EP1536592B1

Authentication between a cellular mobile terminal and a short range access point

Abstract

This record has no abstract on file.

EP1536592B1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Expired 26 November 2023, 2.8 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

15 claims: 15 independent, 0 dependent

  1. 1
    Authentifizierungsverfahren zwischen einem drahtlosen Netz geringer Reichweite (RFP) mit Zugriffspunkten und einer Mobilstation (TM) in einem zellularen Funkverkehrsnetz (RC), dadurch gekennzeichnet, dass es die folgenden Schritte aufweist:- Übertragung (E2) einer Anfrage (RQ), die eine Adresse (ADTM) der Mobilstation und eine Adresse (ADAP) eines Zugriffspunkts (AP) enthält, der sich im Versorgungsgebiet der Mobilstation (TM) bezüglich des Netzes geringer Reichweite befindet, von der Mobilstation über das zellulare Netz (RC) zu einer Verwaltungseinrichtung (PFG),- Bestimmung (E3) eines Geheimcodes (CS) durch die Verwaltungseinrichtung,- ausgehend von der Verwaltungseinrichtung (PFG), Übertragung (E4, E5) einer Bestätigungsmitteilung (MC), die den Geheimcode und die aus der Anfrage entnommene Adresse des Zugriffspunkts enthält, an die Mobilstation über das zellulare Netz, und einer Verbindungsanforderungsmitteilung (MDC), die den Geheimcode und die aus der Anfrage entnommene Adresse der Mobilstation enthält, an den Zugriffspunkt (AP),- Anforderung (E6) einer Verbindung von der Mobilstation zu dem von der aus der Bestätigungsmitteilung (MC) entnommenen Adresse (ADAP) bezeichneten Zugriffspunkt, damit die Mobilstation (TM) und der Zugriffspunkt (AP) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und vom aus der Bestätigungsmitteilung (MC) und aus der Verbindungsanforderungsmitteilung (MDC) entnommenen Geheimcode (CS) einen Sitzungsschlüssel (KS) bestimmen, und- Authentifizierung (E7-E10) der Mobilstation (TM) durch den Zugriffspunkt (AP) in Abhängigkeit vom Sitzungsschlüssel (KS). Method of authentication between a short-range wireless network (RFP) having access points and a mobile terminal (TM) in a cellular radiocommunications network (RC), characterized in that it comprises the following steps: - transmission (E2) of a query (RQ) including an address (ADTM) of the mobile terminal and an address (ADAP) of an access point (AP) situated in the coverage zone of the mobile terminal (TM) which relates to the short-range network, from the mobile terminal to a management means (PFG) via the cellular network (RC),- determination (E3) of a secret code (CS) by the management means,- from the management means (PFG), transmission (E4, E5) of a confirmation message (MC) including the secret code and the access point address extracted from the query to the mobile terminal via the cellular network and of a connection request message (MDC) including the secret code and the mobile terminal address extracted from the query to the access point (AP),- connection request (E6) of the mobile terminal to the access point designated by the address (ADAP) extracted from the confirmation message (MC) such as the mobile terminal (TM) and the access point (AP) determine a session key (KS) as a function of the access point address (ADAP), of the mobile terminal address (ADTM) and of the secret code (CS) extracted from the confirmation message (MC) and the connection request message (MDC), and- authentication (E7-E10) of the mobile terminal (TM) by the access point (AP) as a function of the session key (KS). Procédé d'authentification entre un réseau sans fil de faible portée (RFP) ayant des points d'accès et un terminal mobile (TM) dans un réseau de radiocommunications cellulaire (RC), caractérisé en ce qu'il comprend les étapes suivantes : - transmission (E2) d'une requête (RQ) incluant une adresse (ADTM) du terminal mobile et une adresse (ADAP) d'un point d'accès (AP) situé dans la zone de couverture du terminal mobile (TM) relative au réseau de faible portée, depuis le terminal mobile à un moyen de gestion (PFG) via le réseau cellulaire (RC),- détermination (E3) d'un code secret (CS) par le moyen de gestion,- depuis le moyen de gestion (PFG), transmission (E4, E5) d'un message de confirmation (MC) incluant le code secret et l'adresse du point d'accès extraite de la requête au terminal mobile via le réseau cellulaire et d'un message de demande de connexion (MDC) incluant le code secret et l'adresse du terminal mobile extraite de la requête au point d'accès (AP),- demande (E6) de connexion du terminal mobile au point d'accès désigné par l'adresse (ADAP) extraite du message de confirmation (MC) afin que le terminal mobile (TM) et le point d'accès (AP) déterminent une clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de confirmation (MC) et du message de demande de connexion (MDC), et- authentification (E7-E10) du terminal mobile (TM) par le point d'accès (AP) en fonction de la clé de session (KS).
