picture A3 to a test result SRES, which is returned to the test station P by the tested device M.
The map A3 is a strongly non-linear map that is very difficult to reverse (often referred to as a one-way function), as in Asha Mehrotra loc. shown. Figure A3 is typically selected as a block cipher. The two, Examiner P and Examined M, receive the same response SRES if the two secret keys K<sub>i</sub> for examiner P and for inspected M are identical. In this case the identification result ARES is positive, otherwise negative.
This process can be repeated several times with different random values RAND in order to increase the security. This procedure is already used in the GSM system, but only to identify a user with his USIM user card. With the increasing threat of cloning and theft of cellular devices, the need to incorporate a mechanism into the mobile device that causes the device to identify itself and thus detect stolen, cloned or non-certified devices in a network has increased. However, this requires knowledge of the parameter K<sub>i</sub> by auditors and auditors. However, since there are many service providers and many manufacturers in a wireless network, complex management and exchange of all K are<sub>i</sub>'s necessary in the network between manufacturer and network operator.
The number of units to be identified and their manufacturers is large in today's communication networks and is constantly changing. This further increases the administrative and maintenance effort.
ADVANTAGES OF THE INVENTION
The method according to the invention with the features of claim 1 and the corresponding device according to claim 7 have the advantage over the known approach that an identification mechanism based on C&R technology is created, which does not require a high level of administration and maintenance. The invention enables the identification of a network unit by means of the simplest possible hardware infrastructure present in the network with the simplest possible administration and the least possible communication.
The idea on which the present invention is based is that a modified challenge response technique is used to check whether a physical unit contains a certain secret identity without reading this identity and also without knowing this identity beforehand. This proves the authenticity of the identity of the physical unit or device. The method according to the invention is based on a secret cryptography technique in connection with an arrangement of certain hardware units and with a protocol.
The method according to the invention is based on the storage of a unique secret identity in a protected register within the device to be identified and a secret manufacturer key within a device, for example a smart card, for the examiner. The secret identity or the secret manufacturer key is not made readable by a hardware device, such as in<nplcit id="ncit0003" npl-type="b"><text>Asha Mehrotra, "GSM System Engineering", Artech House Pub., 1996</text></nplcit>, disclosed. However, the device is able to provide information that proves the unique identity of the device through the technology of Challenge & Response (C & R).
The technique of Challenge & Response is a well-known technique and is widely used in cryptographically secured systems for identification. The special features of this procedure are:<ul id="ul0001" list-style="bullet"><li>no register for the identities of the individual devices is required;</li><li>no common knowledge of the secret identity by the examiner and the auditor is necessary;</li><li>the solution is adapted to the conditions and environment of mobile phones with many service providers and manufacturers who work internationally and have poor information exchange and coordination options; and</li><li>the technology builds units that already exist in the system.</li></ul>
The invention is an extension of the challenge response technology in order to make the identification less complex and therefore flexible and cost-effective. In a preferred embodiment, the new technology uses Internet servers and modern smart card technology.
Advantageous developments and improvements of the subject matter of the invention can be found in the subclaims.
According to a preferred development, the open key is generated by a second crypto function from a first secret key and a second secret key.
According to a further preferred development, the secret identity is generated by a third crypto function from the open identity and the second secret key.
According to a further preferred development, the first secret key is stored in the test device and the secret identity is generated in the test device by the following steps: generation of the second secret key by the inverse of the second crypto function from the first secret key and the open key; and the third crypto function generates the secret identity from the open identity and the generated second secret key.
According to a further preferred development, the open key is sent to the test device via the Internet.
According to a further preferred development, a second parameter is generated in the physical unit; sending the second parameter to the test device; and generating the electronic signature and the corresponding electronic signature from the secret identity and the first and second parameters.
According to a further preferred development, the first and the second parameters are linked by an exclusive OR function.
According to a further preferred development, the first and the second parameters are multiplexed and then linked by an exclusive OR function, there being a feedback from the output of the first crypto function to the exclusive OR function. Such a non-linear function additionally increases security.
According to a further preferred development, the first and / or second parameters are provided as random variables.
