EP1362452B1

Method and apparatus for providing authentication in a communication system

Abstract

This record has no abstract on file.

EP1362452B1, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Expired 18 January 2022, 4.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

48 claims: 35 independent, 13 dependent

  1. 1
    A method comprising the steps of:generating a random number, an expected response, and a derived cipher key associated with securing air interface communications with a mobile station (401, 403, 405) ;forwarding the random number and a random seed to a base station (115, 117) that is located in a first pool of devices, wherein the first pool is associated with an intrakey used for encrypting key material that is distributed within the first pool;receiving, from the base station (115, 117), a response to the random number and the random seed;comparing the response and the expected response;andwhen the response matches the expected response, encrypting the derived cipher key using the intrakey and forwarding the encrypted derived cipher key to the base station (115, 117). Procédé comprenant les étapes consistant à: générer un nombre aléatoire, une réponse attendue, et une clé de chiffre dérivée associée à la sécurisation de communications à interface radio avec une station mobile (401, 403, 405);acheminer le nombre aléatoire et une semence aléatoire vers une station de base (115, 117) qui est située dans un premier regroupement de dispositifs, dans lequel le premier regroupement est associé à une intra-clé utilisée pour chiffrer un matériau de clé qui est distribué au sein du premier regroupement;recevoir, à partir de la station de base (115, 117), une réponse au nombre aléatoire et à la semence aléatoire;comparer la réponse et la réponse attendue;etlorsque la réponse concorde avec la réponse attendue, chiffrer la clé de chiffre dérivée en utilisant une intra-clé et acheminer la clé de chiffre dérivée chiffrée à la station de base (115, 117). Verfahren, welches die folgenden Schritte aufweist: Erzeugung einer Zufallszahl, einer erwarteten Antwort und eines abgeleiteten Codierungsschlüssels, welcher in Zusammenhang mit der Sicherstellung von kabelloser Schnittstellenkommunikation mit einer Mobilstation (401, 403, 405) steht;Weiterleitung der Zufallszahl und eines zufälligen Seeds an eine Basisstation (115, 117), welche sich in einem ersten Vorrichtungspool befindet, dadurch gekennzeichnet, dass der erste Pool in Zusammenhang mit einem internen Schlüssel bzw. einem Intrakey steht, welcher zur Codierung von Schlüsselmaterial verwendet wird, das innerhalb des ersten Pools verteilt wird;Empfang einer Antwort auf die Zufallszahl und des zufälligen Seeds von der Basisstation (115, 117);Vergleich der Antwort mit der erwarteten Antwort;undbei Übereinstimmung der Antwort mit der erwarteten Antwort, Codierung des abgeleiteten Codierungsschlüssels unter Verwendung des internen Schlüssels und Weiterleitung des codierten abgeleiteten Codierungsschlüssels an die Basisstation (115, 117).
  2. 2
    Procédé selon la revendication 1, comprenant l'étape consistant à, lorsque la réponse ne concorde pas avec la réponse attendue, rejeter la clé de chiffre dérivée sans acheminer la clé de chiffre dérivée à la station de base (115, 117) . The method of claim 1, further comprising the step of, when the response does not match the expected response, discarding the derived cipher key without forwarding the derived cipher key to the base station (115, 117). Verfahren nach Anspruch 1, welches des Weiteren den folgenden Schritt aufweist:bei Nichtübereinstimmung der Antwort mit der erwarteten Antwort, Entfernung des abgeleiteten Codierungsschlüssels ohne Weiterleitung des abgeleiteten Codierungsschlüssels an die Basisstation (115, 117).
  3. 3
    Procédé selon la revendication 2, comprenant en outre l'étape consistant à envoyer un message d'identification échouée à la station de base (115, 117). The method of claim 2, further comprising the step of sending a failed authentication message to the base station (115, 117). Verfahren nach Anspruch 2, welches das Weiteren den Schritt des Sendens einer fehlgeschlagenen Authentifizierungsnachricht an die Basisstation (115, 117) aufweist.
  4. 4
    Procédé selon la revendication 1, dans lequel la réponse attendue est générée au moins indirectement à partir du nombre aléatoire et de la semence aléatoire. The method of claim 1, wherein the expected response is generated at least indirectly from the random number and the random seed. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die erwartete Antwort zumindest indirekt aus der Zufallszahl und dem zufälligen Seed erzeugt wird.