  2. 2
    Method in accordance with Claim 1, according to which the authentication of the mobile terminal by the access point comprises a request (E7) for determination (E8) from the access point of a response (RP1) as a function of the session key (KS) to the mobile terminal which transmits (E9) the response to the access point, via the short-range network, and in the access point (AP), a determination (E8) of a response (RP1) as a function of the session key (KS) and a comparison (E10) of the responses so as to authorize (E16) the opening of a session between the access point and the mobile terminal when at least the responses compared are identical. Procédé conforme à la revendication 1, selon lequel l'authentification du terminal mobile par le point d'accès comprend une demande (E7) de détermination (E8) depuis le point d'accès d'une réponse (RP1) en fonction de la clé de session (KS) au terminal mobile qui transmet (E9) la réponse au point d'accès, via le réseau de faible portée, et dans le point d'accès (AP), une détermination (E8) d'une réponse (RP1) en fonction de la clé de session (KS) et une comparaison (E10) des réponses pour autoriser (E16) l'ouverture d'une session entre le point d'accès et le terminal mobile lorsqu'au moins les réponses comparées sont identiques. Verfahren nach Anspruch 1, gemäß dem die Authentifizierung der Mobilstation durch den Zugriffspunkt ausgehend vom Zugriffspunkt eine Anforderung (E7) der Bestimmung (E8) einer Antwort (RP1) in Abhängigkeit vom Sitzungsschlüssel (KS) an die Mobilstation, die die Antwort über das Netz geringer Reichweite an den Zugriffspunkt überträgt (E9), und im Zugriffspunkt (AP) eine Bestimmung (E8) einer Antwort (RP1) in Abhängigkeit vom Sitzungsschlüssel (KS) und einen Vergleich (E10) der Antworten enthält, um die Eröffnung einer Sitzung zwischen dem Zugriffspunkt und der Mobilstation zu erlauben (E16), wenn mindestens die verglichenen Antworten gleich sind.
  3. 3
    Method in accordance with Claim 1 or 2, comprising an authentication (E11-E15) of the access point (AP) by the mobile terminal (TM) as a function of the session key (KS), when the access point has authenticated the mobile terminal. Procédé conforme à la revendication 1 ou 2, comprenant une authentification (E11-E15) du point d'accès (AP) par le terminal mobile (TM) en fonction de la clé de session (KS), lorsque le point d'accès a authentifié le terminal mobile. Verfahren nach Anspruch 1 oder 2, das eine Authentifizierung (E11-E15) des Zugriffspunkts (AP) durch die Mobilstation (TM) in Abhängigkeit vom Sitzungsschlüssel (KS) aufweist, wenn der Zugriffspunkt die Mobilstation authentifiziert hat.
