Method for securing the transmission of short messages
Abstract
The method involves requesting a public key (Kpu2) from one mobile equipment (EM2) by another mobile equipment (EM1). The key is received and stored in a temporary memory accompanied by identifier (ID2) of the equipment (EM2). A short messaging service (SMS) message is encrypted with the key. The encrypted message is received and decrypted by the equipment (EM2) with a private key (Kpr2) of the equipment (EM2). An independent claim is also included for a safety module for mobile equipment.

Term
Term ended
Projected expiry passed 29 January 2024, 2.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
12 claims: 10 independent, 2 dependent
- 1Méthode de sécurisation de la transmission de messages courts (SMS, MMS) entre un premier et un second équipement mobile (EM1, EM2) via un réseau de communication mobile (NET) caractérisée en ce qu'elle est basée sur la cryptographie à clés asymétriques utilisant une clé publique (Kpu1, Kpu2) associée à une clé privée (Kpr1, Kpr2) propre à chaque équipement mobile (EM1, EM2) et comprend les étapes suivantes:• requête de la clé publique (Kpu2) du second équipement (EM2) par le premier équipement mobile (EM1),• réception et stockage de cette clé publique (Kpu2) dans une mémoire temporaire accompagnée de l'identifiant (ID2) du second équipement mobile (EM2),• encryption du message court SMS avec ladite clé publique (Kpu2) reçue,• transmission du message encrypté Kpu2(SMS) au second équipement mobile (EM2) via le réseau mobile (NET).• réception et décryption du message (SMS, EMS) par le second équipement mobile (EM2) avec la clé privée (Kpr2) dudit second équipement (EM2). securing method of the transmission of short messages (SMS, MMS) between a first and a second mobile equipment (EM1, EM2) via a network mobile communication (NET) characterized in thatit is based on the asymmetric key cryptography using a public key (Kpu1, Kpu2) associated with a private key (Kpr1, Kpr2) specific to each mobile equipment (EM1, EM2) and comprises the following steps:request the public key (Kpu2) of the second device (EM2) by the first mobile equipment (EM1)receipt and storage of this public key (Kpu2) in a memory accompanied by the temporary identifier (ID2) of the second mobile equipment (EM2)encryption of SMS short message with said public key (Kpu2) received,Kpu2 encrypted transmission of the message (SMS) to the second mobile equipment (EM2) via the mobile network (NET).reception and decryption of messages (SMS, EMS) by the second device mobile (EM2) with the private key (Kpr2) said second equipment (EM2).
- 3Method according to claims 1 and 2, characterized in thata verification the identifier (ID2) of the second mobile device (EM2) is performed including the following steps:transmission with the request of the public key (Kpu2) of the second equipment (EM2) an identifier (ID2) of the second equipment concerned, and comparison with the identifier (ID2 ") received in returnwhen the result of the comparison is positive, encrypting the short message (SMS1) with the public key (Kpu2) received. Méthode selon les revendications 1 et 2, caractérisée en ce qu'une vérification de l'identifiant (ID2) du second équipement mobile (EM2) est effectuée comprenant les étapes suivantes: • transmission avec la requête de la clé publique (Kpu2) du second équipement (EM2) d'un identifiant (ID2) du second équipement concerné, et comparaison avec l'identifiant (ID2') reçu en retour,• lorsque le résultat de la comparaison est positif, encryption du message court (SMS1) avec la clé publique (Kpu2) reçue.
- 4Method according to claims 1 to 3, characterized in thatit comprises an additional step of transmission, with the request of the public key (Kpu2) the second mobile device (EM2) of the identifier (ID1) of the first equipment mobile (EM1) and comparison with the identifier (ID1 ') returned. Méthode selon les revendications 1 à 3, caractérisée en ce qu'elle comporte une étape supplémentaire de transmission, avec la requête de la clé publique (Kpu2) du second équipement mobile (EM2) de l'identifiant (ID1) du premier équipement mobile (EM1) et comparaison avec l'identifiant (ID1') retourné.