  5. 5
    Procédé selon la revendication 1, dans lequel la clé de chiffre dérivée est générée au moins indirectement à partir du nombre aléatoire et de la semence aléatoire. The method of claim 1, wherein the derived cipher key is generated at least indirectly from the random number and the random seed. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der abgeleitete Codierungsschlüssel zumindest indirekt aus der Zufallszahl und dem zufälligen Seed erzeugt wird.
  6. 6
    Procédé selon la revendication 1, dans lequel la clé de chiffre dérivée est stockée au niveau d'un enregistreur de localisation visité ou au niveau d'un emplacement nominal. The method of claim 1, wherein the derived cipher key is stored at a visited location register or at a home location. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der abgeleitete Codierungsschlüssel in einem Aufenthaltsregister (visited location register) oder einem Heimatregister (Home Location) gespeichert ist.
  7. 7
    Procédé selon la revendication 1, dans lequel la clé de chiffre dérivée est chiffrée par une intra-clé et stockée au niveau d'un enregistreur de localisation visité ou au niveau d'un enregistreur de localisation nominal. The method of claim 1, wherein the derived cipher key is encrypted by an intrakey and stored at a visited location register or at a home location register. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der abgeleitete Codierungsschlüssel mit einem internen Schlüssel codiert und in einem Aufenthaltsregister oder einem Heimatregister gespeichert ist.
  8. 8
    Procédé selon la revendication 1, dans lequel les étapes sont effectuées par une unité de commande de zone (107, 121) ou un enregistreur de localisation visité. The method of claim 1, wherein the steps are performed by a zone controller (107, 121) or a visited location register. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die Schritte von einer Bereichssteuerungsvorrichtung (107, 121) oder einem Aufenthaltsregister durchgeführt werden.
  9. 9
    Procédé selon la revendication 1, comprenant en outre les étapes consistant à:recevoir, à partir de la station de base (115, 117), un second nombre aléatoire généré par une station mobile (401, 403, 405);générer une deuxième clé de chiffre dérivée et une seconde réponse au second nombre aléatoire et acheminer la seconde réponse vers la station de base (115, 117);combiner la clé de chiffre dérivée et la deuxième clé de chiffre dérivée, donnant une troisième clé de chiffre dérivée;lorsqu'un message d'authentification positif est reçu à partir de la station de base (115, 117), acheminer la troisième clé de chiffre dérivée vers la station de base (115, 117). The method of claim 1, further comprising the steps of: receiving, from the base station (115, 117), a second random number generated by a mobile station (401, 403, 405);generating a second derived cipher key and a second response to the second random number and forwarding the second response to the base station (115, 117);combining the derived cipher key and the second derived cipher key, yielding a third derived cipher key;when a positive authentication message is received from the base station (115, 117), forwarding the third derived cipher key to the base station (115, 117). Verfahren nach Anspruch 1, welches des Weiteren folgende Schritte aufweist: Empfang einer zweiten Zufallszahl von der Basisstation (115, 117), welche von einer Mobilstation (401, 403, 405) erzeugt wird;Erzeugung eines zweiten abgeleiteten Codierungsschlüssels und einer zweiten Antwort auf die zweite Zufallszahl, und Weiterleitung der zweiten Antwort an die Basisstation (115, 117);Kombinieren des abgeleiteten Codierungsschlüssels und des zweiten abgeleiteten Codierungsschlüssels, Liefern eines dritten abgeleiteten Codierungsschlüssels;bei Empfang einer positiven Authentifizierungsnachricht von der Basisstation (115, 117), Weiterleitung des dritten abgeleiteten Codierungsschlüssels an die Basisstation (115, 117).