  4. 4
    Method in accordance with Claim 3, according to which the authentication of the access point by the mobile terminal comprises an access point invitation (E11) transmitted to the mobile terminal (TM) so that the mobile terminal authenticates the access point by requesting (E12) the access point to determine (E13) a second response (RP2) as a function of the session key (KS) and to transmit (E14) the second response to the mobile terminal via the short-range network (RFP), by determining (E13) a second response (RP2) as a function of the session key (KS), and by comparing (E15) the two responses (RP2) so as to authorize the opening of the session only after an identity of the second responses compared in the mobile terminal. Procédé conforme à la revendication 3, selon lequel l'authentification du point d'accès par le terminal mobile comprend une invitation (E11) du point d'accès transmise au terminal mobile (TM) afin que le terminal mobile authentifie le point d'accès en demandant (E12) au point d'accès de déterminer (E13) une deuxième réponse (RP2) en fonction de la clé de session (KS) et de transmettre (E14) la deuxième réponse au terminal mobile via le réseau de faible portée (RFP), en déterminant (E13) une deuxième réponse (RP2) en fonction de la clé de session (KS), et en comparant (E15) les deuxièmes réponses (RP2) afin de n'autoriser l'ouverture de la session qu'après une identité des deuxièmes réponses comparées dans le terminal mobile. Verfahren nach Anspruch 3, gemäß dem die Authentifizierung des Zugriffspunkts durch die Mobilstation eine Aufforderung (E11) durch den Zugriffspunkt enthält, die an die Mobilstation (TM) übertragen wird, damit die Mobilstation den Zugriffspunkt authentifiziert, indem sie vom Zugriffspunkt fordert (E12), eine zweite Antwort (RP2) in Abhängigkeit vom Sitzungsschlüssel (KS) zu bestimmen (E13) und die zweite Antwort über das Netz geringer Reichweite (RFP) an die Mobilstation zu übertragen (E14), indem sie eine zweite Antwort (RP2) in Abhängigkeit vom Sitzungsschlüssel (KS) bestimmt (E13), und indem sie die zweiten Antworten (RP2) vergleicht (E15), damit die Eröffnung der Sitzung erst nach einer Identität der in der Mobilstation verglichenen zweiten Antworten erlaubt wird.
  5. 5
    Method in accordance with any one of Claims 1 to 4, comprising at most a predetermined number of iterations (E17) of the steps of requesting connection and authentication (E6-10;E6-E15) so long as authentication has failed. Procédé conforme à l'une quelconque des revendications 1 à 4, comprenant au maximum un nombre prédéterminé d'itérations (E17) des étapes de demande de connexion et d'authentification (E6-E10;E6-E15) tant que l'authentification a échoué. Verfahren nach einem der Ansprüche 1 bis 4, das maximal eine vorbestimmte Anzahl von Iterationen (E17) der Schritte der Verbindungsanforderung und der Authentifizierung (E6-E10;E6-E15) aufweist, solange die Authentifizierung fehlgeschlagen ist.
  6. 6
    Method in accordance with Claim 5, comprising an iteration (E18) of steps (E2-E17) stated in Claim 1 in relation to another access point (AP) in the coverage zone of the mobile terminal (TM) when the authentication has failed (E17) a predetermined number of times. Procédé conforme à la revendication 5, comprenant une itération (E18) des étapes (E2-E17) énoncées dans la revendication 1 relativement à un autre point d'accès (AP) dans la zone de couverture du terminal mobile (TM) lorsque l'authentification a échoué (E17) un nombre prédéterminé de fois. Verfahren nach Anspruch 5, das eine Iteration (E18) der in Anspruch 1 aufgezählten Schritte (E2-E17) bezüglich eines anderen Zugriffspunkts (AP) im Versorgungsgebiet der Mobilstation (TM) enthält, wenn die Authentifizierung eine vorbestimmte Anzahl von Malen fehlgeschlagen ist (E17).
  7. 7
    Method in accordance with any one of Claims 1 to 6, comprising in the mobile terminal (TM) a search (E1) for an optimal access point (AP) having the greatest power level received by the mobile terminal from among the access points in the coverage zone of the mobile terminal so that the mobile terminal (TM) introduces the address (ADAP) of the optimal access point into the query (RQ). Procédé conforme à l'une quelconque des revendications 1 à 6, comprenant dans le terminal mobile (TM) une recherche (E1) d'un point d'accès optimal (AP) ayant le plus grand niveau de puissance reçu par le terminal mobile parmi des points d'accès dans la zone de couverture du terminal mobile afin que le terminal mobile (TM) introduise l'adresse (ADAP) du point d'accès optimal dans la requête (RQ). Verfahren nach einem der Ansprüche 1 bis 6, das in der Mobilstation (TM) eine Suche (E1) nach einem optimalen Zugriffspunkt (AP) mit dem größten Leistungspegel enthält, der von der Mobilstation unter Zugriffspunkten im Versorgungsgebiet der Mobilstation empfangen wird, damit die Mobilstation (TM) die Adresse (ADAP) des optimalen Zugriffspunkts in die Anfrage (RQ) einfügt.