According to a further preferred development, the telecommunications network is a mobile telephone system.
According to a further preferred development, the first, second and third crypto functions are the same function.
According to a further preferred development, the same function is a standard function.
According to a further preferred development, steps e) and f) are carried out on a smart card in the test facility.
DRAWINGS
Embodiments of the invention are shown in the drawings and explained in more detail in the following description.
Show it:<dl id="dl0001"><dt>Fig. 1</dt><dd>a schematic representation of the participants and the system structure in a first embodiment of the method according to the invention;</dd><dt>Fig. 2</dt><dd>a schematic representation of the participants and a special system structure in the first embodiment of the method according to the invention;</dd><dt>Fig. 3</dt><dd>the basic principle of the first embodiment of the method according to the invention;</dd><dt>Fig. 4</dt><dd>the initialization procedure INI in the first embodiment of the present invention;</dd><dt>Fig. 5</dt><dd>the identity module on the mobile phone side and its function in the first embodiment of the present invention;</dd><dt>Fig. 6</dt><dd>the smard card on the tester side and its function in the first embodiment of the present invention;</dd><dt>Fig. 7</dt><dd>a schematic representation of a known identification mechanism of a mobile phone to a network operator; and</dd><dt>Fig. 8</dt><dd>is a schematic representation of another known identification mechanism of a mobile phone against a network operator according to the Challenge & Response technology.</dd></dl>
DESCRIPTION OF THE EMBODIMENTS
In the figures, identical reference symbols designate identical or functionally identical components.
<figref idref="f0001">Fig. 1</figref> shows a schematic representation of the participants and the general system structure in a first embodiment of the method according to the invention.
The identities for the system participants are generated by many identity generators (identity holders). The number of identity generators after<figref idref="f0001">Figure 1</figref> is n (natural number), so the identity generators are IG<sub>1</sub>, IG<sub>2</sub> ... IG<sub>n</sub>. G1, G2 denote different groups for the identity generator IG<sub>1</sub>.
The number of identity checkers is m (natural number), so the identity checkers are IP<sub>1</sub> ... IP<sub>m</sub>. Odin<figref idref="f0001">Fig. 1</figref> denotes an open directory with SC1, ..., SCn as n feri available smart cards.
<figref idref="f0001">Fig. 2</figref> shows a schematic representation of the participants and a special system structure in the first embodiment of the inventive method.
This is a mobile phone system with n mobile phone manufacturers as identity generators M<sub>1</sub> ... M<sub>n</sub> for individual identifications IMEI1, IMEI2, etc. In the system there are m identity checkers as service providers OP<sub>1</sub> ... OP<sub>m</sub>. It is pointed out here that the identity cannot only be generated and checked by the manufacturer, but also by other Auth sources, such as an authority or other system administrators.
Any service provider OP<sub>1</sub> ... OP<sub>m</sub> and / or system monitor or administrator should be able to check the authenticity of a radio telephone, called IMEI (International Mobile Equipment Identity), without large data storage.
Authenticity here means that these devices actually come from the manufacturer and that the manufacturer has awarded the IMEI, which means indirectly that the manufacturer is responsible for the quality of the device and its technical characteristics when leaving the factory.
<figref idref="f0002">Fig. 3</figref> shows the basic principle of the first embodiment of the method according to the invention.
This embodiment allows any service provider OP<sub>1</sub> ... OP<sub>m</sub> or each authority or third party to check the authenticity of the identity for each device M in the network without seeing the mobile phone or device. The verifier P also does not need to be contacted by the manufacturer and does not need a list of serial or IMEI numbers and their individual secret keys. The verifier P only needs an electronic card or Smard-Card MSC from the manufacturer (or from the identity provider / holder), and only needs an open directory OR of the manufacturer (e.g. B. Internet). Each manufacturer offers a smart card for each examiner P. These smart cards MSC are to be regarded as part of the open directory OR, as in<figref idref="f0002">Figure 3</figref> is shown.