- 5Method according to claims 3 and 4, characterized in thata message error is displayed when the result of the comparison is negative, said message encouraging the repetition of the transmission of a short message encrypted causing request a public key associated with the private key of the message recipient short. Méthode selon les revendications 3 et 4, caractérisée en ce qu'un message d'erreur est affiché lorsque le résultat de la comparaison est négatif, ledit message incitant la répétition de la transmission d'un message court encrypté entraînant la requête d'une clé publique associée à la clé privée du destinataire du message court.
- 6Method according to claims 3 and 4, characterized in that the second mobile equipment (EM2) returns the identifier (ID2 ') of said second device mobile (EM2) and ID (ID1 ') of the first mobile equipment (EM1) with the key Public (Kpu2) said second mobile equipment (EM2). Méthode selon les revendications 3 et 4, caractérisée en ce que le second équipement mobile (EM2) retourne l'identifiant (ID2') dudit second équipement mobile (EM2) et l'identifiant (ID1') du premier équipement mobile (EM1) avec la clé publique (Kpu2) dudit second équipement mobile (EM2).
- 8Method according to Claims 3, 4 and 7, charac See in that the server (SER) returns the identifier (ID2 ') of the second mobile device (EM2) and the identifier (ID1 ') of the first mobile device (EM1) with the public key (Kpu2) of said second mobile equipment (EM2). Méthode selon les revendications 3, 4 et 7, caractérisée en ce que le serveur (SER) retourne l'identifiant (ID2') du second équipement mobile (EM2) et l'identifiant (ID1') du premier équipement mobile (EM1) avec la clé publique (Kpu2) dudit second équipement mobile (EM2).
- 9Method according to claims 1 to 8, characterized in that equipment mobile (EM1, EM2) is constituted by a mobile phone which is connected a security module consisting of a SIM card (SIM1, SIM2) for the identification of said mobile phone on the network (NET). Méthode selon les revendications 1 à 8, caractérisée en ce que l'équipement mobile (EM1, EM2) est constitué par un téléphone mobile auquel est connecté un module de sécurité constitué par une carte SIM (SIM1, SIM2) servant à l'identification dudit téléphone sur le réseau mobile (NET).
- 10Method according to claims 1 and 9, characterized in that the storage operations, management of public and private keys, encryption and decryption of short messages are carried by the phone's SIM card mobile. Méthode selon les revendications 1 et 9, caractérisée en ce que les opérations de stockage, de gestion des clés publique et privée, d'encryption et de décryption des messages courts sont effectuées par la carte SIM du téléphone mobile.
- 11Method according to claims 1 to 10, characterized in that the request the public key (Kpu2) is performed during the establishment of a communication voice between mobile equipment (EM1, EM2). Méthode selon les revendications 1 à 10, caractérisée en ce que la requête de la clé publique (Kpu2) s'effectue lors de l'établissement d'une communication vocale entre deux équipements mobiles (EM1, EM2).
- 12Module de sécurité pour équipement mobile servant à l'identification dudit équipement sur le réseau mobile caractérisé en ce qu'il comporte des moyens matériels et logiciels de stockage et de gestion d'une clé privée et d'une clé publique d'un algorithme à clés asymétriques et une unité d'encryption de messages courts à transmettre et une unité de décryption de messages courts cryptés reçus. Security module for mobile equipment used for the identification of said equipment on the mobile network characterized in thatit comprises means hardware and software for storage and management of a private key and a public key an asymmetric key algorithm and an encryption unit of short messages and transmitting a decryption unit short encrypted messages received.
Independent claims10
32 paragraphs, as filed
The present invention relates to the field of mobile telecommunications. More particularly, it relates to transmission services of short messages like SMS (Short Message Service) or MMS (Multimedia Message Service) via a mobile network GSM (Global System for Mobile Communications), GPRS (General Packet Radio System) or UMTS (Universal Mobile Telecommunications System).
The use of these short messages SMS and / or MMS by subscribers to a network mobile communication is constantly increasing due to their price relatively low unit and independence of the period compared with standard telephone conversations.
The main drawback found in the delivery of those messages a to another subscriber through the mobile network is that they are transmitted while the clear phone conversations transmitted over the same network are encrypted to prevent abusive plays by third parties.