  8. 8
    Method in accordance with any one of Claims 1 to 6, comprising in the mobile terminal (TM) a search (E1) for access points in the coverage zone of the mobile terminal so as to introduce addresses (ADAP) of the access points found in the query (RQ), and in the means of management (PFG) a selection (E3) of the address (ADAP) of an optimal access point (AP) from among the access point addresses extracted from the query (RQ) according to a predetermined criterion so as to introduce the address of the optimal access point into the confirmation message (MC) transmitted to the mobile terminal and the connection request message (MDC) transmitted to the optimal access point (AP). Procédé conforme à l'une quelconque des revendications 1 à 6, comprenant dans le terminal mobile (TM) une recherche (E1) de points d'accès dans la zone de couverture du terminal mobile afin d'introduire des adresses (ADAP) des points d'accès trouvés dans la requête (RQ), et dans le moyen de gestion (PFG) une sélection (E3) de l'adresse (ADAP) d'un point d'accès optimal (AP) parmi les adresses de point d'accès extraites de la requête (RQ) selon un critère prédéterminé pour introduire l'adresse du point d'accès optimal dans le message de confirmation (MC) transmis au terminal mobile et le message de demande de connexion (MDC) transmis au point d'accès optimal (AP). Verfahren nach einem der Ansprüche 1 bis 6, das in der Mobilstation (TM) eine Suche (E1) nach Zugriffspunkten im Versorgungsgebiet der Mobilstation, um Adressen (ADAP) der gefundenen Zugriffspunkte in die Anfrage (RQ) einzufügen, und in der Verwaltungseinrichtung (PFG) eine Auswahl (E3) der Adresse (ADAP) eines optimalen Zugriffspunkts (AP) unter den Zugriffspunktadressen aufweist, die aus der Anfrage (RQ) gemäß einem vorbestimmten Kriterium entnommen wurden, um die Adresse des optimalen Zugriffspunkts in die Bestätigungsmitteilung (MC), die an die Mobilstation übertragen wird, und in die Verbindungsanforderungsmitteilung (MDC) einzufügen, die an den optimalen Zugriffspunkt (AP) übertragen wird.
  9. 9
    Method in accordance with Claim 8, according to which the predetermined criterion relates to a comparison of power levels (NP) of the access points found (AP) received by the mobile terminal (TM) and transmitted in association with the addresses (ADAP) of the access points found in the query (RQ) so that the means of management (PFG) determines the access point having the greatest power level received as optimal access point. Procédé conforme à la revendication 8, selon lequel le critère prédéterminé est relatif à une comparaison de niveaux de puissance (NP) des points d'accès trouvés (AP) reçus par le terminal mobile (TM) et transmis en association avec les adresses (ADAP) des points d'accès trouvés dans la requête (RQ) afin que le moyen de gestion (PFG) détermine le point d'accès ayant le plus grand niveau de puissance reçu en tant que point d'accès optimal. Verfahren nach Anspruch 8, gemäß dem das vorbestimmte Kriterium sich auf einen Leistungspegelvergleich (NP) der gefundenen Zugriffspunkte (AP) bezieht, die von der Mobilstation (TM) empfangen und zusammen mit den Adressen (ADAP) der in der Anfrage (RQ) gefundenen Zugriffspunkte übertragen werden, damit die Verwaltungseinrichtung (PFG) den empfangenen Zugriffspunkt mit dem größten Leistungspegel als optimalen Zugriffspunkt bestimmt.
  10. 10
    Method in accordance with Claim 8 or 9, according to which the predetermined criterion relates to a comparison of traffic loadings of the access points (AP) found (E1) via the mobile terminal (TM) so that the means of management (PFG) selects the access point having the smallest loading as optimal access point. Procédé conforme à la revendication 8 ou 9, selon lequel le critère prédéterminé est relatif à une comparaison de charges de trafic des points d'accès (AP) trouvés (E1) par le terminal mobile (TM) afin que le moyen de gestion (PFG) sélectionne le point d'accès ayant la plus petite charge en tant que point d'accès optimal. Verfahren nach Anspruch 8 oder 9, gemäß dem das vorbestimmte Kriterium sich auf einen Vergleich von Verkehrslasten der von der Mobilstation (TM) gefundenen (E1) Zugriffspunkte (AP) bezieht, damit die Verwaltungseinrichtung (PFG) den Zugriffspunkt mit der geringsten Last als optimalen Zugriffspunkt wählt.
