Authentication between a cellular mobile terminal and a short range access point
15 claims: 15 independent, 0 dependent
- 1Authentifizierungsverfahren zwischen einem drahtlosen Netz geringer Reichweite (RFP) mit Zugriffspunkten und einer Mobilstation (TM) in einem zellularen Funkverkehrsnetz (RC), dadurch gekennzeichnet, dass es die folgenden Schritte aufweist:- Übertragung (E2) einer Anfrage (RQ), die eine Adresse (ADTM) der Mobilstation und eine Adresse (ADAP) eines Zugriffspunkts (AP) enthält, der sich im Versorgungsgebiet der Mobilstation (TM) bezüglich des Netzes geringer Reichweite befindet, von der Mobilstation über das zellulare Netz (RC) zu einer Verwaltungseinrichtung (PFG),- Bestimmung (E3) eines Geheimcodes (CS) durch die Verwaltungseinrichtung,- ausgehend von der Verwaltungseinrichtung (PFG), Übertragung (E4, E5) einer Bestätigungsmitteilung (MC), die den Geheimcode und die aus der Anfrage entnommene Adresse des Zugriffspunkts enthält, an die Mobilstation über das zellulare Netz, und einer Verbindungsanforderungsmitteilung (MDC), die den Geheimcode und die aus der Anfrage entnommene Adresse der Mobilstation enthält, an den Zugriffspunkt (AP),- Anforderung (E6) einer Verbindung von der Mobilstation zu dem von der aus der Bestätigungsmitteilung (MC) entnommenen Adresse (ADAP) bezeichneten Zugriffspunkt, damit die Mobilstation (TM) und der Zugriffspunkt (AP) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und vom aus der Bestätigungsmitteilung (MC) und aus der Verbindungsanforderungsmitteilung (MDC) entnommenen Geheimcode (CS) einen Sitzungsschlüssel (KS) bestimmen, und- Authentifizierung (E7-E10) der Mobilstation (TM) durch den Zugriffspunkt (AP) in Abhängigkeit vom Sitzungsschlüssel (KS). Method of authentication between a short-range wireless network (RFP) having access points and a mobile terminal (TM) in a cellular radiocommunications network (RC), characterized in that it comprises the following steps: - transmission (E2) of a query (RQ) including an address (ADTM) of the mobile terminal and an address (ADAP) of an access point (AP) situated in the coverage zone of the mobile terminal (TM) which relates to the short-range network, from the mobile terminal to a management means (PFG) via the cellular network (RC),- determination (E3) of a secret code (CS) by the management means,- from the management means (PFG), transmission (E4, E5) of a confirmation message (MC) including the secret code and the access point address extracted from the query to the mobile terminal via the cellular network and of a connection request message (MDC) including the secret code and the mobile terminal address extracted from the query to the access point (AP),- connection request (E6) of the mobile terminal to the access point designated by the address (ADAP) extracted from the confirmation message (MC) such as the mobile terminal (TM) and the access point (AP) determine a session key (KS) as a function of the access point address (ADAP), of the mobile terminal address (ADTM) and of the secret code (CS) extracted from the confirmation message (MC) and the connection request message (MDC), and- authentication (E7-E10) of the mobile terminal (TM) by the access point (AP) as a function of the session key (KS). Procédé d'authentification entre un réseau sans fil de faible portée (RFP) ayant des points d'accès et un terminal mobile (TM) dans un réseau de radiocommunications cellulaire (RC), caractérisé en ce qu'il comprend les étapes suivantes : - transmission (E2) d'une requête (RQ) incluant une adresse (ADTM) du terminal mobile et une adresse (ADAP) d'un point d'accès (AP) situé dans la zone de couverture du terminal mobile (TM) relative au réseau de faible portée, depuis le terminal mobile à un moyen de gestion (PFG) via le réseau cellulaire (RC),- détermination (E3) d'un code secret (CS) par le moyen de gestion,- depuis le moyen de gestion (PFG), transmission (E4, E5) d'un message de confirmation (MC) incluant le code secret et l'adresse du point d'accès extraite de la requête au terminal mobile via le réseau cellulaire et d'un message de demande de connexion (MDC) incluant le code secret et l'adresse du terminal mobile extraite de la requête au point d'accès (AP),- demande (E6) de connexion du terminal mobile au point d'accès désigné par l'adresse (ADAP) extraite du message de confirmation (MC) afin que le terminal mobile (TM) et le point d'accès (AP) déterminent une clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de confirmation (MC) et du message de demande de connexion (MDC), et- authentification (E7-E10) du terminal mobile (TM) par le point d'accès (AP) en fonction de la clé de session (KS).
- 2Method in accordance with Claim 1, according to which the authentication of the mobile terminal by the access point comprises a request (E7) for determination (E8) from the access point of a response (RP1) as a function of the session key (KS) to the mobile terminal which transmits (E9) the response to the access point, via the short-range network, and in the access point (AP), a determination (E8) of a response (RP1) as a function of the session key (KS) and a comparison (E10) of the responses so as to authorize (E16) the opening of a session between the access point and the mobile terminal when at least the responses compared are identical. Procédé conforme à la revendication 1, selon lequel l'authentification du terminal mobile par le point d'accès comprend une demande (E7) de détermination (E8) depuis le point d'accès d'une réponse (RP1) en fonction de la clé de session (KS) au terminal mobile qui transmet (E9) la réponse au point d'accès, via le réseau de faible portée, et dans le point d'accès (AP), une détermination (E8) d'une réponse (RP1) en fonction de la clé de session (KS) et une comparaison (E10) des réponses pour autoriser (E16) l'ouverture d'une session entre le point d'accès et le terminal mobile lorsqu'au moins les réponses comparées sont identiques. Verfahren nach Anspruch 1, gemäß dem die Authentifizierung der Mobilstation durch den Zugriffspunkt ausgehend vom Zugriffspunkt eine Anforderung (E7) der Bestimmung (E8) einer Antwort (RP1) in Abhängigkeit vom Sitzungsschlüssel (KS) an die Mobilstation, die die Antwort über das Netz geringer Reichweite an den Zugriffspunkt überträgt (E9), und im Zugriffspunkt (AP) eine Bestimmung (E8) einer Antwort (RP1) in Abhängigkeit vom Sitzungsschlüssel (KS) und einen Vergleich (E10) der Antworten enthält, um die Eröffnung einer Sitzung zwischen dem Zugriffspunkt und der Mobilstation zu erlauben (E16), wenn mindestens die verglichenen Antworten gleich sind.
