EP1538779B1

Identification information protection method in wlan interconnection

Abstract

This record has no abstract on file.

EP1538779B1, drawing sheet 1
Sheet 1 of 22

Term

Term ended

Expired 14 October 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

7 claims: 7 independent, 0 dependent

  1. 1
    A user identification information protection method for encrypting each field of a message transmitted through at least one relay station by using encryption schemes, which are respectively effective in between a mobile terminal (101) and network elements of a network including a relay station on the other end of communication, the method comprising the steps of:encrypting a part of the message (209, 208) containing a permanent identification information of a mobile user by using an encryption scheme based on using a key which is derived from subscription information of the mobile user stored in a home network, concealing the identification information (208) of the mobile user using a temporary home domain specific mobile user identifier (206);andfurther encrypting the message, after the concealing step, by using a public key of a home domain server belonging to the home network;routing the encrypted message to the home network to which the home domain server belongs, using home domain information. Benutzeridentifikationsinformations-Schutzverfahren zum Verschlüsseln jedes Feldes einer Nachricht, die über wenigstens eine Relaisstation gesendet wird, unter Verwendung von Verschlüsselungsschemata, die jeweils zwischen einem mobilen Endgerät (101) und Netzwerkelementen eines Netzwerks einschließlich einer Relaisstation an dem anderen Ende der Kommunikation wirksam sind, wobei das Verfahren folgende Schritte umfasst: Verschlüsseln eines Teils der Nachricht (209, 208), die permanente Identifikationsinformationen eines mobilen Benutzers enthält, unter Verwendung eines Verschlüsselungsschemas, das auf der Verwendung eines Schlüssels basiert, der aus Abonnementinformationen des mobilen Benutzers abgeleitet ist, die in einem Heimnetzwerk gespeichert sind,Verbergen der Identifikationsinformationen (208) des mobilen Benutzers unter Verwendung einer temporären heimdomänenspezifischen mobilen Benutzerkennung (206);undweiteres Verschlüsseln der Nachricht nach dem Verbergeschritt unter Verwendung eines öffentlichen Schlüssels eines Heimdomänen-Servers, der zu dem Heimnetzwerk gehört;Weiterleiten der verschlüsselten Nachricht an das Heimnetzwerk, zu dem der Heimdomänen-Server gehört, unter Verwendung von Heimdomänen-Informationen. Procédé de protection d'informations d'identification d'utilisateur permettant de crypter chaque champ d'un message transmis au travers d'au moins une station relais en utilisant des principes de cryptage qui sont respectivement efficaces entre un terminal mobile (101) et des éléments de réseau appartenant à un réseau incluant une station relais à l'autre extrémité de la communication, le procédé comprenant les étapes suivantes : le cryptage d'une partie du message (209, 208) contenant des informations d'identification permanente d'un utilisateur mobile en utilisant un principe de cryptage fondé sur l'utilisation d'une clé qui est déduite d'informations d'abonnement de l'utilisateur mobile, stockées dans un réseau de rattachement,la dissimulation des informations d'identification (208) de l'utilisateur mobile en utilisant un identificateur temporaire d'utilisateur mobile spécifique au domaine de rattachement (206), etle cryptage supplémentaire du message, après l'étape de dissimulation, en utilisant une clé publique d'un serveur du domaine de rattachement appartenant au réseau de rattachement,l'acheminement du message crypté vers le réseau de rattachement auquel appartient le serveur de domaine de rattachement, en utilisant les informations de domaine de rattachement.
  2. 2
    Benutzeridentifikationsinformations-Schutzverfahren nach Anspruch 1, weiterhin umfassend folgende Schritte:Senden, an einen Zugangspunkt in dem mobilen Endgerät, der verschlüsselten Identifikationsinformation des mobilen Benutzers, einer Abfragenachricht für den Zugangspunkt (202), einer Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts (207) und der Heimdomänen-Informationen des mobilen Benutzers;Senden, an den Heimdomänen-Server des mobilen Benutzers an dem Zugangspunkt, der verschlüsselten Identifikationsinformationen des mobilen Benutzers und der Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts (207, 306) unter Verwendung der Heimdomänen-Informationen des mobilen Benutzers;Empfangen, von dem Heimdomänenserver des mobilen Benutzers an dem