To expand the use of the SMS service and / or MMS to Messages with confidential content, some transmission protection thereof, at least in a manner similar to that applied to voice transmissions, is required.
The object of the present invention is therefore to secure the transmission of short messages to prevent their capture by third parties which may use fraudulently to the detriment of subscribers and / or operator of mobile telecommunications.
This object is achieved by a method of securing the transmission of messages short between a first and a second mobile device via a network mobile communication system characterized in that it is based on cryptography to asymmetric keys using a public key associated with a private key to and each mobile equipment includes the following steps: <ul><li>request the public key of the second device by the first device mobile,</li><li>receipt and storage of this public key in a temporary memory accompanied by the identifier of the second mobile device,</li><li>encryption of the short message with said received public key,</li><li>transmission of encrypted message to the second mobile equipment via the mobile network.</li><li>reception and decryption of the message by the second mobile equipment with private key of said second device.</li></ul>
The aforementioned mobile devices are made according to one embodiment preferred embodiment of the invention by cell phones also called phone mobile or cellular phones. These devices are equipped with a security module called SIM card enabling identification of the mobile network.
The identifiers transmitted during the process of acquiring the public key correspond either to one phone number or full IMSI number (International Mobile Subscriber Identification) that uniquely identifies a subscriber to the mobile network including among other telephone number.
Before sending an encrypted short message from a mobile equipment another, a public key is requested, in a first variant, with the mobile equipment to which the short message is intended. In a first phase, the request of the public key can be performed by a first communication between the first and the second mobile equipment. After receiving this key is stored and then, during a second phase, the transmission of the short message may have place after encryption thereof with the stored public key. For example, when these mobile devices comprise mobile phones, a user To establish voice communication with its corresponding B to ask for her key. User B will send its key to the user A by means of a short message SMS for example. Upon receipt, the user A stores this key that will be used to encrypt an SMS message that only User B can decrypt with his private key.
The received public key may be verified during the establishment of the first communication either by voice recognition correspondents or by comparing the number dialed when calling with the same number returned by the mobile equipment of the corresponding accompanying the key at its transmission.
When the result of this comparison is positive, that is to say when the number compound and the number returned by the corresponding match, the public key received and accepted the short message encryption can be performed. A message encrypted and can then be decrypted when received by correspondent using the private key stored in the mobile equipment.
In the case of a negative comparison, the received key is rejected and no Encryption can take place. In such cases of non-recognition matching, the user of the mobile equipment can be notified by a message adequate error and start the call tracking the motion of a key to its corresponding.
Method for securing according to the method of the invention with detection of corresponding or more precisely with the verification of the identifier of the origin of key or the validation comprises the further steps of:<ul><li>transmission with the request of the public key of a second equipment identifier of the second equipment concerned, and comparison with the identifier received back,</li><li>when the result of the comparison is positive, encrypting the short message with the received public key.</li></ul>
The storage and management of private and public keys and the operations Encryption and decryption are performed by the security module respective mobile equipment usually called SIM card (Subscriber Identity Module). Asymmetric encryption algorithms public and private keys used to are usually the type RSA (Rivest, Shamir, Adelman) or related. The advantage principal of such algorithms is the personal private key for each module security (SIM) is never exchanged between the mobile equipment, only the Public keys are transmitted. Thus the capture of a public key is useless to decrypt a short message without knowledge of the private key correspondingly.
According to a variant of the method of the invention, recognition of identifiers mobile devices can be double by comparing two identifiers returned by the correspondent. Indeed, in a transmission over a network mobile, the first device transmits the destination identifier and its identifier specific to the second mobile equipment. It returns with its key public, the identifier of the first equipment as well as its own identifier. The first mobile equipment can thus perform a comparison of its own identifying with the one returned by the second device and another comparison the identifier of the second equipment previously provided with one returned by the second equipment. This double comparison helps prevent errors transmission and safer validation of the public key.
The present invention also concerns a security module or SIM card a mobile device or mobile phone including hardware and software for storage and management of a private key and a public key asymmetric key algorithm and an encryption unit short messages of the SMS and / or MMS to send and a message decryption unit short encrypted received.
