Verifying check-in authentication by using an access authentification token
Abstract
A simple and efficient means of checking the registration authorization is proposed by the method and the device for checking the registration authorization prior to the start of the re-registration process based on a registration query from a mobile radio terminal to at least one access device for an intra-domain handover in a mobile communication network. In the network, a token which has been sent by an access device to a mobile radio terminal and has been stored in at least one trust table of at least one access device, is received by at least one further access device during a registration query from a mobile radio terminal and compared with tokens stored in at least one trust table prior to the start of the registration for the purpose of verifying the registration authorization, and the registration is started if an authorization is present.

Term
Term ended
Expired 30 September 2022, 4 years ago.
- Priority and filed
- Granted
- Expired
- Today
23 claims: 22 independent, 1 dependent
- 1Verfahren zum Überprüfen der Einbuchungsberechtigung vor dem Start des Wieder-Registrierungsprozesses aufgrund einer Einbuchungsanfrage eines Mobilfunkendgerätes (5) an mindestens eine Zugangseinrichtung (6) für einen Intra-Domänen-handover in einem mobilen Kommunikationsnetz, dadurch gekennzeichnet, dass eine Berechtigungsmarke, die von einer Zugangseinrichtung (4) an ein Mobilfunkendgerät (5) gesandt wurde und in mindestens einer Vertrauenstabelle (7) von mindestens einer Zugangseinrichtung (4) gespeichert wurde, von mindestens einer weiteren Zugangseinrichtung (1, 4, 6) bei einer Einbuchungsanfrage eines Mobilfunkendgerätes (5) empfangen und mit in mindestens einer Vertrauenstabelle (7) gespeicherten Berechtigungsmarken vor Beginn der Einbuchung zur Einbuchungsberechtigungsprüfung verglichen wird, nur bei Vorliegen einer Berechtigung die Einbuchung gestartet wird und dass die Berechtigungsmarke mit einem Schlüssel verschlüsselt an ein Mobilfunkendgerät (5) übermittelt wird.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die Überprüfung der Einbuchungsberechtigung vor Beginn der Wieder-Registrierungsprozesse geschieht.
- 3Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass für den Wieder-Registrierungsprozess der Verbindungs-Aktualisierungsprozess verwendet wird.
- 4Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass für den Wieder-Registrierungsprozess der Authentifizierungs- und Autorisierungsprozess verwendet wird.
- 5Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass für den Wieder-Registrierungsprozess der Authentifizierungs- und Autorisierungsprozess und der Verbindungs-Aktualisierungsprozess gleichzeitig verwendet werden.
- 6Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Zugangseinrichtung (4) ein Zugangs-Router ist.
- 7Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass nach erfolgreicher Prüfung der Berechtigung von der Zugangseinrichtung (6) die Erneuerung des Verbindungsprozesses gestartet wird.
- 8Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass nach erfolgreicher Prüfung der Berechtigung von der Zugangseinrichtung (6) die Erneuerung des Autorisations- und Authentifikationsprozesses gestartet wird.
- 9Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Berechtigungsmarke mit der Nachricht zur Erneuerung der Verbindung zwischen Zugangseinrichtung (6) und Mobilfunkendgerät (5) gesandt wird.
- 10Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Zugangseinrichtung (4) die von einem Mobilfunkendgerät (5) empfangene Berechtigungsmarke an eine Nachbar-Zugangseinrichtungen (1, 6) versendet.
- 11Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Zugangseinrichtung (4) die von einem Mobilfunkendgerät (5) empfangene Berechtigungsmarke an eine Nachbar-Zugangseinrichtungen (1, 6) versendet, die in einer Vertrauensliste gespeichert ist.
- 12Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Zugangseinrichtung (4) von Nachbar-Zugangseinrichtungen (1, 6) erhaltene Berechtigungsmarken in mindestens einer Vertrauenstabelle (7) speichert.
- 13Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass verwendete Berechtigungsmarken in einer dafür vorgesehenen Vertrauenstabelle gespeichert werden.
- 14Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass ein Mobilfunkendgerät (5) bei einem Intra-Domänen-handover die Berechtigungsmarke an eine weitere Zugangseinrichtung (6) sendet.
