Nova Patents
EP1624639A1

Sim-based authentication

Abstract

SIM-based authentication over access networks not supporting the security protocol 802.1X, comprising the steps of: SIM-authentication, wherein a user, by means of a user terminal 40 and via a WISP network 20, authenticates towards an EAP-SIM server 31 comprised in a mobile operator network 30; extracting information used to derive temporarily credentials from an access accept message emanating from said EAP-SIM server 31, and storing these as username/password in a database 35;. Further comprising back-authentication, wherein a user performs a login towards a WISP access server 23 using the same username and password derived from information stored on a SIM card, Said WISP access server 23 forwards an access request and said username/password to an OSC+ 33. Further, matching said forwarded username/password with the temporary account stored in said database 35, and if credentials match, sending an accept message towards a WISP proxy 22 that sends a login accept message to said terminal 40.

EP1624639A1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 2 August 2024, 2.1 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

15 claims: 11 independent, 4 dependent

  1. 1
    A method for SIM-based authentication over access networks (20, 30) not supporting the security protocol 802.1X, comprising the steps of:- SIM-authentication, wherein a user, by means of a user terminal (40) and via a WISP network (20), authenticates towards an EAP-SIM server (31) comprised in a mobile operator network (30), - in a mobile operator server OSC+ (33), extracting from a message sent from the EAP-SIM server (31) in the mobile operator network (30), information used to derive temporarily credentials, e.g. Master Session Key, MSK, and Chargeable User ID, CUID, parameters, from an RADIUS access accept message emanating from the EAP-SIM server (31), and storing the temporary credentials (username/password) in a local database (35);- deriving temporary credentials (username/password) in the user terminal (40) from information stored on a SIM-card and - back-authentication, wherein a user performs a login towards a WISP access server (23) using said username/password, and wherein said WISP access server (23) forwards an access request and said username/password to said mobile operator server OSC+ (33);and - in said mobile operator server OSC+ (33), matching said forwarded username/password with the temporary credentials stored in said local database (35), and if credentials match, sending a RADIUS-access accept message towards a WISP RADIUS proxy (22) that sends a login accept message to said user terminal (40).
  2. 4
    The method of any preceding claim, wherein said mobile operator server OSC+ (33) extracts temporarily credentials, e.g. the Master Session Key, MSK, and Chargeable User ID, CUID, parameters.
  3. 5
    The method of any preceding claim, wherein the temporary credentials are of the form:usr=IMSI@MobileOperator.com/pw=f(MSK), where usr is the username, IMSI is the International Mobile Subscriber Identity and the MobileOperator.com is the realm part of the mobile operator, pw is the password, and MSK is the Master Session Key and f(MSK) denotes some function to derive a syntactically correct password from the MSK.
  4. 6
    The method of any preceding claim, wherein said WISP RADIUS proxy (22) inspects the realm part of said username.
  5. 7
    The method of any preceding claim, wherein said mobile operator server OSC+ (33) matches the supplied username/password with the temporary account stored in the local database (35).
  6. 8
    The method of any preceding claim, wherein unused credentials will be automatically removed from the local database (35).
  7. 9
    A system for SIM-based authentication over access networks (20, 30) not supporting the security protocol 802.1x, said system comprising a WISP network (20) communicatively connected to a mobile operator network (30) by means of a routers (24, 34), characterised in that :- a user terminal (40) configured to perform SIM-authentication, whereby said user terminal (40) is configured to, via said WISP network (20), authenticate towards an EAP-SIM server (31) comprised in said mobile operator network (30), - a mobile operator server OSC+ (33) configured to extract information used to derive temporarily credentials, e.g. Master Session Key, MSK, and Chargeable User ID, CUID, parameters, from an access accept message emanating from said EAP-SIM server (31);configured to store these as username/password in a local database (35);- said user terminal (40) further being configured to derive temporary credentials (username/password) from information stored on a SIM-card, configured for back-authentication, whereby said user terminal (40) is configured to perform a login towards a WISP access server (23) using said username/password, and whereby said WISP access server (23) is configured to forward an access request and said username/password to said mobile operator server OSC+ (33);and - said mobile operator server OSC+ (33) further being configured to match said forwarded username/password with the temporary account stored in said local database (35), and if credentials match, configured to send a RADIUS-access accept message towards a WISP RADIUS proxy (22) that is configured to send a login accept message to said user terminal (40).
  8. 12
    The system of any of the claims 9 - 11, wherein said temporary credentials are configured to be of the form:usr=ISMI@MobileOperator.com/pw=f(MSK), where usr is the username, IMSI is the International Mobile Subscriber Identity the MobileOperator.com is the web address of the mobile operator, pw is the password, and MSK is the Master Session Key, and f(MSK) denotes some function to derive a valid password from the MSK.
  9. 13
    The system of any of the claims 9 - 12, wherein said WISP RADIUS proxy (22) is configured to inspect the realm part of the username/password.
  10. 14
    The system of any of the claims 9 - 13, wherein said mobile operator server OSC+ (33) is configured to match the supplied username/password with the temporary account stored in the local database (35).
  11. 15
    The system of any of the claims 9 - 14, wherein said mobile operator server OSC+ (33) is configured to automatically remove unused credentials from said local database (35).