- 3Method in accordance with Claim 1 or 2, comprising an authentication (E11-E15) of the access point (AP) by the mobile terminal (TM) as a function of the session key (KS), when the access point has authenticated the mobile terminal. Procédé conforme à la revendication 1 ou 2, comprenant une authentification (E11-E15) du point d'accès (AP) par le terminal mobile (TM) en fonction de la clé de session (KS), lorsque le point d'accès a authentifié le terminal mobile. Verfahren nach Anspruch 1 oder 2, das eine Authentifizierung (E11-E15) des Zugriffspunkts (AP) durch die Mobilstation (TM) in Abhängigkeit vom Sitzungsschlüssel (KS) aufweist, wenn der Zugriffspunkt die Mobilstation authentifiziert hat.
- 4Method in accordance with Claim 3, according to which the authentication of the access point by the mobile terminal comprises an access point invitation (E11) transmitted to the mobile terminal (TM) so that the mobile terminal authenticates the access point by requesting (E12) the access point to determine (E13) a second response (RP2) as a function of the session key (KS) and to transmit (E14) the second response to the mobile terminal via the short-range network (RFP), by determining (E13) a second response (RP2) as a function of the session key (KS), and by comparing (E15) the two responses (RP2) so as to authorize the opening of the session only after an identity of the second responses compared in the mobile terminal. Procédé conforme à la revendication 3, selon lequel l'authentification du point d'accès par le terminal mobile comprend une invitation (E11) du point d'accès transmise au terminal mobile (TM) afin que le terminal mobile authentifie le point d'accès en demandant (E12) au point d'accès de déterminer (E13) une deuxième réponse (RP2) en fonction de la clé de session (KS) et de transmettre (E14) la deuxième réponse au terminal mobile via le réseau de faible portée (RFP), en déterminant (E13) une deuxième réponse (RP2) en fonction de la clé de session (KS), et en comparant (E15) les deuxièmes réponses (RP2) afin de n'autoriser l'ouverture de la session qu'après une identité des deuxièmes réponses comparées dans le terminal mobile. Verfahren nach Anspruch 3, gemäß dem die Authentifizierung des Zugriffspunkts durch die Mobilstation eine Aufforderung (E11) durch den Zugriffspunkt enthält, die an die Mobilstation (TM) übertragen wird, damit die Mobilstation den Zugriffspunkt authentifiziert, indem sie vom Zugriffspunkt fordert (E12), eine zweite Antwort (RP2) in Abhängigkeit vom Sitzungsschlüssel (KS) zu bestimmen (E13) und die zweite Antwort über das Netz geringer Reichweite (RFP) an die Mobilstation zu übertragen (E14), indem sie eine zweite Antwort (RP2) in Abhängigkeit vom Sitzungsschlüssel (KS) bestimmt (E13), und indem sie die zweiten Antworten (RP2) vergleicht (E15), damit die Eröffnung der Sitzung erst nach einer Identität der in der Mobilstation verglichenen zweiten Antworten erlaubt wird.
- 5Method in accordance with any one of Claims 1 to 4, comprising at most a predetermined number of iterations (E17) of the steps of requesting connection and authentication (E6-10;E6-E15) so long as authentication has failed. Procédé conforme à l'une quelconque des revendications 1 à 4, comprenant au maximum un nombre prédéterminé d'itérations (E17) des étapes de demande de connexion et d'authentification (E6-E10;E6-E15) tant que l'authentification a échoué. Verfahren nach einem der Ansprüche 1 bis 4, das maximal eine vorbestimmte Anzahl von Iterationen (E17) der Schritte der Verbindungsanforderung und der Authentifizierung (E6-E10;E6-E15) aufweist, solange die Authentifizierung fehlgeschlagen ist.
- 6Method in accordance with Claim 5, comprising an iteration (E18) of steps (E2-E17) stated in Claim 1 in relation to another access point (AP) in the coverage zone of the mobile terminal (TM) when the authentication has failed (E17) a predetermined number of times. Procédé conforme à la revendication 5, comprenant une itération (E18) des étapes (E2-E17) énoncées dans la revendication 1 relativement à un autre point d'accès (AP) dans la zone de couverture du terminal mobile (TM) lorsque l'authentification a échoué (E17) un nombre prédéterminé de fois. Verfahren nach Anspruch 5, das eine Iteration (E18) der in Anspruch 1 aufgezählten Schritte (E2-E17) bezüglich eines anderen Zugriffspunkts (AP) im Versorgungsgebiet der Mobilstation (TM) enthält, wenn die Authentifizierung eine vorbestimmte Anzahl von Malen fehlgeschlagen ist (E17).
- 7Method in accordance with any one of Claims 1 to 6, comprising in the mobile terminal (TM) a search (E1) for an optimal access point (AP) having the greatest power level received by the mobile terminal from among the access points in the coverage zone of the mobile terminal so that the mobile terminal (TM) introduces the address (ADAP) of the optimal access point into the query (RQ). Procédé conforme à l'une quelconque des revendications 1 à 6, comprenant dans le terminal mobile (TM) une recherche (E1) d'un point d'accès optimal (AP) ayant le plus grand niveau de puissance reçu par le terminal mobile parmi des points d'accès dans la zone de couverture du terminal mobile afin que le terminal mobile (TM) introduise l'adresse (ADAP) du point d'accès optimal dans la requête (RQ). Verfahren nach einem der Ansprüche 1 bis 6, das in der Mobilstation (TM) eine Suche (E1) nach einem optimalen Zugriffspunkt (AP) mit dem größten Leistungspegel enthält, der von der Mobilstation unter Zugriffspunkten im Versorgungsgebiet der Mobilstation empfangen wird, damit die Mobilstation (TM) die Adresse (ADAP) des optimalen Zugriffspunkts in die Anfrage (RQ) einfügt.