- 15Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine weitere Zugangseinrichtung (6) die Berechtigungsmarke nach der Gültigkeitsdauer der Berechtigungsmarke überprüft.
- 16Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine weitere Zugangseinrichtung (6) die Berechtigungsmarke nach dem Erstellen der Berechtigungsmarke überprüft.
- 17Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass ein einen Schlüssel repräsentierender Zusatz der Berechtigungsmarke mit einem berechneten Schlüssel der Zugangseinrichtung (6) verglichen wird.
- 18Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Berechtigungsmarke die Identität des Mobilfunkendgerät (5) enthält.
- 19Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Berechtigungsmarke die Identität der erstellenden Zugangseinrichtung (4) enthält.
- 20Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Berechtigungsmarke die Erstellungszeit enthält.
- 21Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Berechtigungsmarke eine Zufallszahl enthält.
- 22Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass eine Berechtigungsmarke einen einen Schlüssel repräsentierenden Zusatz enthält.
- 23Vorrichtung zum Überprüfen der Zugangsberechtigung beim Starten von Authentifizierungs- und Autorisierungsprozessen aufgrund von einer Einbuchungsanfrage eines Mobilfunkendgerätes (5) an mindestens eine Zugangseinrichtung (4) für einen Intra-Domänen-handover in einem mobilen Kommunikationsnetz, mit einer Empfangseinheit (10) zum Empfangen einer Berechtigungsmarke und einer Anfrage betreffend die Berechtigung für den Zugang eines Mobilfunkendgerätes, mit einer Verarbeitungseinheit (11) zum Erstellen von Berechtigungsmarken und zum Überprüfen von erhaltenen Berechtigungsmarken, mit der Verarbeitungseinheit (11) zum Verschlüsseln der Berechtigungsmarken mit einem Schlüssel, mit mindestens einer Vertrauenstabelle (7) zum Speichern von erstellten und von mindestens einer Zugangseinrichtung (6) erhaltenen Berechtigungsmarken und mit einer Sendeeinheit (12) zum Senden von erstellten verschlüsselten Berechtigungsmarken an ein Mobilfunkendgerät (5) und mindestens einer weiteren Zugangseinrichtung (6) und zum Weiterleiten der Zugangsberechtigung an weitere Netzwerkeinheiten.
Independent claims23
16 paragraphs, as filed
p0001<nplcit id="ncit0001" npl-type="s"><text>SUBRAMANYAM V ET AL: "Security in mobile systems" Reliable Distributed Systems, 1998. Proceedings. Seventeenth IEEE Symposium on West Lafayette, IN, USA 20-23 Oct. 1998, Los Alamitos, Calif., USA, IEEE Comput. Soc, US, 20 October 1998 (1998-10-20), pages 407-412</text></nplcit>, XP010319125 ISBN: 0-8186-9218-9 discusses requirements for mobility in a network and the extension of existing security schemes. For users, it may be important to have continuous access to information in a network even when they are mobile, such as a doctor who must constantly monitor the health of a patient. Communication in such cases is usually performed via wireless connections and is difficult to guarantee security in exchanging messages. Common goals for secure computing (computing) have been the archiving of trustworthiness, integrity, availability, legitimacy and accountability.
p0002The invention relates to a method and a device for checking the booking authorization before the start of authentication and authorization processes based on an entry request of a mobile radio terminal to at least one access device for an intra-domain handover in a mobile communications network.