  11. 11
    Method in accordance with any one of claims 8 to 10, according to which the predetermined criterion relates furthermore to an elimination of the addresses (ADAP) of the access points found (AP) which are situated outside a zone of location including the mobile terminal (TM) and defined in the cellular network (RC), before the selection of the address of the optimal access point. Procédé conforme à l'une quelconque des revendications 8 à 10, selon lequel le critère prédéterminé est relatif en outre à une élimination des adresses (ADAP) des points d'accès trouvés (AP) qui sont situés à l'extérieur d'une zone de localisation incluant le terminal mobile (TM) et définie dans le réseau cellulaire (RC), avant la sélection de l'adresse du point d'accès optimal. Verfahren nach einem der Ansprüche 8 bis 10, gemäß dem das vorbestimmte Kriterium sich außerdem auf eine Unterdrückung der Adressen (ADAP) der gefundenen Zugriffspunkte (AP), die sich außerhalb eines die Mobilstation (TM) einschließenden und im zellularen Netz (RC) definierten Lokalisierungsbereichs befinden, vor der Auswahl der Adresse des optimalen Zugriffspunkts bezieht.
  12. 12
    Method in accordance with any one of Claims 1 to 11, characterized in that the secret code (CS) determined by the means of management (PFG) is generated psuedo-randomly and has a length of greater than 16 bytes. Procédé conforme à l'une quelconque des revendications 1 à 11, caractérisé en ce que le code secret (CS) déterminé par le moyen de gestion (PFG) est généré pseudo-aléatoirement et a une longueur supérieure à 16 octets. Verfahren nach einem der Ansprüche 1 bis 11, dadurch gekennzeichnet, dass der von der Verwaltungseinrichtung (PFG) bestimmte Geheimcode (CS) pseudozufällig erzeugt wird und eine Länge von mehr als 16 Bytes hat.
  13. 13
    Method in accordance with any one of Claims 1 to 12, comprising in the means of management (PFG) a determination (E3) of the session key (KS) instead of the determinations (E6) of the session key in the mobile terminal (TM) and the access point (AP), and an introduction (E4, E5) of the session key determined (KS) instead of the secret code into the confirmation message (MC) and the connection request message (MDC). Procédé conforme à l'une quelconque des revendications 1 à 12, comprenant dans le moyen de gestion (PFG) une détermination (E3) de la clé de session (KS) à la place des déterminations (E6) de la clé de session dans le terminal mobile (TM) et le point d'accès (AP), et une introduction (E4, E5) de la clé de session déterminée (KS) à la place du code secret dans le message de confirmation (MC) et le message de demande de connexion (MDC). Verfahren nach einem der Ansprüche 1 bis 12, das in der Verwaltungseinrichtung (PFG) eine Bestimmung (E3) des Sitzungsschlüssels (KS) anstelle der Bestimmungen (E6) des Sitzungsschlüssels in der Mobilstation (TM) und im Zugriffspunkt (AP), und eine Einführung (E4, E5) des bestimmten Sitzungsschlüssels (KS) anstelle des Geheimcodes in die Bestätigungsmitteilung (MC) und die Verbindungsanforderungsmitteilung (MDC) aufweist.