The identification method according to this embodiment basically works as follows: The identity transmitter initializes the mobile telephone M in a pre-procedure INI carried out by a certification area CC by providing it with a secret identity SIMEI, which is stored in a writable but unreadable memory in the identification module 2 'of the device M. Furthermore, the identification module 2 'is given the ability to process a predetermined identification procedure upon request. The identification module 2 'should be a vital component of the device M, which means that removal or replacement of the identification module 2' leads to a loss of function. Furthermore, the device M is provided with an openly transferable identity IMEI, which is stored in a non-volatile memory of the device M that cannot be modified after the first description.
The checker P requests the identity of the mobile telephone M by means of an identity request (IR), with which a parameter CHv is transmitted.
The mobile phone M then sends its identity IMEI together with an electronic signature SIGt of the identity provider (manufacturer) and another parameter CHt to the verifier P.
The examiner P asks for a manufacturer verification key EMIGK from the open directory OR on the Internet.
The inspector P is convinced of the manufacturer's signature by the manufacturer's smart card MSC and decides whether the identity is genuine or not; To do this, he creates a corresponding electronic signature SIGv using the parameters IMEI, CHv, CHt and EMIGK and compares this with the transmitted electronic signature SIGt. If both electronic signatures SIGt and SIGv match, the identity is genuine, otherwise not.
The system processes and mechanisms are described in detail below using <figref idref="f0002 f0003">4 to 6</figref> explained.
<figref idref="f0002">Fig. 4</figref> Fig. 10 shows the initialization procedure INI in the first embodiment of the present invention.
The manufacturer / identity provider assigns the identity IMEI for his device M as an addition to the serial number according to the procedure agreed in the standard.
In the device M, the manufacturer writes the first secret identity SIMEI in a protected register, which the manufacturer generates using his own secret manufacturer key MIGK (Master Identity Generator Key). A one-way image F1 generates the first secret identity SIMEI from the identity IMEI and the manufacturer key MIGK:<maths id="math0001" num="(1)"><math display="block"><mi>SIMEI</mi><mo>=</mo><mi mathvariant="normal">F</mi><mn>1</mn><mspace width="1ex" /><mfenced separators=""><mi>IMEI</mi><mo>,</mo><mspace width="1ex" /><mi>MIGK</mi></mfenced></math><img file="EP1290905B1_D0001.tif" /></maths>
Each manufacturer can provide one or more such MIGK keys for each device group.
The manufacturer publishes a public key EMIGK on its open internet homepage OMHP. EMIGK is an encrypted image of the manufacturer key MIGK using the function F2 where:<maths id="math0002" num="(2)"><math display="block"><mi>EMIGK</mi><mo>=</mo><mi mathvariant="normal">F</mi><mn>2</mn><mspace width="1ex" /><mfenced separators=""><mi>MIGK</mi><mo>,</mo><mspace width="1ex" /><mi>SMMK</mi></mfenced></math><img file="EP1290905B1_D0002.tif" /></maths>
SMMK (Secret Manufacturer Master-Key) is the manufacturer's main secret key. The manufacturer can provide such an entry for each device type or use a single entry for all manufacturer types.
The manufacturer keeps the two keys SMMK and MIGK secret. However, the manufacturer supplies the smart card MSC to the verifier P (s), which contains SMMK in a protected and unreadable register (cf.<figref idref="f0003">Figure 6</figref>) and the inverse function to F2, i.e. F2<sup>-1</sup>, contains, which can generate the manufacturer key MIGK from SMMK and EMIGK.
All interim results in the smart card MSC (<figref idref="f0003">Fig. 6</figref>) and in the identification module 2 '(<figref idref="f0003">Fig. 5</figref>) cannot be reached physically (ie neither for writing nor for reading). This should be ensured during manufacture.
For security reasons, the manufacturer can manufacture the MSC smart card himself in order to meet the above conditions or obtain it from a trustworthy third party.
<figref idref="f0003">Fig. 5</figref> shows the identity module on the side of the mobile phone and its function in the first embodiment of the present invention.
The tester P, for example the network operator or the authority, asks the device M for its identity in the request IR and requests a signature for the supplied random value CHv.