  10. 10
    A method performed by any of a base station (115, 117) that is located in a first pool of devices and comprising the steps of:receiving an authentication request from a mobile station (401, 403, 405);determining whether to forward the request to an authentication agent;when it is determined to forward the request, forwarding the request to the authentication agent;receiving a random number and a random seed from the authentication agent;forwarding the random number and the random seed to the mobile station (401, 403, 405);receiving a response to the random number and the random seed from the mobile station (401, 403, 405) and forwarding the response to the authentication agent;when the authentication agent authenticates the mobile station (401, 403, 405), receiving from the authentication agent a derived cipher key that is encrypted using an intrakey associated with the first pool and used for encrypting key material that is distributed within the first pool;andencrypting messages to the mobile station (401, 403, 405) and decrypting messages from the mobile station (401, 403, 405) with the derived cipher key. Procédé effectué par l'une quelconque parmi une station de base (115, 117) qui est située dans un premier regroupement de dispositifs et comprenant les étapes consistant à: recevoir une demande d'authentification à partir d'une station mobile (401, 403, 405);déterminer s'il faut ou non acheminer la demande à un agent d'authentification;lorsqu'il est déterminé d'acheminer la demande, acheminer la demande à l'agent d'authentification;recevoir un nombre aléatoire et une semence aléatoire à partir de l'agent d'authentification;acheminer le nombre aléatoire et la semence aléatoire vers la station mobile (401, 403, 405);recevoir une réponse au nombre aléatoire et à la semence aléatoire à partir de la station mobile (401, 403, 405) et acheminer la réponse vers l'agent d'authentification;lorsque l'agent d'authentification authentifie la station mobile (401, 403, 405), recevoir de l'agent d'authentification une clé de chiffre dérivée qui est chiffrée en utilisant une intra-clé associée au premier regroupement et utilisée pour chiffrer le matériau de clé qui est distribué au sein du premier regroupement;etchiffrer des messages vers la station mobile (401, 403, 405) et déchiffrer les messages à partir de la station mobile (401, 403, 405) avec la clé de chiffre dérivée. Verfahren, welches von jeder beliebigen der Basisstation (115, 117) durchgeführt wird, die sich in einem ersten Vorrichtungspool befindet, wobei das Verfahren die folgenden Schritte aufweist: Empfang einer Authentifizierungsanfrage von einer Mobilstation (401, 403, 405);Bestimmen, ob die Anfrage an einen Authentifizierungsagent weitergeleitet werden soll;Bei Bestimmung, dass die Anfrage weitergeleitet werden soll, Weiterleitung der Anfrage an den AuthentifizierungsagentEmpfang einer Zufallszahl und eines zufälligen Seeds von dem Authentifizierungsagent;Weiterleitung der Zufallszahl und des zufälligen Seeds an die Mobilstation (401, 403, 405);Empfang einer Antwort auf die Zufallszahl und des zufälligen Seed von der Mobilstation (401, 403, 405) und Weiterleitung der Antwort an den Authentifizierungsagent;bei Authentifizierung der Mobilstation (401, 403, 405) durch den Authentifizierungsagent, Empfang eines abgeleiteten Codierungsschlüssels von dem Authentifizierungsagent, wobei der Codierungsschlüssel unter Verwendung eines internen Schlüssels codiert wird, der in Zusammenhang mit dem ersten Pool steht und zur Codierung von Schlüsselmaterial verwendet wird, welches in dem ersten Pool verteilt wird;undCodierung von Nachrichten an die Mobilstation (401, 403, 405) und Decodierung von Nachrichten von der Mobilstation (401, 403, 405) mit dem abgeleiteten Codierungsschlüssel.
  11. 11
    Procédé selon la revendication 10, comprenant en outre l'étape consistant à, lorsque l'agent d'authentification envoie une authentification négative à la station de base (115, 117), acheminer l'authentification négative à la station mobile (401, 403, 405). The method of claim 10, further comprising the step of, when the authentication agent sends a negative authentication to the base station (115, 117), forwarding the negative authentication to the mobile station (401, 403, 405). Verfahren nach Anspruch 10, welches das Weiteren folgenden Schritt aufweist:Bei Senden einer negativen Authentifizierung durch den Authentifizierungsagent an die Basisstation (115, 117), Weiterleitung der negativen Authentifizierung an die Mobilstation (401, 403, 405).
  12. 12
    Procédé selon la revendication 10, dans lequel l'agent d'authentification est une unité de commande de zone (107, 121) ou un enregistreur de localisation visité. The method of claim 10, wherein the authentication agent is a zone controller (107, 121) or a visited location register. Verfahren nach Anspruch 10, dadurch gekennzeichnet, dass es sich bei dem Authentifizierungsagent um eine Bereichssteuerungsvorrichtung (107, 112) oder ein Aufenthaltsregister handelt.