Zugangspunkt, eines Zugangspunkt-Antwortschlüssels (603), einer ersten Antwort (604) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts und einer zweiten Antwort (606) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts;undEmpfangen, von dem Zugangspunkt in dem mobilen Endgerät, einer Antwort (702) auf die Abfragenachricht für den Zugangspunkt und der zweiten Antwort (703) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts, die durch den Zugangspunkt übertragen wurden. Procédé de protection d'informations d'identification d'utilisateur selon la revendication 1, comprenant en outre les étapes suivantes : la transmission, à un point d'accès dans le terminal mobile, des informations d'identification cryptées de l'utilisateur mobile, d'un message de demande d'accès pour le point d'accès (202), d'un message de demande d'accès pour le réseau de rattachement du terminal mobile (207) et des informations de domaine de rattachement de l'utilisateur mobile,la transmission au serveur de domaine de rattachement de l'utilisateur mobile dans le point d'accès des informations d'identification cryptées de l'utilisateur mobile et du message de demande d'accès pour le réseau de rattachement du terminal mobile (207, 306) en utilisant les informations de domaine de rattachement de l'utilisateur mobile ;la réception en provenance du serveur de domaine de rattachement de l'utilisateur mobile dans le point d'accès d'une clé de réponse de point d'accès (603), d'une première réponse (604) au message de demande d'accès pour le réseau de rattachement du terminal mobile, ainsi que d'une seconde réponse (606) au message de demande d'accès pour le réseau de rattachement du terminal mobile, etla réception en provenance du point d'accès dans le terminal mobile d'une réponse (702) au message de demande d'accès pour le point d'accès, ainsi que d'une seconde réponse (703) au message de demande d'accès pour le réseau de rattachement du terminal mobile transféré par le point d'accès. The user identification information protection method according to claim 1, further comprising the steps of: transmitting to an access point, in the mobile terminal, the encrypted identification information of the mobile user, a challenge message for the access point (202), a challenge message for the home network of the mobile terminal (207) and the home domain information of the mobile user;transmitting to the home domain server of the mobile user, in the access point, the encrypted identification information of the mobile user and the challenge message for the home network of the mobile terminal (207, 306), using the home domain information of the mobile user;receiving from the home domain server of the mobile user, in the access point, an access point response key (603), a first response (604) to the challenge message for the home network of the mobile terminal and a second response (606) to the challenge message for the home network of the mobile terminal;andreceiving from the access point, in the mobile terminal, a response (702) to the challenge message for the access point and the second response (703) to the challenge message for the home network of the mobile terminal transferred by the access point.
  3. 3
    Benutzeridentifikationsinformations-Schutzverfahren nach Anspruch 2, weiterhin umfassend den folgenden Schritt:bei dem Schritt des Sendens der Nachrichten von dem mobilen Endgerät zu dem Zugangspunkt, Verschlüsseln der Abfragenachricht für den Zugangspunkt unter Verwendung eines öffentlichen Schlüssels des Zugangspunktes und Verschlüsseln der Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts unter Verwendung eines öffentlichen Schlüssels des Heimdomänen-Servers. Procédé de protection d'informations d'identification d'utilisateur selon la revendication 2, comprenant en outre l'étape consistant à crypter le message de demande d'accès pour le point d'accès, lors de l'étape de transmission des messages depuis le terminal mobile jusqu'au point d'accès, en utilisant une clé publique du point d'accès et en cryptant le message de demande d'accès pour le réseau de rattachement du terminal mobile en utilisant une clé publique du serveur de domaine de rattachement. The user identification information protection method according to claim 2, further comprising the step of: in the step of transmitting the messages from the mobile terminal to the access point, encrypting the challenge message for the access point using a public key of the access point and encrypting the challenge message for the home network of the mobile terminal using a public key of the home domain server.
  4. 4