- 8Method in accordance with any one of Claims 1 to 6, comprising in the mobile terminal (TM) a search (E1) for access points in the coverage zone of the mobile terminal so as to introduce addresses (ADAP) of the access points found in the query (RQ), and in the means of management (PFG) a selection (E3) of the address (ADAP) of an optimal access point (AP) from among the access point addresses extracted from the query (RQ) according to a predetermined criterion so as to introduce the address of the optimal access point into the confirmation message (MC) transmitted to the mobile terminal and the connection request message (MDC) transmitted to the optimal access point (AP). Procédé conforme à l'une quelconque des revendications 1 à 6, comprenant dans le terminal mobile (TM) une recherche (E1) de points d'accès dans la zone de couverture du terminal mobile afin d'introduire des adresses (ADAP) des points d'accès trouvés dans la requête (RQ), et dans le moyen de gestion (PFG) une sélection (E3) de l'adresse (ADAP) d'un point d'accès optimal (AP) parmi les adresses de point d'accès extraites de la requête (RQ) selon un critère prédéterminé pour introduire l'adresse du point d'accès optimal dans le message de confirmation (MC) transmis au terminal mobile et le message de demande de connexion (MDC) transmis au point d'accès optimal (AP). Verfahren nach einem der Ansprüche 1 bis 6, das in der Mobilstation (TM) eine Suche (E1) nach Zugriffspunkten im Versorgungsgebiet der Mobilstation, um Adressen (ADAP) der gefundenen Zugriffspunkte in die Anfrage (RQ) einzufügen, und in der Verwaltungseinrichtung (PFG) eine Auswahl (E3) der Adresse (ADAP) eines optimalen Zugriffspunkts (AP) unter den Zugriffspunktadressen aufweist, die aus der Anfrage (RQ) gemäß einem vorbestimmten Kriterium entnommen wurden, um die Adresse des optimalen Zugriffspunkts in die Bestätigungsmitteilung (MC), die an die Mobilstation übertragen wird, und in die Verbindungsanforderungsmitteilung (MDC) einzufügen, die an den optimalen Zugriffspunkt (AP) übertragen wird.
- 9Method in accordance with Claim 8, according to which the predetermined criterion relates to a comparison of power levels (NP) of the access points found (AP) received by the mobile terminal (TM) and transmitted in association with the addresses (ADAP) of the access points found in the query (RQ) so that the means of management (PFG) determines the access point having the greatest power level received as optimal access point. Procédé conforme à la revendication 8, selon lequel le critère prédéterminé est relatif à une comparaison de niveaux de puissance (NP) des points d'accès trouvés (AP) reçus par le terminal mobile (TM) et transmis en association avec les adresses (ADAP) des points d'accès trouvés dans la requête (RQ) afin que le moyen de gestion (PFG) détermine le point d'accès ayant le plus grand niveau de puissance reçu en tant que point d'accès optimal. Verfahren nach Anspruch 8, gemäß dem das vorbestimmte Kriterium sich auf einen Leistungspegelvergleich (NP) der gefundenen Zugriffspunkte (AP) bezieht, die von der Mobilstation (TM) empfangen und zusammen mit den Adressen (ADAP) der in der Anfrage (RQ) gefundenen Zugriffspunkte übertragen werden, damit die Verwaltungseinrichtung (PFG) den empfangenen Zugriffspunkt mit dem größten Leistungspegel als optimalen Zugriffspunkt bestimmt.
- 10Method in accordance with Claim 8 or 9, according to which the predetermined criterion relates to a comparison of traffic loadings of the access points (AP) found (E1) via the mobile terminal (TM) so that the means of management (PFG) selects the access point having the smallest loading as optimal access point. Procédé conforme à la revendication 8 ou 9, selon lequel le critère prédéterminé est relatif à une comparaison de charges de trafic des points d'accès (AP) trouvés (E1) par le terminal mobile (TM) afin que le moyen de gestion (PFG) sélectionne le point d'accès ayant la plus petite charge en tant que point d'accès optimal. Verfahren nach Anspruch 8 oder 9, gemäß dem das vorbestimmte Kriterium sich auf einen Vergleich von Verkehrslasten der von der Mobilstation (TM) gefundenen (E1) Zugriffspunkte (AP) bezieht, damit die Verwaltungseinrichtung (PFG) den Zugriffspunkt mit der geringsten Last als optimalen Zugriffspunkt wählt.
- 11Method in accordance with any one of claims 8 to 10, according to which the predetermined criterion relates furthermore to an elimination of the addresses (ADAP) of the access points found (AP) which are situated outside a zone of location including the mobile terminal (TM) and defined in the cellular network (RC), before the selection of the address of the optimal access point. Procédé conforme à l'une quelconque des revendications 8 à 10, selon lequel le critère prédéterminé est relatif en outre à une élimination des adresses (ADAP) des points d'accès trouvés (AP) qui sont situés à l'extérieur d'une zone de localisation incluant le terminal mobile (TM) et définie dans le réseau cellulaire (RC), avant la sélection de l'adresse du point d'accès optimal. Verfahren nach einem der Ansprüche 8 bis 10, gemäß dem das vorbestimmte Kriterium sich außerdem auf eine Unterdrückung der Adressen (ADAP) der gefundenen Zugriffspunkte (AP), die sich außerhalb eines die Mobilstation (TM) einschließenden und im zellularen Netz (RC) definierten Lokalisierungsbereichs befinden, vor der Auswahl der Adresse des optimalen Zugriffspunkts bezieht.
- 12Method in accordance with any one of Claims 1 to 11, characterized in that the secret code (CS) determined by the means of management (PFG) is generated psuedo-randomly and has a length of greater than 16 bytes. Procédé conforme à l'une quelconque des revendications 1 à 11, caractérisé en ce que le code secret (CS) déterminé par le moyen de gestion (PFG) est généré pseudo-aléatoirement et a une longueur supérieure à 16 octets. Verfahren nach einem der Ansprüche 1 bis 11, dadurch gekennzeichnet, dass der von der Verwaltungseinrichtung (PFG) bestimmte Geheimcode (CS) pseudozufällig erzeugt wird und eine Länge von mehr als 16 Bytes hat.