In a second embodiment of the present invention, the mobile equipment wishing transmit encrypted short message to another mobile device requesting key public its corresponding with a central server instead of equipment called mobile.
In this configuration, the central server stores a database in a set of identifiers as phone numbers or IMSI numbers each associated with a public key. And before transmission of a short message confidential content, the mobile phone is primarily addressed to the central server to obtain the public key corresponding to the number receiving the message. This key is used to encrypt the short message to be transmitted which is then decrypted, after receipt, with the recipient's private key.
In a variant of the configuration with the central server, it may be considered trustworthy, making the steps recognition identifiers transmitted and received superfluous.
The invention will be better understood from the detailed description which follows and which refers to the accompanying Figures given by way of non-limiting example, know:<ul><li>Figure 1 shows a block diagram showing the steps of the application of a key public and the recognition of mobile equipment called.</li><li>2 illustrates the step of transmitting an encrypted short message</li><li>3 illustrates the variant of the method of the invention where a public key is sought from a central server.</li></ul>
1 shows two mobile devices or mobile phones EM1 and EM2 each provided with a security module or respectively SM1 and SM2 SIM card exchanging data according to the first variant of the method of the invention. This variant differs in that the public key (Kpu2) is provided by the mobile phone (EM2) to the phone EM1 following a request rq (Kpu2) issued by this last. When a call is accompanied by a transmission of a message command short encrypted SMS, the first phone transmits the request rq (Kpu2) in the second phone with its identifier ID1 and ID2 that of his party. These identifiers (ID1, ID2) are in most cases the phone number of mobile phones (EM1, EM2) respectively. After receiving this request, the EM2 phone communicates the corresponding public key associated with the Kpu2 private key Kpr2 both stored in SIM2. This key is accompanied phone number caller ID1 'and that of the corresponding phone ID2 '. After receiving this data, the phone stores them in calling EM1 a temporary memory for verification. Indeed, before accepting a key Encryption Kpu2, telephone EM1 who required checks whether it originates from the EM2 of the called phone by comparing the numbers (ID1 'ID2') returned with those (ID1, ID2) that passed before the first call. he This is a test of equality on the one hand between the ID1 number of phone calling EM1 and the number ID1 'returned by the corresponding (ID1 = ID1') and secondly between the ID2 number corresponding transmitted and the ID2 'returned by the latter (ID2 = ID2 "). This double check may be reduced, according to a variant, only that of the serial numbers of corresponding transmitted and returned (ID2 = ID2 "). If these equations are true, the public key of Kpu2 phone EM2 matching is stored and used for the encryption of the short message SMS1 these operations being carried out by the SIM card (SM1).
In the case of an unsuccessful comparison, the received key is considered invalid and erased from the temporary memory which can cause a display error message on the phone's screen EM1. The subscriber is EM1 asked to repeat a new transmission of an encrypted SMS messages resulting new application of a public key with a new number recognition.
2 shows the case of transmission of an encrypted SMS short message with the public key corresponding Kpu2. The latter will be able to decrypt it message using the private key Kpr2 stored in the SIM card associated with the key Public Kpu2 with which the message is encrypted.
Public keys successfully received from called parties and validated can be stored on the SIM card into the appropriate directory along with the phone numbers. These keys allow thus stored subsequently direct encryption of SMS short messages without first go through the steps to request the key and verification phone number corresponding.
3 shows the second variant of the method of the invention wherein the mobile phone EM1 is seeking the public key of Kpu2 phone EM2 corresponding to a central server SER. It administers a database containing a list of identifiers couples or phone numbers - public keys corresponding (ID1 - Kpu1 ... Dn - Kpun). In addition, the central server SER, can depend on one or more mobile operators offering the service encrypted SMS message transmission, can be considered worthy of trust. Therefore, the simple verification or double numbers phone server (IDs IDs = ') or appellant (ID1 = ID1), as described in first variant where the key is provided by the corresponding phone becomes optional or unnecessary.
A public key obtained from the central server (SER) can also be stored in the phone numbers directory as in the variant where the key comes from the party to which the encrypted message is intended.