    Benutzeridentifikationsinformations-Schutzverfahren nach Anspruch 2, weiterhin umfassend folgende Schritte:Senden, von dem mobilen Endgerät an einen zentralen Server in dem Heimdomänen-Server des mobilen Benutzers, einer Nachricht, die die von dem Zugangspunkt übertragene Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts (402) umfasst;undEmpfangen, in dem Heimdomänen-Server des mobilen Benutzers, einer Nachricht die den Zugangspunkt-Antwortschlüssel (503) umfasst, der von dem zentralen Server an den Zugangspunkt übertragen wurde, der ersten Antwort (504) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts und der zweiten Antwort (505) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts. Procédé de protection d'informations d'identification d'utilisateur selon la revendication 2, comprenant en outre les étapes suivantes : la transmission depuis le terminal mobile jusqu'à un serveur central, dans le serveur de domaine de rattachement de l'utilisateur mobile, d'un message comprenant le message de demande d'accès pour le réseau de rattachement du terminal mobile (402) transféré par le point d'accès, etla réception dans le serveur de domaine de rattachement de l'utilisateur mobile, d'un message comprenant la clé de réponse de point d'accès (503) transféré depuis le serveur central jusqu'au point d'accès, de la première réponse (504) au message de demande d'accès pour le réseau de rattachement du terminal mobile, ainsi que de la seconde réponse (505) au message de demande d'accès pour le réseau de rattachement du terminal mobile. The user identification information protection method according to claim 2, further comprising the steps of: transmitting from the mobile terminal to a central server, in the home domain server of the mobile user, a message comprising the challenge message for the home network of the mobile terminal (402) transferred by the access point;andreceiving in the home domain server of the mobile user, a message comprising the access point response key (503) transferred from the central server to the access point, the first response (504) to the challenge message for the home network of the mobile terminal and the second response (505) to the challenge message for the home network of the mobile terminal.
  5. 5
    A mobile terminal for encrypting each field of a message transmitted through at least one relay station by using encryption schemes, which are respectively effective in between the mobile terminal (101) and network elements including a relay station on the other end of communication, the mobile terminal comprising:means configured to generate a part of the message (209, 208) containing a permanent identification information of a mobile user encrypted by using an encryption scheme based on using a key which is derived from subscription information of the mobile user stored in a home network,means configured to conceal the identification information (208) of the mobile user using a temporary home domain specific mobile user identifier (206);andmeans adapted to further encrypt the message, after being concealed, by using a public key of a home domain server belonging to the home network;means configured to transmit the encrypted message so as to be routed to the home network to which the home domain server belongs, using home domain information. Mobiles Endgerät zum Verschlüsseln jedes Feldes einer Nachricht, die durch wenigstens eine Relaisstation gesendet wird, unter Verwendung von Verschlüsselungsschemata, die jeweils zwischen dem mobilen Endgerät (101) und Netzwerkelementen einschließlich einer Relaisstation am anderen Ende der Kommunikation wirksam sind, wobei das mobile Endgerät umfasst: eine Einrichtung, die dazu eingerichtet ist, einen Teil der Nachricht (209, 208) zu erzeugen, die permanente Identifikationsinformationen eines mobilen Benutzers enthält, die unter Verwendung eines Verschlüsselungsschemas, auf der Basis der Verwendung eines Schlüssels verschlüsselt sind, der aus Abonnementinformationen des mobilen Benutzers abgeleitet ist, der in einem Heimnetzwerk gespeichert ist,eine Einrichtung, die dazu eingerichtet ist, die Identifikationsinformationen (208) des mobilen Benutzers unter Verwendung einer temporären heimdomänenspezifischen mobilen Benutzerkennung (206) zu verbergen;undeine Einrichtung, die dazu eingerichtet ist, die Nachricht weiter zu verschlüsseln, nachdem sie verborgen wurde, indem ein öffentlicher Schlüssel eines Heimdomänen-Servers verwendet wird, der zu dem Heimnetzwerk gehört;eine Einrichtung, die dazu eingerichtet ist, die verschlüsselte Nachricht zu senden, um unter Verwendung von Heimdomänen-Informationen