- 13Method in accordance with any one of Claims 1 to 12, comprising in the means of management (PFG) a determination (E3) of the session key (KS) instead of the determinations (E6) of the session key in the mobile terminal (TM) and the access point (AP), and an introduction (E4, E5) of the session key determined (KS) instead of the secret code into the confirmation message (MC) and the connection request message (MDC). Procédé conforme à l'une quelconque des revendications 1 à 12, comprenant dans le moyen de gestion (PFG) une détermination (E3) de la clé de session (KS) à la place des déterminations (E6) de la clé de session dans le terminal mobile (TM) et le point d'accès (AP), et une introduction (E4, E5) de la clé de session déterminée (KS) à la place du code secret dans le message de confirmation (MC) et le message de demande de connexion (MDC). Verfahren nach einem der Ansprüche 1 bis 12, das in der Verwaltungseinrichtung (PFG) eine Bestimmung (E3) des Sitzungsschlüssels (KS) anstelle der Bestimmungen (E6) des Sitzungsschlüssels in der Mobilstation (TM) und im Zugriffspunkt (AP), und eine Einführung (E4, E5) des bestimmten Sitzungsschlüssels (KS) anstelle des Geheimcodes in die Bestätigungsmitteilung (MC) und die Verbindungsanforderungsmitteilung (MDC) aufweist.
- 14Authentication system between a short-range wireless network (RFP) having access points and a mobile terminal (TM) in a cellular radiocommunications network (RC), characterized in that it comprises:a management means(PFG) for determining a secret code (CS) in response to a query (RQ) which includes the mobile terminal address (ADTM) and the address (ADAP) of an access point (AP) situated in the coverage zone of the mobile terminal (TM) which relates to the short-range network and which is transmitted from the mobile terminal via the cellular network (RC), and for transmitting a confirmation message (MC) including the secret code and the access point address extracted from the query (RQ) to the mobile terminal (TM) via the cellular network (RC) and a connection request message (MDC) including the secret code and the mobile terminal address (ADTM) extracted from the query to the access point (AP),the mobile terminal for requesting a connection to the access point (AP) designated by the address (ADAP) extracted from the confirmation message (MC), and for determining a session key (KS) as a function of the address (ADAP), of the mobile terminal access point address (ADTM) and of the secret code (CS) extracted from the confirmation message (MC), andthe access point (AP) for determining the session key (KS) as a function of the access point address (ADAP), of the mobile terminal address (ADTM) and of the secret code (CS) extracted from the connection request message (MDC) and for authenticating the mobile terminal as a function of the session key (KS). Authentifizierungssystem zwischen einem drahtlosen Netz geringer Reichweite (RDFP) mit Zugriffspunkten und einer Mobilstation (TM) in einem zellularen Funkverkehrsnetz (RC), dadurch gekennzeichnet, dass es aufweist: eine Verwaltungseinrichtung (PFG), um einen Geheimschlüssel (CS) als Antwort auf eine Anfrage (RQ) zu bestimmen, die die Adresse (ADTM) der Mobilstation und die Adresse (ADAP) eines Zugriffspunkts (AP) enthält, der sich im Versorgungsgebiet der Mobilstation (TM) bezüglich des Netzes geringer Reichweite befindet, und die von der Mobilstation über das zellulare Netz (RC) übertragen wird, um eine Bestätigungsmitteilung (MC), die den Geheimschlüssel und die aus der Anfrage (RQ) entnommene Adresse des Zugriffspunkts enthält, über das zellulare Netz (RC) an die Mobilstation (TM), und eine Verbindungsanforderungsmitteilung (MDC), die den Geheimcode und die aus der Anfrage entnommene Adresse (ADTM) der Mobilstation enthält, an den Zugriffspunkt (AP) zu übertragen,die Mobilstation, um eine Verbindung mit dem von der aus der Bestätigungsmitteilung (MC) entnommenen Adresse (ADAP) bezeichneten Zugriffspunkt (AP) anzufordern, und um einen Sitzungsschlüssel (KS) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und dem aus der Bestätigungsmitteilung (MC) entnommenen Geheimcode (CS) zu bestimmen, undden Zugriffspunkt (AP), um den Sitzungsschlüssel (KS) in Abhängigkeit von der Adresse (ADAP) des Zugriffspunkts, der Adresse (ADTM) der Mobilstation und dem aus der Verbindungsanforderungsmitteilung (MDC) entnommenen Geheimcode (CS) zu bestimmen, und um die Mobilstation in Abhängigkeit vom Sitzungsschlüssel (KS) zu authentifizieren. Système d'authentification entre un réseau sans fil de faible portée (RFP) ayant des points d'accès et un terminal mobile (TM) dans un réseau de radiocommunications cellulaire (RC), caractérisé en ce qu'il comprend : un moyen de gestion (PFG) pour déterminer un code secret (CS)- en réponse à une requête (RQ) qui inclut l'adresse (ADTM) du terminal mobile et l'adresse (ADAP) d'un point d'accès (AP) situé dans la zone de couverture du terminal mobile (TM) relative au réseau de faible portée et qui est transmise depuis le terminal mobile via le réseau cellulaire (RC), et pour transmettre un message de confirmation (MC) incluant le code secret et l'adresse du point d'accès extraite de la requête (RQ) au terminal mobile (TM) via le réseau cellulaire (RC) et un message de demande de connexion (MDC) incluant le code secret et l'adresse (ADTM) du terminal mobile extraite de la requête au point d'accès (AP),le terminal mobile pour demander une connexion au point d'accès (AP) désigné par l'adresse (ADAP) extraite du message de confirmation (MC) et pour déterminer une clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de confirmation (MC) , etle point d'accès (AP) pour déterminer la clé de session (KS) en fonction de l'adresse (ADAP) du point d'accès, de l'adresse (ADTM) du terminal mobile et du code secret (CS) extrait du message de demande de connexion (MDC) et pour authentifier le terminal mobile en fonction de la clé de session (KS).