  13. 13
    Procédé selon la revendication 10, dans lequel la station de base (115, 117) est située dans une zone et dans lequel la clé de chiffre dérivée est chiffrée par une intra-clé lorsqu'elle est transférée au sein de la zone avant d'être acheminée vers la station de base. The method of claim 10, wherein the base station (115, 117) is located in a zone and wherein the derived cipher key is encrypted by an intrakey when transferred within the zone before being forwarded to the base station. Verfahren nach Anspruch 10, dadurch gekennzeichnet, dass sich die Basisstation (115, 117) in einem Bereich befindet, und dass der abgeleitete Codierungsschlüssel mit einem internen Schlüssel codiert wird, wenn er vor Weiterleitung an die Basisstation innerhalb des Bereichs übertragen wird.
  14. 14
    Procédé selon la revendication 10, dans lequel l'un quelconque d'un site de base et d'une unité de commande de site TETRA prend la place de la station de base (115, 117). The method of claim 10, wherein any of a base site and a TETRA site controller takes the place of the base station (115, 117). Verfahren nach Anspruch 10, dadurch gekennzeichnet, dass jede beliebige der Basisstandorte und eine TETRA-Standortssteuervorrichtung den Platz der Basisstation (115, 117) einnimmt.
  15. 15
    A method performed by a base station that is located in a first pool of devices and comprising the steps of:receiving a random number from a mobile station;forwarding the random number to an authentication agent;receiving a response to the random number and a random seed from the authentication agent;forwarding the response and the random seed to the mobile station;when the mobile station authenticates the infrastructure comprising the authentication agent and the base stations, forwarding an authenticated message to the authentication agent;receiving from the authentication agent a derived cipher key that is encrypted using an intrakey associated with the first pool and used for encrypting key material that is distributed within the first pool;encrypting messages to the mobile station and decrypting messages from the mobile station with a derived cipher key. Procédé effectué par une station de base qui est située dans un premier regroupement de dispositifs et comprenant les étapes consistant à: recevoir un nombre aléatoire d'une station mobile;acheminer le nombre aléatoire vers un agent d'authentification;recevoir une réponse au nombre aléatoire et une semence aléatoire à partir de l'agent d'authentification;acheminer la réponse et la semence aléatoire vers la station mobile;lorsque la station mobile authentifie l'infrastructure comprenant l'agent d'authentification et les stations de base, acheminer un message authentifié vers l'agent d'authentification;recevoir de l'agent d'authentification une clé de chiffre dérivée qui est chiffrée en utilisant une intra-clé associée au premier regroupement et utilisée pour chiffrer un matériau de clé qui est distribué au sein du premier regroupement;chiffrer les messages vers la station mobile et déchiffrer les messages à partir de la station mobile avec une clé de chiffre dérivée. Verfahren, welches von einer Basisstation durchgeführt wird, die sich in einem ersten Vorrichtungspool befindet und die folgenden Schritte aufweist: Empfang einer Zufallszahl von einer Basisstation;Weiterleitung der Zufallszahl an einen Authentifizierungsagent;Empfang einer Antwort auf die Zufallszahl und eines zufälligen Seeds von dem Authentifizierungsagent;Weiterleitung der Antwort und des zufälligen Seeds an die Mobilstation;bei Authentifizierung der Infrastruktur, welche den Authentifizierungsagent und die Basisstationen einschließt, durch die Mobilstation, Weiterleitung einer Authentifizierungsnachricht an den Authentifizierungsagent;Empfang eines abgeleiteten Codierungsschlüssels von dem Authentifizierungsagent, wobei der Codierungsschlüssel unter Verwendung eines internen Schlüssels codiert wird, der einen Bezug zu dem ersten Pool hat und zur Codierung von Schlüsselmaterial verwendet wird, das innerhalb des ersten Pools verteilt wird;Codierung von Nachrichten an die Mobilstation und Decodierung von Nachrichten von der Mobilstation mit einem abgeleiteten Codierungsschlüssel.
  16. 16
    Procédé selon la revendication 15, dans lequel l'agent d'authentification est une unité de commande de zone (107, 121) ou un enregistreur de localisation visité. The method of claim 15, wherein the authentication agent is a zone controller (107, 121) or a visited location register. Verfahren nach Anspruch 15, dadurch gekennzeichnet, dass es sich bei dem Authentifizierungsagent um eine Bereichssteuervorrichtung(107, 121) oder ein Aufenthaltsregister handelt.
Independent claims16