The device M generates in its identity module 2 'the electronic signature SIGt as a function of the first secret identity SIMEI and CHv and a new random value CHt, which is generated by the device M, by means of the crypto function F3: <maths id="math0003" num="(3)"><math display="block"><mi>SIGt</mi><mo>=</mo><mi mathvariant="normal">F</mi><mn>3</mn><mspace width="1ex" /><mfenced separators=""><mi>SIMEI</mi><mo>,</mo><mspace width="1ex" /><mi>CHv</mi><mo>,</mo><mspace width="1ex" /><mi>CHt</mi></mfenced></math><img file="EP1290905B1_D0003.tif" /></maths>
The electronic signature SIGt is sent together with CHt and IMEI to the verifier P as a certified identity, as in <figref idref="f0002">Figure 3</figref> is shown. CHv is already available at examiner P because it was generated there.
The verifier P calculates the corresponding electronic signature SIGv from IMEI, CHt, CHv using the same crypto function F3: <maths id="math0004" num="(4)"><math display="block"><mi>SIGv</mi><mo>=</mo><mi mathvariant="normal">F</mi><mn>3</mn><mspace width="1ex" /><mfenced separators=""><mi>IMEI</mi><mo>,</mo><mspace width="1ex" /><mi>CHv</mi><mo>,</mo><mspace width="1ex" /><mi>CHt</mi></mfenced></math><img file="EP1290905B1_D0004.tif" /></maths> If SIGt = SIGv, then IMEI is considered authentic.
A protected area is set up in the device M, which contains a non-readable register with SIMEI and the cryptographic mapping F3 and a register with IMEI, which is preferably not modifiable. For this purpose, the device M contains a random generator CHt. All these units are integrated together in a protected physical unit, here in the identity module 2 ', as in<figref idref="f0003">Figure 5</figref> shown. The following steps are carried out to generate the electronic signature SIGt of the device M: A random value CHt is newly generated.
CHv and CHt are linked together with SIMEI by the crypto one-way function F3. For example, CHt XOR CHv can first be generated and then mapped using F3 with SIMEI as key, as in '<figref idref="f0003">Figure 5</figref> is shown. It is also possible, as in<figref idref="f0003">Figure 5</figref> shown to multiplex CHv and CHt (multiplexer control not shown) and then feed it to the XOR (+), with feedback from the output of F3 to the XOR (+).
The device M then delivers the following test vector tuple to the tester as a testable identity vector: <maths id="math0005" num=""><math display="block"><mi>Check vector</mi><mo>=</mo><mfenced separators=""><mi>IMEI</mi><mo>,</mo><mspace width="1ex" /><mi>SIGt</mi><mo>,</mo><mspace width="1ex" /><mi>CHt</mi><mo>,</mo><mspace width="1ex" /><mi>CHv</mi></mfenced></math><img file="EP1290905B1_D0005.tif" /></maths>
The IMEI identity, which is considered an open identity, makes the device type and manufacturer known. The inspector P can then easily pick up the associated open test bowl EMIGK from the Internet from the manufacturer's open directory OR. Alternatively, the examiner could maintain a list from the manufacturer and update it from time to time to save access on the Internet and only go to the manufacturer's Internet directory if the manufacturer offers new types.
<figref idref="f0003">Fig. 6</figref> shows the smard card on the side of the examiner and its function in the first embodiment of the present invention.
The verifier P receives the test vector from the mobile telephone M and checks whether the signature SIGt proves the identity of the device, that is to say SIGv = SIGt applies. The inspector P then has proof that the IMEI claimed by the device M actually comes from the manufacturer. For this purpose, the smart card MSC from the manufacturer is necessary, which should be available for every examiner P. This smart card MSC after<figref idref="f0003">Figure 6</figref> contains all three figures F1, F2<sup>-1</sup> and F3 as well as a protected, once writable register with the secret key SMMK, as manufacturer / identity provider master secret key (Secret Manufacturer Master Key). As mentioned, SMMK is written into the smart card MSC by the manufacturer / identity holder. SMMK is physically unreadable. The protected keys also meet the following rules:<ol id="ol0001" ol-style=""><li>1. They are not physically legible, preferably even when the device is opened desturatively.</li><li>2nd They can only be overwritten if the writer knows the current content.</li></ol>
The examiner P feeds the test vector to the smart card MSC and carries out the following operations: The tester P fetches the manufacturer's test key EMIGK from the Internet after receiving the IMEI or type of the device and the name of the manufacturer from the device M.