According to this second variant, the method of the invention may be fully automated, that is to say that the above steps from the query of the key public until the transmission of encrypted short message are executed rear transparent plan for the user of the mobile equipment. Indeed, the central server is permanently connected to the mobile network which allows to require a public key in any time even if the mobile equipment or correspondent telephone tripped or disconnected from the network.
Upon receipt, by phone EM1, the public key transmitted by the Kpu2 SER server, the message is SMS1 encrypted with the public key and Kpu2 EM2 transmitted to the corresponding phone with ID1 and ID2 identifiers.
According to this automated variant, a storage of the received public key may be proposed by a display proper message before or after sending the message SMS1 encrypted. In this way, further sending a new message SMS1 encrypted to the same correspondent no longer requires application of the key with the central server (SER) but only a key fetch control of the memory of the SIM card.
The automatic method can thus be supplemented by a preliminary step Search the key recipient of the encrypted SMS message in the memory of the SIM card before running the request of said key from the server (SER) in case the key is not available in the SIM card.
Alternatively, the SMS message transmission service can be encrypted limited to users listed in the SER server database. In such case, a check of the calling telephone number can be performed by confrontation with those on the list server. When this verification fails because of the absence of a number from this list, an SMS short message can be transmitted by the server SER to encourage non-registered users to sign up SMS transmission service encrypted.
This check can also be performed with the phone number of corresponding when the server receives a public key request. In the case where the request does not result in corresponding recording default, the server transmits a short message of invitation to registration in the database server data. The user who issued the request is informed that he can not transmit short message encrypted in this particular match with a wrench After the server. By cons, it still has the ability to call his correspondent asking its key by voice and transmit the encrypted message as described above.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| FR2952211A1 | Cited by | France | – | Search report | – |
| FR3050301A1 | Cited by | France | – | Search report | – |
| EP2320618A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| WO2009121046A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US9848081B2 | Cited by | United States of America | – | Applicant | – |
| US10778658B1 | Cited by | United States of America | – | Applicant | – |
| US9680803B2 | Cited by | United States of America | – | Search report | – |
| US10917440B1 | Cited by | United States of America | – | Applicant | – |
| WO2009121046A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| FR2988248A1 | Cited by | France | – | Search report | – |
| EP1830296A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP3236429A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP2015553A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US9680803B2 | Cited by | United States of America | – | Applicant | – |
| US9848081B2 | Cited by | United States of America | – | Applicant | – |
| US2011145564A1 | Cited by | United States of America | – | Pre-grant | – |
| US8225380B2 | Cited by | United States of America | – | Applicant | – |
| US8325925B2 | Cited by | United States of America | – | Applicant | – |
| US10789594B2 | Cited by | United States of America | – | Applicant | – |
| US10395458B2 | Cited by | United States of America | – | Applicant | – |
| US9853926B2 | Cited by | United States of America | – | Applicant | – |
| US2003078058A1 | Cites | United States of America | X | Search report | 1,12 |
| US2003078058A1 | Cites | United States of America | X | Search report | 1,12 |
| GB2387505A | Cites | United Kingdom | X | Search report | 1,12 |
| GB2387505A | Cites | United Kingdom | X | Search report | 1,12 |
| US6081601A | Cites | United States of America | XY | Search report | 1,7-12 |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 04100311 | European Patent Office (EPO) | A | |
| EP20040100311 | – | – | – |
7 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | EP | |
| Designated country de not longer valid8566 | 8566 | DE | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1569482
- Publication, DOCDB
- 1569482
- Publication, EPODOC
- EP1569482
- Application
- 4100311
- Application, DOCDB
- 04100311
- Application, EPODOC
- EP20040100311
Titles3
- German
- Verfahren zur Sicherung der Übertragung von Kurznachrichten
- English
- Method for securing the transmission of short messages
- French
- Méthode de sécurisation de la transmission de messages courts
Classification
- CPC, 7
- H04L63/0442
- H04L9/08
- H04L9/30
- H04L63/0853
- H04W12/02
- H04W4/14
- H04W12/0017
- IPC, 4
- H04L9 08
- H04L9 30
- H04L29 06
- H04W12 00
Designated states31
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
- Extension states, 4
- Albania
- Lithuania
- Latvia
- North Macedonia