p0003QoS mechanisms (QoS) have the purpose of guaranteeing service characteristics, such as end-to-end runtime, etc., in networks that support mobile Internet communications. In these networks, there is a threat to these mechanisms by Denial of Service (DoS) attacks, which aim to reduce the availability of services to legitimate users. One threat is that QoS signaling mechanisms are used to activate mobile nodes for requests to a network, which means resource reservation. If the network can not efficiently verify the "credibility" of QoS requests, such as querying the origin and authorization of a request from a mobile node, the network's performance can be reduced with false QoS requests. A mobile radio terminal, for example, leaves its home network and switches to a network with HMIPv6 connection and an AAA architecture. In this case, it is assumed that between the mobility anchor point (MAP) and each access router (AR), between the local AAA server (AAAL) and each access router (AR), between the MAP and the AAAL and between an access Routers and the other access routers, there is always a security association (security relationship = SA). After a mobile radio terminal has registered successfully, its authentication and authorization information (AA) is stored in a local AAA server (AAAL) and its identity is with the MAP and the access router (AR), in which the mobile radio terminal is registered first Has been known. Thereafter, the mobile radio terminal can move between the entry areas of the access router (AR) without an interruption in a communication. In order to optimize the intra-domain handover, the waiting time for registration with the individual access routers must be minimized as far as possible. In general, DoS attacks prevent or block the normal use or management of communication facilities (or other services). Denial of Service denial of service (DoS) attacks have a specific purpose. For example, DoS attacks can cause the network to collapse or turn off, or reduce the performance of overloading the network by means of a high number of false messages sent. All mobile terminals in an access network can send QoS requests to all nodes along the communication path for reserving resources. This also allows attackers to send QoS queries in the access network. For this reason, an access device, such as an access router, must check the "credibility" of a QoS request from a mobile terminal before processing the request further. If an access facility uses the local AAA server before the start of the reservation process, there is a significant wait time for the re-registration process. When a mobile radio terminal switches from the entrance area of an access router to the entry area of another access router in the access network (intra-domain handover), no interruption between the mobile radio terminal and the access network is to occur. While the mobile terminal is holding the connection to the first access router, it initiates a new registration process with another access router by transmitting connection update messages. If it is not previously verified whether the mobile terminal is a registered user in the access network, attackers can burden the access network, for example, the computing capacity by means of requests for authentication and authorization, or reserving resources for incorrect inquiries,
p0004It is therefore an object of the present invention to ensure the efficiency of the communication network by means of effective protection against incorrect inquiries.
p0005The object is achieved according to the invention in each case by the subject matter of the independent patent claims with respect to the method and the device. One core of the invention is that, in the case of intra-domain handover, before the start of connection update and reauthentication and reauthorization processes (AAA processes), a check of the registration authorization with an authorization mark takes place to prevent DoS attacks . The advantages of this method are a low wait time for re-registration processes and effective protection against DoS attacks. With this method, the Filling (The DoS attack attempts to fill the memory of the attacked system and allow the system to no longer receive legitimate requests.) The access router's memory due to a DoS attack, the performance degradation of the Signaling capacity in the access network can be avoided by incorrect inquiries and the unauthorized allocation of resources in the local AAA server by incorrect requests. Advantageous embodiments are given in the subclaims referred to in this claim. Reducing the risk of repeatedly issued permissions (= token), such as a cookie, can be achieved due to a narrowly limited scope of validity by accepting the authorization tag.
p0006The invention is explained in more detail with the aid of an exemplary embodiment shown in the FIGURE. FIG<dl id="dl0001" compact="compact"><dt>FIG</dt><dd>How the first authorization mark (= token) is sent to the mobile radio terminal,</dd><dt>FIG</dt><dd>How the previously generated authorization mark is sent without limitation of the validity area and without indication for use to a further access device,</dd><dt>FIG</dt><dd>As the previously generated authorization mark is transmitted without an indicator for use in a limited area of validity,</dd><dt>FIG</dt><dd>As the previously generated authorization mark is provided with an indicator for use in a limited area of validity, </dd><dt>FIG</dt><dd>How an authorization mark is sent to a mobile terminal for an intra-domain handover,</dd><dt>FIG</dt><dd>4 is a schematic of a device for sending and checking authorization marks.</dd></dl>