- 15System in accordance with Claim 14, characterized in that the means of management itself determines the session key and introduces it instead of the secret code into the confirmation message (MC) and the connection request message (MDC). System nach Anspruch 14, dadurch gekennzeichnet, dass die Verwaltungseinrichtung selbst den Sitzungsschlüssel bestimmt und ihn anstelle des Geheimcodes in die Bestätigungsmitteilung (MC) und die Verbindungsanforderungsmitteilung (MDC) einfügt. Système conforme à la revendication 14, caractérisé en ce que le moyen de gestion détermine lui-même la clé de session et l'introduit à la place du code secret dans le message de confirmation (MC) et le message de demande de connexion (MDC).
Independent claims15
52 paragraphs, as filed
The present invention relates generally to establish a connection between an access point of a wireless short-range Bluetooth or WiFi type and a mobile terminal of a cellular network GSM type with a transceiver module to communicate with an access point of the short-range network. It concerns more particularly the generation of a key binding when authenticating the mobile terminal and the access point so as to pair them.
Safety of a wireless connection including Bluetooth, for example, a user wishing to establish a Bluetooth connection between a portable personal computer and a cellular mobile terminal enters a PIN identification code as a secret key to computer keyboards and the mobile terminal. The computer and the mobile terminal each establish a link key based on random numbers exchanged between them, the secret key, and the computer's Bluetooth address and the mobile terminal. For example, if the personal computer is considered as the authenticator of the link, it generates a random number (challenge) that communicates via the Bluetooth radio interface to the mobile terminal. The terminal calculates a dependent response of the received random number, the link key and the Bluetooth address of the mobile terminal so that the computer compares the response to the terminal that it has calculated itself, which authenticates the mobile terminal when there is identity of the compared responses.
The pairing of the computer and the terminal requires a secret key (PIN) to share the link key. The secret key must be long enough and absent from dictionaries so that the secret key is not exposed to attacks aimed to find this one to deduce the key link and encryption key. Such attacks cast doubt on the authenticity and integrity of data exchanged.
To guard against such attacks, the secret key must be relatively long, leading a laborious entry and prone to errors, especially in the mobile terminal of which the human-machine interface is limited.
The US 2002/031228 A1 patent application discloses an example access device to open a door of a hotel room. The access device can be connected via a Bluetooth link to a mobile terminal of a cellular telecommunications network. The mobile terminal requires a connection to a server associated with the hotel via the cellular network or a Bluetooth link. The server then transmits a key to the mobile terminal. After a connection to the access device, the mobile device sends the key to the access device that compares the received key to a key stored in the access device to validate and provide access to the chamber. No authentication of the mobile terminal by the access device is provided.
The article by Uri Blumenthal et al., "A Scheme for Dynamic Authentication and Key Exchange in Wireless Networks", Bell Labs Technical Journal 7 (2), p. 37-48, 2002, describes a combination of authentication for a mobile terminal that depends on a "domestic" short-range network with an authentication server contains a secret key beforehand also stored in the mobile terminal, when in connection with an access point connected to the authentication server of another network short-range network said "foreign". The home network server authenticates both the mobile terminal and the server of the foreign network based on a first "authenticator" which is calculated by the mobile terminal based on the secret key, random number provided by the server foreign network and the terminal and an identifier of the terminal. The first authenticator is transmitted to the home network server through the access point and the server the foreign network. The server recalculates the home network the first authenticator in particular according to the stored secret key found in correspondence with the identifier of the terminal transmitted by the server the foreign network.
If the terminal is authenticated following an equal first independent recalculated and sent authenticators any session key, the home network server generates a second "authenticator" depending on the secret key, random numbers and the identifier of the terminal and calculates a session key based on the secret key, a third random number and the second authenticator. The second authenticator is transmitted to the terminal server through the foreign network and the access point so that the terminal recalculates the second authenticator and authenticates the server on the home network when the second transmitted authenticators and recalculated are equal. After this second independent authentication of the session key, the terminal generates the session key.
All previous settings are transmitted through the mobile terminal connection - access point - Server foreign network - server on the home network, without any connection through the home network between the mobile terminal and the server of the home network, which requires of previously storing the secret key in the mobile terminal and the home network server to fulfill a secure authentication, while simultaneously weakening the authentication by using the same secret key to generate the session key for each session between the mobile terminal and an access point.
Patent application WO 02/07135 A1 relates to the activation of an interactive terminal connected to a telecommunication network from a mobile terminal in a radio network. The mobile terminal signals its presence in the vicinity of the terminal, including transmission of a message including the terminal identifier and a location area identifier of the radio network to a management means that prompts the user of the terminal s approaching from the nearest terminal to which the user is authenticated using a secret code read from a memory card, or a biometric print of the user transmitted by the terminal to a server. Patent application WO 02/07135 A1 suggests no mutual authentication of the mobile terminal and the terminal through the radio network.
The invention aims to secure the establishment of a connection between a wireless mobile terminal and an access point of a wireless short range without the need to enter a secret key (PIN) while ensuring the use of such a key that can be very long and be renewed each session between the mobile terminal and an access point.
To achieve this, an authentication process before a session between a wireless short-range having access point and a mobile terminal in a cellular radio network, is characterized in that it comprises the following steps:<ul><li>transmitting a request including an address of the mobile terminal and an address of an access point within the mobile terminal coverage area on the short-range network from the mobile terminal management means via the cellular network ,</li><li>determining a secret code by the management means, </li><li>from the management means, transmitting a confirmation message including the secret code and address of the extracted access point the application to the mobile terminal via the cellular network and a connection request message including the secret code and address of the mobile terminal extracted from the request to the access point,</li><li>connection request from the mobile terminal to the access point designated by the address from the confirmation message to the mobile terminal and the access point determines a session key according to the mail of the access point to the address of the mobile terminal and the extracted PIN confirmation message and the connection request message, and</li><li>authentication of the mobile terminal by the access point based on the session key.</li></ul>
Authentication can include a request for determination of the access point of a response based on the session key to the mobile terminal that transmits the response to the access point via the short-range network, and in point access, determining a function of the session key response and a comparison of responses to authorize the opening of a session between the access point and the mobile terminal when at least the responses compared are identical .
Preferably the previous authentication of the mobile terminal by the access point is specified by an authentication of the access point by the mobile terminal according to the session key, when the access point has authenticated the mobile terminal. In this case, the method may comprise the following a comparative responses identity in the access point, an invitation transmitted to the mobile terminal so that the mobile terminal authenticates the access point, asking the access point determining a second response as a function of the session key and transmitting the second response to the mobile terminal via the short-range network, determining a second response as a function of the session key and by comparing the second response to only allow the opening of the session after a second identity responses compared in the mobile terminal.
In practice, it is preferable that the mobile terminal search multiple access points in the mobile terminal coverage area to introduce addresses of access points found in the application. The management means selects the address of an optimal access point from among the access point addresses extracted from the query according to one or more predetermined criteria to enter the address of the optimal access point into the message confirmation sent to the mobile terminal and the connection request message transmitted to the optimal access point.
Alternatively, the management means determines the session key instead of the determinations of the session key in the mobile terminal and the access point, and introduced the session key established in place of the secret code in the message confirmation and the connection request message so that during authentication responses compared are determined in particular according to the session key extracted from previous messages.
The invention also provides a system of authentication between a wireless short-range having access point and a mobile terminal in a cellular radio network which is characterized according to claim 14.
Alternatively, the average management can determine for himself the session key and insert instead the secret code in the confirmation message and the connection request message.
Other features and advantages of the present invention appear more clearly on reading the following description of several preferred embodiments of the invention, by way of nonlimiting examples, with reference to the corresponding accompanying drawings in which:<ul><li>1 is a block diagram of a telecommunications system including a mobile terminal in a cellular radio network and at least one access point in a wireless short range for setting modern a re the process of authentication of the invention; and</li><li>Figure 2 shows the main steps of a method of authentication algorithm between the mobile terminal and the access point of the invention.</li></ul>
The telecommunications shown in the system of Figure 1 for implementation of the authentication method according to the invention essentially comprises a cellular mobile terminal TM in a cellular radio communication network RC, one or more access points AP connected by a network distribution of R & D without a short-range wireless network RFP providing access to a network of high-speed packet RP, such as the internet, and PFG management platform specific to the invention. For example, the RC cellular network is a GSM network and the low-range wireless network RFP is a Bluetooth network.
The mobile terminal TM includes two radio interfaces respectively with the cellular network RC and the low-range network RFP.
AP access points and mobile devices alternatively each include a pseudo-random generator and each manage an authentication algorithm AA to produce responses RP1, RP2 each based on a random number and a secret code the mobile terminal address or access point in the low range network RFP. AS a session key algorithm is implemented in the access point and the mobile terminal.
RC cellular network such as a GSM network, is schematically represented in Figure 1 by the main ways in which the mobile terminal TM is temporarily attached, such as a base station BTS, a base station controller BSC, a switch MSC mobile service associated with a location register VLR and a home location register HLR.
PFG management platform is connected to the home location register HLR, either directly as an authentication center (not shown) connected to the HLR, either as a server through an intermediate network such as the Internet RP. The PFG platform can also be connected to a short message center SMSC (Short Message Service Center) where requests RQ are transmitted to the form of short messages by mobile terminals, and / or can be connected to a signaling message center USSD (Unstructured Supplementary Service Data) where RQ requests sent to it in the form of USSD messages by mobile terminals. USSD messages are transmitted in real established sessions and faster than short messages. The short message center and the signaling message center will hereinafter interchangeably with "CM message center." The platform contains PFG including a pseudo-random generator to generate CS secret codes in demand for mobile terminals such as the terminal TM. Secret codes present according to the invention, a large typically at least sixteen bytes length or longer than 128 bits.
The platform contains PFG, according to embodiments of the invention, an ADAP addresses the listing database AP access points from multiple wireless networks from short range, in association with the geographical locations of access points AP compared to location areas defined in the RC ZL cellular network. It is recalled that location area in a cellular network covers several cells respectively associated with base stations BTS and a MSC manages one or more location areas.
As discussed below, the platform PFG is an intermediate management means between a mobile terminal TM and AP access point to transmit them a secret code CS to perform authentication. According to embodiments described below, the PFG platform is also used to select optimal access point in response to a request RQ of a mobile terminal.
In Figure 1 shows only a wireless short-range; it is understood that the mobile terminal TM can communicate with any network without wireless short-range particularly in a public place, such as a train station, a shopping mall, an airport, a hotel, etc. AP radio access point, for example, a terminal equipped with a Bluetooth radio interface to communicate within a few dozen meters with mobile terminals TM, and a line interface to communicate with one hand AP other access points throughout the distribution network RD, if any, the wireless short-range, on the other hand to offer packages of broadband communications to mobile terminals through a connection of distribution network RD to the internet RP. In some without low-range wireless network configurations, the distribution network RD is an intranet that is directly connected with xDSL internet PR, or the distribution network RD coincides with the internet and each RP access point AP is connected directly to the internet RP through xDSL lines.
As shown in Figure 2, the authentication method according to a preferred embodiment of the invention essentially comprises steps E1 to E17. Initially, the mobile terminal MT has been activated and recognized by the RC network in a radioelectrically cell area covered by the latter. The terminal TM to the standby state and is located in a location area ZL RC network and a temporary identity TMSI has been assigned by the VLR attached to this location area, as is known.
In step E1, the user of the terminal TM that enters the coverage area of the RFP without low-range wireless network with access points AP decides to select a Bluetooth menu on the terminal TM, particularly a sub search menu (inquiry mode) AP access points. AP access points as terminals can be searched, that is to say each scan periodically the presence of a mobile terminal to detect an interrogation (inquiry) transmitted by mobile devices. Through this, the mobile terminal TM ADAP collects the addresses of access points located within the coverage area of the mobile terminal TM on the low range network RFP. The terminal TM sorts among the responses to his research he receives the addresses of entities of low range network RFP that correspond to device classes associated with access points, to rule out address from a device one equipped with a transceiver module compliant with the RFP network, such as a mobile phone terminal, a personal digital assistant PDA, laptop, etc.
