Authentication in telecommunications networks
Abstract
A method of making a call-connection of a user terminal to a second network comprises providing authentication data to the uscr terminal via an authenticated call-connection with a first network. It also requires selectively allowing call-connection to the second network dependent on said authentication data.

Term
Term ended
Projected expiry passed 12 November 2021, 4.9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
10 claims: 2 independent, 8 dependent
- 1A method of making a call-connection of a user terminal to a second network comprising the steps of providing authentication data to the user terminal via an authenticated call-connection with a first network, and selectively allowing call-connection to the second network dependent on said authentication data.
- 10A telecommunications system comprising a first network and a second network, and at least one user terminal call-connectable to either network, the terminal being operative in authenticated call-connection with the first network to receive authentication data, the second network comprising means operative to selectively allow call-connection to the second network dependent on said authentication data.
Independent claims2
31 paragraphs, as filed
<u>Technical Field</u>
0001The present invention relates to a method of making a call-connection, and to a telecommunications system.
<u>Background of the Invention</u>
0002When a user wishes to use a commercial communications network, the network must authenticate the user (i.e. it must be convinced that they are who they claim to be), so that the bill can be assigned to the correct person. This is especially true of networks where there is no physical connection to the user (e.g. cellular and wireless networks).
0003Authentication (proving to the network that you are who you are) is very important to wireless network operators as it allows them to bill users, and to prevent non-subscribers from accessing the system. Such authentication is normally carried out when the user connects to the network.
0004Encryption is important to users for security reasons, but has an additional advantage to the operator in that it prevents a third party from taking over an already authenticated connection. So encryption provides continuing authentication, which again is important for billing.
0005In general, for a user to authenticate themselves to the network, they must be in possession of some sort of secret key (e.g. a password, or the SIM card in a mobile phone) that only themselves and the network have access to.
0006In existing cellular networks such as Global System for Mobiles GSM and Universal Mobile Telecommunications System UMTS authentication is achieved by a subscriber identity module SIM card in the mobile knowing an individual secret code only known to it and the core of the cellular network. The secret code allows the mobile to respond correctly to authentication challenges, and to set encryption keys correctly for the call-connection. The user does not have access to the secret code itself as it is hidden inside the SIM. For example, in GSM, the network sends a random value to the phone. The SIM card then uses this value, along with the secret key to generate a response, and an encryption key to encrypt further communications. The network generates these values in the same way, and for communication to continue, the returned response must be correct, and the data must be encrypted in the correct way. In reality, it is often possession of the encryption key that is important in authenticating the user, the secret key simply being a way of generating an encryption key in a secure manner.
0007On the other hand in existing data networks (including wireless data networks), authentication is at best similar to that used in cellular networks. However, the secret code is normally input by the user, rather than being hidden from them. This is a less secure solution, and more difficult to administer.
0008Many cellular operators wish to provide a service where the user can make use of either cellular, or wireless data networking techniques such as IEEE specification for wireless LAN 802.1 1b. However, the poorer security of wireless data networks compared to cellular networks is unattractive, and the need for the user to manually administer additional secrets for data access is unattractive.
<u>Summary of the Invention</u>
0009The present invention provides a method of making a call-connection of a user terminal to a second network comprising the steps of providing authentication data to the user terminal via an authenticated call-connection with a first network, and selectively allowing call-connection to the second network dependent on said authentication data.
0010Advantages of the present invention in its preferred embodiments are that using a connection over an authenticated network to pass proof of identity for authentication on another network or networks is a simple but powerful technique. The presence of an existing authenticated connection is readily useable to authenticate the user for an additional network. By passing encryption keys, or authentication secrets, for the additional network over the existing network, unauthorised users can be prevented from accessing the additional network. Also the resulting security levels achieved for wireless LAN networks can be as good as for cellular networks.
0011Preferably the allowing is undertaken by the second network. Preferably the authentication data is also provided to the second network by another path for comparison with the authentication data received from the terminal.
0012Preferably the authentication data comprises a secret key code.
0013Preferably the authentication data comprises an encryption key code for encrypting call messages.
0014Preferably the authentication data is periodically updated. Furthermore preferably authentication for the additional network is automatic, and preferably does not require manual intervention.
0015Preferably the first network is a mobile telecommunications network. For example a Global System for Mobiles GSM network, a Universal Mobile Telecommunications System UMTS network, or other third generation mobile network.
0016Preferably the second network is a wireless local area network LAN, such as in accordance with IEEE Specification for wireless Local Area Networks 802.11b.
0017Preferably upon the call-connection to the second network being made, the user terminal remains in simultaneous call-connection with both the first network and the second network. Alternatively, the call-connection to the first network is terminated upon the call-connection to the second network being made.