p0007<figref idrefs="f0001">FIG</figref> Shows how the mobile radio terminal 5 transmits a first registration request to an access router 4 upon power-up or the first login in the access network. After the local AAA server receives the positive authentication and authorization information from the home AAA server, it informs the mobility anchor point (MAP) 2 of the successful authentication and authorization check. Thereafter, the mobility anchor point (MAP) 2 sends the session key generated by the home AAA server and forwarded with the authentication and authorization information to the access router 4 to allow the access router a security Association with the mobile radio terminal 5. The access router 4 creates an authorization tag, encrypts it with the session key, and sends it to the mobile radio terminal 5. The mobile terminal 5 is securely obtained the session key by means of a long-term security association from the home AAA server. Authorization marks are always created here by an access router. The first authorization mark is received by the mobile radio terminal 5 from the access router in which the mobile radio terminal 5 logs on or performs an intra-domain handover, ie, after successful registration, the authorization tag encrypted with the session key is transmitted between the mobile radio terminal 5 and all access routers of the mobile radio terminal 5 And is transmitted from an access router 4 to the mobile terminal 5 with the connection update message. Each access router 4 has at least one trusted list 7. In a trusted list 7 (Trusted List), information about the access routers 1, 6 is stored whose authorization marks are accepted and in a different trust list 7 (trusting list) information about the access Routers 1.6 which accept the authorization marks of the originating router 4. The already used authorization marks are stored in a third trust list 7. All authorization marks which have already been successfully used by a mobile radio terminal are stored here. In this way it is achieved that one. Authorization mark is "depreciated" after a single use and can not be used repeatedly. The two other trust lists serve the purpose that not every authorization flag used must be stored in each access router 1, 4, 6 of the entire access network, but only in the access routers 1, 4, 6, which are shown in the two trust lists (Trusted List and Trusting List). Without the limitation of the scope, the method would not scale for large access networks. It only accepts authorization tags created by the access routers 4 that are in its trusted list. A further trusted list 7 contains the access routers which accept the created authorization marks from this access router 4. To increase security, an access router 4 stores the authorization tags of its neighbor access routers into a trusted list. This creates a limited scope of validity for the acceptance of an authorization mark since an access router 4 accepts only its self-generated authorization markers and those created by a neighbor access router 6. If a mobile terminal 5 wishes to perform an intra-domain handover, it adds (5) the permission mark to the re-registration request and sends it (5) as text to the new access router 6. The new access router 6 performs three actions For checking the authorization mark by:<ul><li>Verification of the validity period for the expiry date of the authorization mark;</li><li>Verifying the identity of the access router that has created the authorization mark in a trusted list 7;</li><li>After checking the above points, a key-hashed digest is computed with the permission mark information using the authorization flag key and compared with the random number addition already present in the authorization mark.</li></ul>
p0008If the authentication check is successful, the connection update and re-authorization process is started. The new access router 6 will authenticate the re-registration request when it receives the session key contained in the re-registration request (BU ACK message) from the mobility anchor point (MAP) If the verification fails, the access router 6 will not process the re-registration request further. If, after some time, the mobile radio terminal 5 has not yet received a response via the re-registration from the access router 6, the mobile radio terminal 5 must begin an authorization and authentication process via the local AAA server 3 and the home AAA server, as in FIG An intra-domain handover, or when the device is turned on. 5. However, it can not use the optimized handover process.
p0009From the access router 6, a new authorization tag is created with the session key and sent to the mobile terminal 5 for the next intra-domain handover if the reauthentication process did not fail. The old authorization mark can not be reused. After verifying the authorization mark, the access router 6 informs the access router 4 that created the authentication mark about the use of the authentication mark. The access router 4, which had created the authorization mark, informed all access routers 1, 6 in its trusted lists 7, except the access router 6, which had used the authorization mark to prevent a second use of the authorization mark. When the authorization mark reaches its expiry date for the validity of the authorization mark, the authorization mark is deleted from the trust lists 7 of the access router 1, 4, An authorization tag contains the authorization tag information and the random number addition (hash code). The authorization tag information includes:<ul><li>The identity of the mobile radio terminal 5: the one-time identification of the mobile radio terminal 5 in the access network; This may be a one-time identification which a mobile radio terminal 5 receives after its first registration;</li><li>The identity of the access router that created the authorization tag: The unique (= unique, unique) access router identification may be its IP address or other unique identification capability in the access network.</li><li>The production period for the creation of the authorization mark is used to limit the period of validity of the authorization mark.</li><li>A random number: This is used to differentiate two authorization marks, which were created at the same time.</li></ul>
p0010A random number additional message is an excerpt from the authorization tag information and the authorization tag key. The calculation of the random number addition can be effected either by the function HMAC-MD5 or HMAC-SHA1. The authorization tag key is distributed from the mobility anchor point (MAP) 2 to each access router and periodically updated.