The examiner P enters the received components of the test vector together with EMIGK into the smart card MSC. The MSC smart card first decrypts EMIGK using the SMMK key and the decrypted function F2<sup>-1</sup>. This results in the manufacturer / identity provider master secret key MIGK. The hardware and software of the MSC smart card must not make it possible to read MIGK.
The first secret identity SIMEI is then generated. This is done by using MIGK and IMEI via function F1, like<figref idref="f0003">Figure 6</figref> shows. The hardware and software of the MSC smart card, in turn, must not enable SIMEI to be read.
SIMEI is linked internally with the two random variables CHt, CHv via the function F3 in the same way as in the smart card MSC in order to obtain the electronic signature SIGv.
If SIGv = SIGt, then the identity IMEI is considered genuine and the identity of the device is accepted, otherwise the identification has failed.
Although the present invention has been described above on the basis of a preferred exemplary embodiment, it is not restricted to this but can be modified in a variety of ways.
The standardized crypto function in the mobile phone system can be used for the figures F1, F2 and F3. In this case F1 = F2 = F3 = SF (standard function) is assumed.
This simplifies the structure of the MSC smart card, since such smart cards already exist in the system, manufacturers can use them. Since SF is also available in the mobile phone, the result is an extremely effective implementation.
Contents4
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office |
|---|---|---|
| EP0800293A | Cites | European Patent Office (EPO) |
| WO0001187A | Cites | World Intellectual Property Organization (WIPO) |
14 members in 5 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 10026326 | Germany | A | |
| 10026326 | Germany | – | |
| 0101180 | Germany | W | |
| 10026326 | – | – | – |
| DE2000126326 | – | – | – |
| DE2001001180 | – | – | – |
| WO2001DE01180 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| DE10026326A1 | Germany | A1 | |
| WO0191478A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0191478A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1290905A2 | European Patent Office (EPO) | A2 | |
| JP2003535497A | Japan | A | |
| US2004111616A1 | United States of America | A1 | |
| JP4819286B2 | Japan | B2 | |
| US8271787B2 | United States of America | B2 | |
| US2013072159A1 | United States of America | A1 | |
| US8638933B2 | United States of America | B2 | |
| US2014235207A1 | United States of America | A1 | |
| US9100827B2 | United States of America | B2 | |
| DE10026326B4 | Germany | B4 | |
| EP1290905B1This record | European Patent Office (EPO) | B1 |
32 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04Q0007380000R079 | R079 | DE | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1290905
- Publication, DOCDB
- 1290905
- Publication, EPODOC
- EP1290905
- Application
- 19292697
- Application, DOCDB
- 01929269
- Application, EPODOC
- EP20010929269
Titles3
- German
- VERFAHREN ZUR KRYPTOGRAFISCHEN IDENTIFIKATION EINER PHYSIKALISCHEN EINHEIT IN EINEM DRAHTLOSEN TELEKOMMUNIKATIONSNETZWERK
- English
- METHOD FOR THE CRYPTOGRAPHICALLY VERIFIABLE IDENTIFICATION OF A PHYSICAL UNIT IN A PUBLIC, WIRELESS TELECOMMUNICATIONS NETWORK
- French
- PROCEDE D'IDENTIFICATION CONTROLABLE PAR CRYPTOGRAPHIE D'UNE UNITE PHYSIQUE DANS UN RESEAU DE TELECOMMUNICATION OUVERT SANS FIL
Classification
- CPC, 8
- H04W12/06
- H04L9/3247
- H04L9/3271
- H04L63/126
- H04L2209/26
- H04L2209/80
- H04W12/00518
- H04W12/04
- IPC, 5
- H04L9 32
- H04W12 04
- H04L9 08
- H04W12 02
- H04W12 06
Designated states4
- Contracting states, 4
- Germany
- France
- United Kingdom
- Italy