In step E2, the ADAP addresses of available access points found during the previous search are stored in the TM and introduced in a request RQ terminal to be transmitted to the management platform PFG through the fixed network of the cellular network RC . The request RQ ADTM includes the address of the terminal TM prestored therein so that the PFG platform to communicate with the selected access points later. The RQ request includes an address as a recipient of IDPFG identifier PFG platform that has been pre-stored in the mobile terminal TM. The request RQ can be in the form of a short message or USSD signaling message and platform PFG is then connected to the corresponding message center CM.
The request RQ having been issued automatically by the terminal TM and received by PFG platform, the platform examines the list of ADAP access point addresses extracted from the request RQ to select the optimal access point based on a or more predetermined criteria in step E3. The selection of the optimal access point is preceded by checking the mobile terminal of the user profile identified by its IMSI TM permanent identifier to allow it to access an access point wireless network RFP low range .
In a first variation, a predetermined criterion relates to a comparison reference signal power levels emitted by the access points found by the mobile terminal MT, received via the terminal TM. In this variant, the terminal TM also includes, in association with each address ADAP available access point and found in the transmitted request RQ, a power level of NP received in the terminal. The terminal then transmits the request RQ with ADAP couples, NP at PFG management platform that compares the received power levels NP to determine the greatest received power level and select the associated access point AP to the greatest level of received power as the optimal access point to establish a connection with the terminal TM.
In a somewhat similar to the previous variant, the optimal access point having the highest power level received by the mobile terminal is searched and selected in step E1 among the available access points and found in the area coverage of the mobile terminal TM, the mobile terminal TM itself instead of PFG platform. The request RQ contains only the ADAP address of the optimal access point AP instead of the list of ADAP couples, NP.
In a second embodiment, a predetermined criterion relates to a comparison of traffic loads AP access points available and found the mobile terminal TM so that the PFG management platform selects the access point with the smallest load traffic as optimal access point. Traffic loads AP access points of the low range network RFP are collected by the distribution network RD which communicate periodically via the Internet RP or a dedicated line, the PFG platform for an update of the basic data on the access points.
According to an additional variant can be combined with the first or second preceding embodiment, the PFG platform queries the home location register HLR of the cellular network RC in order to read the IDZL identifier of the location area where the terminal TM is located in the cellular network, before the address selection of optimal access point. Depending on the IDZL location area identifier, the PFG platform eliminates ADAP addresses in the list included in the request RQ designating available access points AP and found that are located outside the area of location including the mobile terminal TM and defined in the cellular network. This additional variant prevents a mobile terminal replaces the access point by declaring with an address of a remote access point of the mobile terminal to communicate with it. Then the optimal access point is selected by PFG platform is simply taking the address of the first access point to the list taken from the request RQ, or by combining this variant with the variant power levels or loads access points traffic to select the access point with the highest power level or the lowest traffic load among those in the location area.
A step E3, also the pseudo-random generator in the PFG management platform determines a secret code CS has a great length, at least 128 bits.
The platform then prepares PFG then two messages.
In step E4, a message containing the address confirmation MC ADAP optimal access point and the secret code CS product is established by PFG platform to transmit to the mobile terminal TM through the cellular network RC. The MC message is the same type as the request RQ is to say a short message SM or a USSD message, and passes through the center of messages corresponding CM. The secret code CS extract the message MC is stored in association with the optimal access point address ADAP in the mobile terminal TM. The terminal TM has to step E4 the secret code CS, as if, in the prior art, the user had entered the PIN at the terminal keyboard.
In parallel to step E4, the PFG platform establishes a connection request message including address MDC ADTM the mobile terminal TM, address ADAP optimal access point and the secret code CS generated to the point optimal access AP in the wireless short-range, in step E5. The connection request message MDC is in the form of an IP packet (Internet Protocol) which passes through the internet RP to the distribution network RD network without low-range wireless RFP. The secret code CS extract MDC message is stored in association with the address ADTM in the optimal access point AP.
In response to the ADAP address of the optimal access point AP extract of MC confirmation message received by the mobile terminal TM, it tries to connect to the optimal access point AP and identified by inviting the access point optimal to authenticate. In step E6, the mobile terminal TM transmits a first T1 frame containing the terminal address ADTM, address ADAP optimal access point and a connection request flag and determination of DC session key.
Optimal access point periodically search mode recognizes the frame T1 is for him. The mobile terminal and the access point then each determine a shared session key KS applying the session key algorithm AS address of the mobile terminal ADTM, ADAP address of the access point, the secret code CS and one or more random numbers RAND exchanged between them through the low range network RFP. The mobile terminal used in the secret code CS is the excerpt in the confirmation message MC, while the secret code CS used in the access point AP is the extract from the MDC Connection Request message. The mobile terminal TM and optimal access point AP are well paired. The session key KS is stored in the terminal and the access point, and is used, in particular for authentication and data encryption, that until the disconnection of the access point AP and the mobile terminal TM.
The authentication of the mobile terminal TM is then triggered by the optimal access point emitting in response to the first frame T1, T2 including a frame optimal access point address ADAP, address ADTM of the terminal TM, RAP a random number generated by the pseudo-random generator in the access point and a DRP response request flag to the mobile terminal TM, in step E7.
The method then proceeds to step E8, E9 and E10 for a proper authentication of the mobile terminal TM by the optimal access point AP. Upon receipt of the frame T2 with the response request flag in step E8 mobile terminal TM applies the random number RAP extracted from the T2 frame, the session key KS determined in step E6 and address ADTM the AA authentication algorithm that produces a response RP1. Also in step E8, the optimal access point AP performs a similar app: RP1 = AA (RAP, KS, ADTM), but in which the session key is that he has determined in step E6 and ADTM associated with the address. Then the mobile terminal transmits, in step E9, a frame including T3, besides ADTM ADAP and addresses, the response RP1 = AA (RAP, KS, ADTM) which was determined in the mobile terminal. The frame T3 is recognized by the optimal access point AP that the step E10 compares the response RP1 determined the optimal access point in response RP1 extracted from the received frame T3. If the compared RP1 answers are identical, the optimal access point AP authorizes registration through it from the mobile terminal TM to the distribution network RD and the Internet RP, in step E16 .
The session key KS for this open session will be used to determine the key to a next session session between the mobile terminal MT and AP access point if the session key KS has not been cleared in the meantime expiration of a period of time from the storage key KS, predetermined by the operator managing the access point.
A more complete version on mutual authentication when the optimal access point AP has authenticated the mobile terminal TM in step E10, the optimal access point AP transmits to step E11 T4 a frame containing the addresses ADAP and ADTM and IA indicator to invite the terminal TM to authenticate.
In response to the previous frame T4, the mobile terminal TM triggers authentication optimal access point emitting a T5 frame for optimal access point address ADAP. T5 frame includes a random number generated by the RTM pseudo-random generator in the mobile terminal and a DRP response request flag, in step E12. Following T5 frame, at step E13 the access point AP applies the random number extracted RTM T5 frame, the session key KS determined in step E6 and address ADAP to the algorithm AA authentication producing a second response RP2. Also in step E13, the mobile terminal TM is running an application: AA = RP2 (RTM, KS, ADAP), but in which the session key is that he has determined in step E6 and associated with the ADAP address. Then the optimal access point AP transmits a frame including T6, besides the ADAP address and ADTM, the response RP2 = AA (RTM, KS, ADAP) that has been determined in the optimal access point. T6 frame is recognized by the mobile terminal TM to that step E15 compares the response RP2 determined in the mobile terminal in response RP2 extracted from the received frame T6. If RP2 the compared responses are identical, the terminal TM confirmed by issuing another frame the opening of the session requested the optimal access point AP in step E16.
Alternatively, the session key KS is not determined separately by the mobile terminal TM and optimal access point AP in step E6 but is predetermined by the PFG management platform, in step E3. The platform generates a random session key KS same size as that of the embodiment described above.
However, to ensure consistency, the platform may contain the AS session key algorithm. At the end of step E3, the platform has selected the optimal access point and associated ADAP address of the optimal access point at ADTM handheld extracted from the request RQ, allowing him determine the session key by applying ADAP and ADTM addresses, secret code CS and one or more random number RAND to the aS algorithm is: KS = AS (ADAP, ADTM, CS, RAND).
In steps E4 and E5, the PFG management platform introduces the session key KS determined in place of CS secret code in the confirmation message MC transmitted to the mobile terminal and the connection request message transmitted to the MDC AP optimal for the optimal access point and the mobile terminal using the session key KS for authentication E6 to E10 or E6 to E15 and after the session opened in step E16, step E6 with more determination session key KS.
As indicated in step E17, if the authentication of the mobile terminal by the optimal access point failed, that is to say if the RP1 responses compared to step E10 are different, or if authentication mutual failed, that is to say if the RP2 responses compared to step E15 are different, an attempt to logon request is repeated by performing the execution of steps E6 to E10 according to realization authentication of the terminal by the optimal access point, or steps E6 to E15 according to the mutual authentication variant.
In practice, the connection request stages, determination of responses and E6 responses compared to E10 or E6 to E15 can be repeated a maximum of N times as the compared responses RP1 and RP2 are different, N being a predetermined number iterations for example equal to 3.
If after N iterations connection request to step E17, authentication failed, that is to say the compared responses are still different, the process may automatically return to step E2 to perform steps E3 to E17 following in relation to the ADAP address of another access point selected according to predetermined criteria, for example, from the list included in the request RQ, as shown in an intermediate step E18. Selecting this other access point in the list naturally excludes the last optimal access point that was previously selected and for which N login attempts have failed. The other selected optimal access point is located in the coverage area of the mobile terminal TM relating to the short-range network RFP and may be the access point with the highest level received power or the smallest traffic load in the remaining list, or one that succeeds the last optimal access point selected from the list.
While the invention has been described for a cellular network and a GSM wireless short-range Bluetooth type the invention is also applicable in the context of a mobile radio network for the UMTS or more generally third generation type and other networks without low-range wireless for example of the type in the IEEE 802.11b standard and according to the following other standards to it, that is to say for networks also expressed networks Wi-Fi (Wireless Fidelity).
2 sheets
Sheet 1 Sheet 2
Every citation, both waysCites: the store holds 4 of 5
| Document | Relation | Office |
|---|---|---|
| WO0207135A | Cites | World Intellectual Property Organization (WIPO) |
| FR2825869A | Cites | France |
| US2002031228A1 | Cites | United States of America |
| US2003134642A1 | Cites | United States of America |
9 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 03292926 | European Patent Office (EPO) | A | |
| EP20030292926 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| EP1536592A1 | European Patent Office (EPO) | A1 | |
| US2005130627A1 | United States of America | A1 | |
| EP1536592B1This record | European Patent Office (EPO) | B1 | |
| AT336125T | Austria | T | |
| ATE336125T1 | Austria | T1 | |
| DE60307482D1 | Germany | D1 | |
| DE60307482T2 | Germany | T2 | |
| ES2271503T3 | Spain | T3 | |
| US7590246B2 | United States of America | B2 |
59 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: FRENCHFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1536592
- Publication, DOCDB
- 1536592
- Publication, EPODOC
- EP1536592
- Application
- 3292926
- Application, DOCDB
- 03292926
- Application, EPODOC
- EP20030292926
Titles3
- German
- Authentifizierung zwischen einer zellularen Mobilendgerät und einem kurzreichweitigen Zugangspunkt
- English
- Authentication between a cellular mobile terminal and a short range access point
- French
- Authentification entre un terminal mobile de réseau cellulaire et un point d'accès de réseau de faible portée
Classification
- CPC, 12
- H04W12/06
- H04L63/0869
- H04L63/18
- H04L2463/061
- H04W84/18
- H04W12/003
- H04W88/06
- H04W12/00512
- H04W12/00516
- H04W12/71
- H04W12/73
- H04W12/50
- IPC, 4
- H04L12 28
- H04Q7 38
- H04L12 56
- H04W12 00
Designated states27
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