p0011An authorization mark thus looks as follows:<ul><li>Eligibility mark: = Eligibility mark information, Eligibility mark-Random number addition</li><li>Token information: = (identity of the mobile station, the identity of the generating access router, ores ugungszeitpunkt, random number)</li><li>Eligibility mark-random number addition: = HMAC (Eligibility mark key, Eligibility mark information)</li></ul>
p0012<figref idrefs="f0002">FIG</figref> Shows the case where the scope of validity for a created authorization mark is the entire access network. When an authentication mark is sent to an access router 6 for first use, only (6) is secure against DoS attacks because it is the only (6) aware that the authentication mark has been used and only it (6) can Thus preventing a second use of the authorization mark. Other access routers 1, 4, which do not have information on the use of the authorization tag, could be at risk of not detecting a DoS attack since the access router 6 did not pass on the information on the use of the authentication tag in the access network Has. However, the information on the use of the authorization mark on the entire access network causes a lot of signaling traffic in the access network.
p0013<figref idrefs="f0003">FIG</figref> and <figref idrefs="f0004">4</figref> Show how each access router inserts its two adjacent access routers and itself into at least one trusted list to reduce the scope of the authentication mark, eg, access router 4 carries the access routers 1 and 6 and itself into at least one Trust list. Thus, the authentication mark created by the access router is accepted only by the access routers 1, 4, and 6. The access router 4 has security associations with the access routers 1, 6 and each access router 4, 1 and 6 has at least one trusted list 7 with information indicating which authorization markers (4) from which access routers 1 , 4 and 6 accepted. The mobile radio terminal 5 receives an authorization mark created by the access router 4 and transmits it for an intra-domain handover to an access router 6. After successful verification of the authorization mark, the connection update and the AAA process can begin. The access routers that are not included in the trust list 7 of the access router 4 (eg, all other access routers other than 1, 4, and 6) are not in danger of obtaining a repeated permission mark that has already been used . The access router 6, which has used the authorization mark, also knows about the usage, ie only access routers 1 and 4 are in danger of a possible DoS attack since they would still accept this authorization mark.
p0014<figref idrefs="f0005">FIG</figref> Shows how the access router 6, after having accepted the authentication tag 6, immediately transmits information to the access router 4 that has created the authentication tag. Thereafter, the access router 4 informs the access router 1 in its trusted list 7 and the access router 6 so that it 6 does not accept any further copies of the authorization mark. If the verification of the authorization mark fails, the re-registration process is not started, otherwise, the connection update process and the re-authorization process are initiated at the same time. When a re-registration request (BU ACK message) with the session key arrives at the access router 6, the latter (6) checks a digital signature transmitted by a mobile node over the entire runtime of the QoS request with the session key The re-authentication was created. After a successful verification of the authorization mark, the access router 6 adds a new authorization mark, encrypted with the session key, to the re-registration request (BU ACK message) and sends it to the mobile radio terminal 5.
p0015<figref idrefs="f0006">FIG</figref> Shows how an access router 4 creates an authorization mark with a processing unit 11 and sends it with a transmitting unit 12 to a mobile radio terminal. Authorization marks which have been created by further access routers 6 are forwarded via a receiving unit 10 to a processing unit 11, which sends them 11 to a further trusted list 7. Each access router (4, 6) has at least one trusted list. In a trusted list 7, information about the access routers (1, 6) is stored whose authorization marks are accepted, and in a different trust list 7 (trusting list), information is stored via the access routers (1, 6) Which accept the authorization marks of the generating access router (4). The already used authorization marks are stored in a third trust list 7. All authorization marks which have already been successfully used by a mobile radio terminal are stored here. If a mobile terminal 5 wishes to perform