an das Heimnetzwerk weitergeleitet zu werden, zu dem der Heimdomänen-Server gehört. Terminal mobile permettant de crypter chaque champ d'un message transmis au travers d'au moins une station relais en utilisant des principes de cryptage qui sont respectivement efficaces entre le terminal mobile (101) et des éléments de réseau incluant une station relais à l'autre extrémité de la communication, le terminal mobile comprenant : un moyen configuré pour générer une partie du message (209, 208) contenant des informations d'identification permanente d'un utilisateur mobile cryptées en utilisant un principe de cryptage fondé sur l'utilisation d'une clé qui est déduite des informations d'abonnement de l'utilisateur mobile stockées dans un réseau de rattachement,un moyen configuré pour dissimuler les informations d'identification (208) de l'utilisateur mobile en utilisant un identificateur temporaire d'utilisateur mobile spécifique au domaine de rattachement (206), etun moyen conçu pour crypter de plus le message, après qu'il a été dissimulé, en utilisant une clé publique d'un serveur de domaine de rattachement appartenant au réseau de rattachement,un moyen configuré pour transmettre le message crypté de sorte à ce qu'il soit acheminé vers le réseau de rattachement auquel appartient le serveur de domaine de rattachement, en utilisant les informations de domaine de rattachement.
  6. 6
    Mobiles Endgerät nach Anspruch 5, wobei das mobile Endgerät weiterhin umfasst:eine Einrichtung, die dazu eingerichtet ist, die verschlüsselten Identifikationsinformationen des mobilen Benutzers, eine Abfragenachricht für den Zugangspunkt (202), eine Abfragenachricht für das Heimnetzwerk des mobilen Endgerätes (207) und die Heimdomäneninformationen des Mobilgeräts an einen Zugangspunkt zu senden;eine Einrichtung, die dazu eingerichtet ist, von dem Zugangspunkt eine Antwort (702) auf die Abfragenachricht für den Zugangspunkt und eine zweite Antwort (703) auf die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts zu empfangen, die vom Zugangspunkt übertragen wurden. Terminal mobile selon la revendication 5, le terminal mobile comprenant en outre : un moyen configuré pour transmettre à un point d'accès les informations d'identification cryptées de l'utilisateur mobile, un message de demande d'accès pour le point d'accès (202), un message de demande d'accès pour le réseau de rattachement du terminal mobile (216), ainsi que les informations de domaine de rattachement de l'utilisateur mobile,un moyen configuré pour recevoir en provenance du point d'accès une réponse (702) au message de demande d'accès pour le point d'accès ainsi qu'une seconde réponse (703) au message de demande d'accès pour le réseau de rattachement du terminal mobile transféré par le point d'accès. The mobile terminal according to claim 5, wherein the mobile terminal further comprises: means configured to transmit to an access point the encrypted identification information of the mobile user, a challenge message for the access point (202), a challenge message for the home network of the mobile terminal (207) and the home domain information of the mobile user;means configured to receive from the access point a response (702) to the challenge message for the access point and a second response (703) to the challenge message for the home network of the mobile terminal transferred by the access point.
  7. 7
    Mobiles Endgerät nach Anspruch 6, wobei das mobile Endgerät weiterhin umfasst:eine Einrichtung, die dazu eingerichtet ist, die Abfragenachricht für den Zugangspunkt (202) unter Verwendung eines öffentlichen Schlüssels des Zugangspunkts zu verschlüsseln, und eine Einrichtung, die dazu eingerichtet ist, die Abfragenachricht für das Heimnetzwerk des mobilen Endgeräts (207) unter Verwendung eines öffentlichen Schlüssels des Heimdomänen-Servers zu verschlüsseln. Terminal mobile selon la revendication 6, le terminal mobile comprenant en outre : un moyen configuré pour crypter le message de demande d'accès pour le point d'accès (202) en utilisant une clé publique du point d'accès, ainsi qu'un moyen configuré pour crypter le message de demande d'accès pour le réseau de rattachement du terminal mobile (207) en utilisant une clé publique du serveur de domaine de rattachement. The mobile terminal according to claim 6, wherein the mobile terminal further comprises: means configured to encrypt the challenge message for the access point (202) using a public key of the access point and means configured to encrypt the challenge message for the home network of the mobile terminal (207) using a public key of the home domain server.