  14. 14
    Authentication system between a short-range wireless network (RFP) having access points and a mobile terminal (TM) in a cellular radiocommunications network (RC), characterized in that it comprises:a management means(PFG) for determining a secret code (CS) in response to a query (RQ) which includes the mobile terminal address (ADTM) and the address (ADAP) of an access point (AP) situated in the coverage zone of the mobile terminal (TM) which relates to the short-range network and which is transmitted from the mobile terminal via the cellular network (RC), and for transmitting a confirmation message (MC) including the secret code and the access point address extracted from the query (RQ) to the mobile terminal (TM) via the cellular network (RC) and a connection request message (MDC) including the secret code and the mobile terminal address (ADTM) extracted from the query to the access point (AP),the mobile terminal for requesting a connection to the access point (AP) designated by the address (ADAP) extracted from the confirmation message (MC), and for determining a session key (KS) as a function of the address (ADAP), of the mobile terminal access point address (ADTM) and of the secret code (CS) extracted from the confirmation message (MC), andthe access point (AP) for determining the session key (KS) as a function of the access point address (ADAP), of the mobile terminal address (ADTM) and of the secret code (CS) extracted from the connection request message (MDC) and for authenticating the mobile terminal as a function of the session key (KS). Authentifizierungssystem zwischen einem drahtlosen Netz geringer Reichweite (RDFP) mit Zugriffspunkten und einer Mobilstation (TM) in einem zellularen Funkverkehrsnetz (RC), dadurch gekennzeichnet, dass es aufweist: eine Verwaltungseinrichtung (PFG), um einen Geheimschlüssel (CS) als Antwort auf eine Anfrage (RQ) zu bestimmen, die die Adresse (ADTM) der Mobilstation und die Adresse (ADAP) eines Zugriffspunkts (AP) enthält, der sich im Versorgungsgebiet der Mobilstation (TM) bezüglich des Netzes geringer Reichweite befindet, und die von der Mobilstation über das zellulare Netz (RC) übertragen wird, um eine Bestätigungsmitteilung (MC), die den Geheimschlüssel und die aus der Anfrage (RQ) entnommene Adresse des Zugriffspunkts enthält, über das zellulare Netz (RC) an die Mobilstation (TM), und eine Verbindungsanforderungsmitteilung (MDC), die den Geheimcode und die aus der Anfrage entnommene Adresse (ADTM) der Mobilstation enthält, an den Zugriffspunkt (AP) zu übertragen,die Mobilstation, um eine Verbindung mit dem von der aus der Bestätigungsmitteilung (MC) entnommenen Adresse (ADAP) bezeichneten Zugriffspunkt (AP) anzufordern, und um einen Sitzungsschlüssel (KS) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und dem aus der Bestätigungsmitteilung (MC) entnommenen Geheimcode (CS) zu bestimmen, undden Zugriffspunkt (AP), um den Sitzungsschlüssel (KS) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und dem aus der Verbindungsanforderungsmitteilung (MDC) entnommenen Geheimcode (CS) zu bestimmen, und um die Mobilstation in Abhängigkeit vom Sitzungsschlüssel (KS) zu authentifizieren. Système d'authentification entre un réseau sans fil de faible portée (RFP) ayant des points d'accès et un terminal mobile (TM) dans un réseau de radiocommunications cellulaire (RC), caractérisé en ce qu'il comprend : un moyen de gestion (PFG) pour déterminer un code secret (CS)- en réponse à une requête (RQ) qui inclut l'adresse (ADTM) du terminal mobile et l'adresse (ADAP) d'un point d'accès (AP) situé dans la zone de couverture du terminal mobile (TM) relative au réseau de faible portée et qui est transmise depuis le terminal mobile via le réseau cellulaire (RC), et pour transmettre un message de confirmation (MC) incluant le code secret et l'adresse du point d'accès extraite de la requête (RQ) au terminal mobile (TM) via le réseau cellulaire (RC) et un message de demande de connexion (MDC) incluant le code secret et l'adresse (ADTM) du terminal mobile extraite de la requête au point d'accès (AP),le terminal mobile pour demander une connexion au point d'accès (AP) désigné par l'adresse (ADAP) extraite du message de confirmation (MC) et pour déterminer une clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de confirmation (MC) , etle point d'accès (AP) pour déterminer la clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de demande de connexion (MDC) et pour authentifier le terminal mobile en fonction de la clé de session (KS).
  15. 15
    System in accordance with Claim 14, characterized in that the means of management itself determines the session key and introduces it instead of the secret code into the confirmation message (MC) and the connection request message (MDC). System nach Anspruch 14, dadurch gekennzeichnet, dass die Verwaltungseinrichtung selbst den Sitzungsschlüssel bestimmt und ihn anstelle des Geheimcodes in die Bestätigungsmitteilung (MC) und die Verbindungsanforderungsmitteilung (MDC) einfügt. Système conforme à la revendication 14, caractérisé en ce que le moyen de gestion détermine lui-même la clé de session et l'introduit à la place du code secret dans le message de confirmation (MC) et le message de demande de connexion (MDC).
Independent claims15