an intra-domain handover, it adds (5) the permission mark to the re-registration request and sends it (5) as text to the new access router 6. The new access router 6 receives the permission flag Via a receiving unit 10 and forwards it to a processing unit 11 for checking. The processing unit 11 performs three actions for checking the authorization mark:<ul><li>Verification of the validity period for the expiry date of the authorization mark; </li><li>Verifying the identity of the access router that has created the authorization mark in a trusted list 7;</li><li>After checking the above points, a key-hashed digest is computed with the permission mark information using the authorization flag key and compared with the random number addition already present in the authorization mark.</li></ul>
p0016If the authentication check is successful, the connection update and re-authorization process is started. The new access router 6 will authenticate the re-registration requests when it receives the session key contained in the re-registration request (BU ACK message) from the mobility anchor point (MAP) 2 via a receiving unit 10. *** " If the verification fails, the access router 6 will not process the re-registration request further. If, after some time, the mobile radio terminal 5 has not yet received a response via the re-registration from the access router 6 via a transmitting unit 12, the mobile radio terminal 5 must begin an authorization and authentication process via the local AAA server 3 and the home AAA server , As with an intra-domain handover or when the device 5 is switched on.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO0122685A | Cites | World Intellectual Property Organization (WIPO) |
| SUBRAMANYAM V ET AL: "Security in mobile systems" RELIABLE DISTRIBUTED SYSTEMS, 1998. PROCEEDINGS. SEVENTEENTH IEEE SYMPOSIUM ON WEST LAFAYETTE, IN, USA 20-23 OCT. 1998, LOS ALAMITOS, CA, USA,IEEE COMPUT. SOC, US, 20. Oktober 1998 (1998-10-20), Seiten 407-412, XP010319125 ISBN: 0-8186-9218-9 | Non-patent | – |
| HUNG-YU LIN ET AL: "Authentication in wireless communications" GLOBAL TELECOMMUNICATIONS CONFERENCE, 1993, INCLUDING A COMMUNICATIONS THEORY MINI-CONFERENCE. TECHNICAL PROGRAM CONFERENCE RECORD, IEEE IN HOUSTON. GLOBECOM '93., IEEE HOUSTON, TX, USA 29 NOV.-2 DEC. 1993, NEW YORK, NY, USA,IEEE, 29. November 1993 (1993-11-29), Seiten 550-554, XP010109722 ISBN: 0-7803-0917-0 | Non-patent | – |
| MOLVA R ET AL: "AUTHENTICATION OF MOBILE USERS" IEEE NETWORK, IEEE INC. NEW YORK, US, Bd. 8, Nr. 2, 1. März 1994 (1994-03-01), Seiten 26-34, XP000515077 ISSN: 0890-8044 | Non-patent | – |
12 members in 8 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 0210962 | European Patent Office (EPO) | W | |
| 0210962 | European Patent Office (EPO) | W | |
| EP2002010962 | – | – | – |
| WO2002EP10962 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO2004034717A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002342779A1 | Australia | A1 | |
| US2005079866A1 | United States of America | A1 | |
| EP1547418A1 | European Patent Office (EPO) | A1 | |
| JP2006501780A | Japan | A | |
| US7171202B2 | United States of America | B2 | |
| EP1547418B1This record | European Patent Office (EPO) | B1 | |
| AT387825T | Austria | T | |
| ATE387825T1 | Austria | T1 | |
| DE50211804D1 | Germany | D1 | |
| ES2300484T3 | Spain | T3 | |
| JP4278614B2 | Japan | B2 |
46 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Transfer of patentPC2A | PC2A | ES | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04Q0007380000R079 | R079 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04Q0007380000R079 | R079 | DE | |
| Change of representativeR082 | R082 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation not filedEN | EN | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Title (correction)VERIFYING CHECK-IN AUTHENTICATION BY USING AN ACCESS AUTHENTIFICATION TOKENRTI1 | RTI1 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1547418
- Publication, DOCDB
- 1547418
- Publication, EPODOC
- EP1547418
- Application
- 2779443
- Application, DOCDB
- 02779443
- Application, EPODOC
- EP20020779443
Titles3
- German
- Überprüfen der Einbuchungsberechtigung durch eine Zugangs-Berechtigungsmarke
- English
- Verifying check-in authentication by using an access authentification token
- French
- Verification d'une habilitation d'enregistrement par jeton d'habilitation d'acces
Classification
- CPC, 7
- H04L63/0807
- H04L63/12
- H04L63/1458
- H04W8/06
- H04W12/062
- H04W12/108
- H04W12/122
- IPC, 7
- H04Q7 38
- H04L29 06
- H04W12 00
- H04W12 06
- H04W12 08
- H04W36 00
- H04W60 00
Designated states1
- Contracting states, 1
- Italy