0018The present invention also relates to corresponding apparatus.
0019The present invention also provides a telecommunications system comprising a first network and a second network, and at least one user terminal call-connectable to either network, the terminal being operative in authenticated call-connection with the first network to receive authentication data, the second network comprising means operative to selectively allow call-connection to the second network dependent on said authentication data.
0020Preferably the system further comprising an authentication server operative to provide the authentication data to the terminal.
<u>Brief Description of the Drawings</u>
0021A preferred embodiment of the present invention will now be described by way of example and with reference to the drawings, in which: <ul id="ul0001" list-style="none" compact="compact"><li>Figure 1 is a diagrammatic illustration of a terminal connected to two networks.</li></ul>
<u>Detailed Description</u>
0022As shown in Figure 1, a terminal 1 is provided that has the capability to connect via respective interfaces 2,3 to two networks, either simultaneously, or by alternating. The networks are denoted (a) and (b) respectively. Network (a) is a Global System for Mobiles GSM network. Network (b) is Wireless Local Area Network LAN.
0023In operation, the terminal 1 is initially connected to network (a), and that network (a) uses authentication and encryption to provide a secure data path 4. The terminal uses this secure data path 4 to download security information that will allow it to establish a connection using network (b). This information could be for example a secret key, password, or encryption key.
0024The following sequence of steps take place:- <ul id="ul0002" list-style="none" compact="compact"><li>(1) The terminal 1 sets up a secure, authenticated, encrypted data connection over network (a).</li><li>(2) The terminal 1 uses that connection to communicate with an authentication server(not shown) which resides in network (a), and is given a secret key to use when establishing a connection over network (b).</li><li>(3) The authentication server informs network (b) of the secret key to be used by the terminal 1. This is important as both network (b) and the terminal 1 must have the same secret key in order to set-up a connection.</li><li>(4) The terminal 1 decides to make use of network (b). This is triggered in various ways such as user initiated or caused by the movement of the terminal 1 into an area covered by network (b).</li><li>(5) The terminal 1 authenticates itself to network (b) and sets up an encryption key using whatever method is in use on network (b). The important factor is that it is only possession of the correct secret key that allows the terminal to calculate the correct security responses, and to generate the correct encryption key to use.</li><li>(6) The terminal 1 now has a secure, authenticated, encrypted connection over network (b).</li></ul>
0025In an alternative embodiment, the authentication server in network (a) queries network (b) for the secret key to use rather than simply instructing network (b) of the secret key to use.
0026In some embodiments the networks are of the same type whereas in other embodiments they are different. The networks can be fixed, or mobile such as cellular networks or wireless local area networks.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP1811719A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US8638765B2 | Cited by | United States of America | – | Applicant | – |
| WO2012123145A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO2006039943A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| EP2007160A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| WO2007099295A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| GB2411086B | Cited by | United Kingdom | – | Search report | – |
| WO2007099295A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO2007038781A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| EP1672945A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP2498538A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP1850203A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US7653037B2 | Cited by | United States of America | – | Applicant | – |
| US9313727B2 | Cited by | United States of America | – | Applicant | – |
| GB2411086A | Cited by | United Kingdom | – | Search report | – |
| US11032694B2 | Cited by | United States of America | – | Applicant | – |
| US8160035B2 | Cited by | United States of America | – | Applicant | – |
| WO0076194A1 | Cites | World Intellectual Property Organization (WIPO) | XY | Search report | 1-8,10 |
| US5608723A | Cites | United States of America | X | Search report | 1-6,10 |
| US5649308A | Cites | United States of America | Y | Search report | 9 |
1 member in 1 office; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 01309529 | European Patent Office (EPO) | A | |
| EP20010309529 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| EP1311136A1This record | European Patent Office (EPO) | A1 |
7 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | EP | |
| Designated country de not longer valid8566 | 8566 | DE | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1311136
- Publication, DOCDB
- 1311136
- Publication, EPODOC
- EP1311136
- Application
- 1309529
- Application, DOCDB
- 01309529
- Application, EPODOC
- EP20010309529
Titles3
- German
- Authentifizierung in Telekommunikationsnetzwerken
- English
- Authentication in telecommunications networks
- French
- Authentification dans des réseaux de télécommunication
Classification
- CPC, 6
- H04W12/06
- H04L63/18
- H04W84/042
- H04W12/04031
- H04W84/12
- H04W88/06
- IPC, 6
- H04L12 28
- H04W12 00
- H04W12 06
- H04W84 04
- H04W84 12
- H04W88 06
Designated states26
- Contracting states, 20
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia