System and method for secure transaction of data between wireless communication device and server
Abstract
The present application provides a system and method for a set of Extensible Authentication Protocols (EAPs) based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms (with a suitable permutation) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost. According to one embodiment, a method and system of ECC and SKE based EAPs (through a permutation technique) which can avoid replay attacks. The application also provides a light weight security with better performance in comparison to the lower layer chip level security provided by 2G, 3G or 4G Applications and no certificates exchanged during the communication.

Term
4.7 yearsto projected expiry
Projected expiry 27 May 2031, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 3 independent, 12 dependent
- 1A method of authenticating a wireless communication device, comprising the steps of:transmitting a first message to a server from a communication device;generating a random number at the server, the said random number is masked;generating a first encrypted signal at the server by bundling a second message with the masked random number;transmitting the first encrypted signal from the server to the communication device;decrypting the first encrypted signal at the communication device;retrieving the random number at the communication device, the mask is removed;generating a signature signal at the communication device;generating a second encrypted signal at the communication device;transmitting the second encrypted signal from the communication device to the server;decrypting the second encrypted signal at the communication device;validating the second encrypted signal by comparing the corresponding signature values of the server and the communication device at the server;generating a response based on the comparison of the signature values at the server;and transmitting the response to the communication device by the server.
- 2The method of Claim 1, wherein the first encrypted signal is generated by bundling the second message with at least one of the hash values associated with the masked random number, a public key and the nonce value associated with the random number.
- 3The method of Claim 1, wherein encrypting the second signal by bundling a third message with a signature signal associated with a private key of the communication device.
- 4A method of authenticating a wireless communication device, comprising the steps of:transmitting a first message to a server from a communication device;generating a first random number and a prime number at the server, the said random and prime numbers are masked;generating a first encrypted signal at the server by bundling a second message with at least one of the masked random number and the masked prime number;transmitting the first encrypted signal from the server to the communication device;decrypting the first encrypted signal at the communication device;retrieving the first random number and the prime number at the communication device, removing the corresponding mask;generating a second random number at the communication device;generating a second encrypted signal at the communication device;transmitting the second encrypted signal from the communication device to the server;decrypting the second encrypted signal at the communication device;retrieving the second random number at the communication device;validating the second encrypted signal by comparing the corresponding hash values and nonce values of the server and the communication device at the server;generating a response based on the comparison of the hash values and nonce values at the server;and transmitting the response to the communication device by the server.
- 5The method of Claim 4, further comprising transmitting a 192-bit pre-shared private (encryption) key from the server to the communication device using an AES-CTR algorithm.
- 6The method of Claim 4, wherein the second random number is generated using a Pseudo Random Number Generator (PNRG) method.
- 7The method of Claim 4, wherein the second encrypted signal is generating by bundling a third message with at least one of the hash value associated with the second random number and nonce value associated with a private key, the said private key is generated using a Deterministic Random Sequence Generation (DSRG) process.
- 8The method of Claim 4, wherein decrypting the second encrypted signal includes retrieving the private key.
- 9The method of Claim 4, wherein validating the second encrypted signal by comparing either one of the corresponding value of hash value associated with the second random number and nonce values associated with the private key of the communication device.
- 10A system for authenticating a wireless communication device, comprising:a random number generator at a server configured to generate a first random number, the random number is masked;a prime number generator at the server configured to generate a prime number;a first encryption module at the server configured to generate a first encrypted signal by bundling a second message with at least one data signal from the first random number or the prime number;a communication device configured to receive the first encrypted signal from the server;a first decryption module at the communication device configured to decrypt the first encrypted signal and retrieve at least one of the first random number or prime number, the corresponding mask is removed;a random number generator at the communication device configured to generate a second random number;a signature signal generation module at the communication device configured to generate a signature signal;a second encryption module at the communication device configured to generate a second encrypted signal by bundling a third message with at least one data signal from the signature signal or the second random number;a transceiver at the communication device configured to transmit the second encrypted signal from the communication device to the server;a second decryption module at the server configured to decrypt the second encrypted signal;and a validation module at the server configured to validate the second encrypted signal by comparing at least one of the corresponding signature values, hash values and nonce values of the server and the communication device.
- 11The system of Claim 10, wherein the first encryption module is configured to generate the first encrypted signal by bundling the second message with at least one of the hash value associated with the masked random number, hash value associated with the random number, a public key and the nonce value associated with the random number.
- 12The system of Claim 10, wherein the second encryption module is configured to generate the second encrypted signal by bundling the third message with at least one of the a private key, the corresponding signature signals associated therewith the private key and hash value of the second random number.
- 13The system of Claim 10, wherein the second decryption module is configured to retrieve the private key from the second encrypted signal.
- 14The system of Claim 10, wherein validation module is configured to validate the second encrypted signal by comparing either one of the corresponding value of a public key of the communication device, hash values and nonce values of the server and the communication device.
- 15The system of Claim 10, wherein the communication device is a wireless communication device enabled to operate using a 2G, 3G, or 4G communication protocol.
Independent claims15
79 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
0001The present application relates to the field of wireless communications. Particularly, this application relates to a system and method for secure transaction of data between at least one wireless communication device and a server by using lightweight Extensible Authentication Protocols (EAPs) based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms.
BACKGROUND OF THE INVENTION
0002In the mobile and wireless communication, authentication methods are generally used to gain network access. The communication server (either for mobile or wireless) provides accessibility must have a set of processes and protocols to verify user's identity. There is a need of a standard way for verifying user's logon, monitoring user's network usage and customer billing. Currently there are standards and protocols that can fulfill the above criteria for Authentication, Authorization and Accounting (AAA) purposes. But some of them are not secure and their performance will not meet 3G mobile communication requirements.
0003However, the current mobile and wireless authentication mechanisms employ the usage of Certificates. The Authorization protocols must support some notion of a "charging certificate". These Certificates being heavy weight in size affect the performance of the Mobile Application. With the conservative standards set by many Institutions chiefly in the mobile banking sector there is a requirement for light weight protocols which help in ensuring optimum performance of mobile applications through wireless media.
0004Moreover, mobile and wireless devices, like smart phones, PDAs, cellular phones and Remote control systems, play an increasingly important role in the digital environment. The pervasive use of mobile and wireless devices brings new security and privacy risks and with the extensive use of mobile devices consumers continuously leave traces of their identities and transactions, sometimes even by just carrying the devices around in their pockets. Since providing true privacy is hard as hiding identity information is irrelevant as long as some other linkable information is associated with the messages, the usage of a light weight protocol will help provide effective solutions to a majority of mobile and wireless applications.
0005Some of the inventions which deal with providing systems and methods for secure transaction of data between at least one wireless communication device and a server are: <ul id="ul0001" list-style="none" compact="compact"><li><patcit id="pcit0001" dnum="US20090180612A"><text>US Patent Publication Number 20090180612 filed by Leu et al</text></patcit> discloses about an authentication method employing ECC. It is applicable to a mobile broadcast TV system having one or more head end systems, at least a transmitter, and at least a mobile set. The authentication method comprises at least one request message from mobile sets simultaneously or in a short period of time arriving at a head end system for authentication; manipulating each broadcast authentication message by ECC; manipulating each service request message by ECC and pairing operation; performing a mutual authentication between the head end system and mobile sets by ECC and pairing operation; and broadcasting one group of authentication messages to all the mobile sets of many requests arrived at the head end system simultaneously or in a short period of time for the same service.</li></ul>
0006United States Patent number <patcit id="pcit0002" dnum="US7243232B"><text>7243232 filed by Vanstone et al</text></patcit> discloses about a key establishment protocol that includes the generation of a value of cryptographic function, typically a hash, of a session key and public information. This value is transferred between correspondents together with the information necessary to generate the session key. Provided the session key has not been compromised, the value of the cryptographic function will be the same at each of the correspondents. The value of the cryptographic function cannot be compromised or modified without access to the session key.
0007United States Patent number <patcit id="pcit0003" dnum="US7716482B"><text>7716482 filed by Jung et al</text></patcit> discloses about a conference session key distribution method used in an ID-based cryptographic system includes selecting two different temporary secret keys, generating a message and generating session key generation variables using the temporary secret keys of a session initiating party. Only valid participating parties receive the session key generation variables. Each party determines the session shared key from the session key generation variables.
0008United States Patent number <patcit id="pcit0004" dnum="US6658476B"><text>6658476 filed by Van C. Van</text></patcit> discloses about a client-server protocol support list in the context of standard request-response protocols such as the HyperText Transport Protocol (HTTP). In one embodiment, a method includes receiving a request according to a predetermined transport protocol. In response to receiving the request, the method transmits a list of supported client-server protocols in order of server preference, in accordance with the predetermined transport protocol. In one embodiment, the request is an OPTIONS request under HTTP. In one embodiment, the list is not a complete list of the protocols supported by the server.
0009<patcit id="pcit0005" dnum="US20100031051A"><text>US Patent Publication number 20100031051 filed by Machani et al</text></patcit> discloses about a method of authenticating and encrypting a client-server communication, comprising the steps of: a) generating a first one-time password (OTP1) and a second one-time password (OTP2) from a cryptographic token; b) generating an encryption key (K_ENC) and a MAC key (K_MAC) based on OTP2; c) preparing and protecting the client data using K_ENC and K_MAC; d) sending a request message from the client to the server, the request message containing the protected client data, a cryptographic token identifier (TID) and OTP1; e) validating OTP1 at the server, and generating OTP2 at the server upon successful validation; f) deriving K_ENC and K_MAC from OTP2 at the server; g) processing the request message and generating result data h) encrypting the result data using K_ENC and creating a digest using K_MAC; i) sending the encrypted result data to the client; and i) decrypting the result data at the client using K_ENC and verifying the authenticity of the result data using K_MAC.
0010United States Patent number <patcit id="pcit0006" dnum="US6189098B"><text>6189098 filed by Burton S. Kaliski, Jr.</text></patcit> discloses about a protocol for establishing the authenticity of a client to a server in an electronic transaction by encrypting a certificate with a key known only to the client and the server. The trust of the server, if necessary, can be established by a public key protocol. The client generates and sends over a communications channel a message containing at least a part of a certificate encrypted with the server's public key or a secret session key. The server receives and processes the message to recover at least part of the certificate, verifies and accepts it as proof of the client's authenticity.
0011United States Publication number filed <patcit id="pcit0007" dnum="US20070189527A"><text>20070189527 by Brown et al</text></patcit> discloses about an elliptic curve random number generator avoids escrow keys by choosing a point Q on the elliptic curve as verifiably random. An arbitrary string is chosen and a hash of that string computed. The hash is then converted to a field element of the desired field, the field element regarded as the x-coordinate of a point Q on the elliptic curve and the x-coordinate is tested for validity on the desired elliptic curve. If valid, the x-coordinate is decompressed to the point Q, wherein the choice of which is the two points is also derived from the hash value. Intentional use of escrow keys can provide for back up functionality. The relationship between P and Q is used as an escrow key and stored by for a security domain. The administrator logs the output of the generator to reconstruct the random number with the escrow key.
0012United States Publication number <patcit id="pcit0008" dnum="US20060098819A"><text>20060098819 filed by Zeng et al</text></patcit> discloses about methods, devices and systems for generating a plurality of public keys from one private key with the same generator of a group. A public key cryptosystem is also disclosed for generating a plurality of anonymous public keys all of which relate to the same party used for secure communications. Those anonymous public keys are generated using the same generator from one single private key. With the invention, computation is reduced, memory can be saved and security level can be improved.
0013United States Patent number <patcit id="pcit0009" dnum="US6563928B"><text>6563928 filed by Vanstone et al</text></patcit> teaches that a technique of validating the key exchange messages using ECC to prevent a man-in the middle attack.
0014None of the above mentioned prior arts provide a system and method for a lightweight and high speed certificateless extensible authentication protocols (EAPs), which occupy less memory space for storage, for mobile and wireless communications and also provide EAPs which are suitable for wireless communication devices enabled with 2G, 3G or 4G networks.
0015Thus, in the light of the above mentioned prior art, it is evident that, there is a need to have a system and method which: <ul id="ul0002" list-style="bullet" compact="compact"><li>Solves Confidentiality, Authentication, Authorization and Accounting (CAAA) issues for mobile phones and wireless devices at an affordable cost;</li><li>Provides a certificateless extensible authentication protocols (EAPs) for mobile and wireless communications;</li><li>Provides two way authentication in comparison to the current one way authentication standards; and</li><li>Provides extensible authentication protocols (EAPs) based on the ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms (with a suitable permutation) which are easy to deploy on existing wireless communication devices.</li></ul>
SUMMARY OF THE INVENTION
0016Before the present systems and methods, enablement are described, it is to be understood that this application is not limited to the particular systems, and methodologies described, as there can be multiple possible embodiments which are not expressly illustrated in the present disclosures. It is also to be understood that the terminology used in the description is for the purpose of describing the particular versions or embodiments only, and is not intended to limit the scope of the present application.
0017The primary objective is to provide a system and method for a set of Extensible Authentication Protocols (EAPs) based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms (with a suitable permutation) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost.
0018It is another significant objective to provide a method and system for a set extensible authentication protocols using ECC and SKE mechanisms. These protocols can be easily implemented into mobile and wireless communication devices.
0019It is another objective to provide a method and system of ECC and SKE based EAPs (through a permutation technique) which can avoid replay attacks.
0020It is another objective to provide a system and method for a lightweight and high speed certificateless extensible authentication protocols (EAPs), which occupy less memory space for storage, for mobile and wireless communications.
0021It is another objective to provide a certificateless extensible authentication protocols (EAPs) for mobile and wireless communications.
0022It is another objective to provide a securely transfer of registry and provision of consumer details over the communication network,
0023It is another objective to provide a light weight security with better performance in comparison to the lower layer chip level security provided by 2G, 3G or 4G applications.
0024It is another objective to provide a provision of two way authentication in comparison to the current one way authentication standards.
0025The present application uses ECC and SKE algorithms in the proposed EAP schemes. In the ECC as well SKE based EAPs, there is no certificates exchanged between wireless communication device and server. During the communication, a permutation technique (cubing a random number w.r.to a prime p = 2 mod 3)) is used between the wireless communication device and the server ends in order to avoid reply attack. The defined permutation: r → r3 = r3 mod p (where p = 2 mod 3) is a bijective map employed as a crucial role in the proposed EAPs.
0026In one aspect, a system comprises a server and a wireless communication device is communicatively coupled with each other via communication network, wherein the communication network can be selected from the group of Wide area network (WAN), Local Area Network (LAN) or Metropolitan Area Networks (MAN), internet, intranet, etc. In a preferred embodiment, the communication network is internet. The wireless communication device can be selected from one of the group of mobile handsets, smart phones, PDAs, cellular phones, or tiny devices and the wireless communication device enabled with 2G, 3G, or 4G networks. In a preferred embodiment, the wireless communication device is mobile phone.
0027According to one embodiment, any one of the three lightweight Extensible Authentication Protocols (EAPs) can be used for performing authentication process to facilitate the wireless communication device prior to being allowed access to the server. The above said lightweight Extensible Authentication Protocols (EAPs) using any one of the ECC and SKE mechanisms (with a suitable permutation) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost.
BRIEF DESCRIPTION OF THE DRAWINGS
0028The foregoing summary, as well as the following detailed description of preferred embodiments, is better understood when read in conjunction with the appended drawings. There is shown in the drawings example embodiments, however, the application is not limited to the specific system and method disclosed in the drawings. <ul id="ul0003" list-style="none"><li><figref idref="f0001">Figure 1</figref> illustrates the secure transaction of data using EAP Protocol based on ECC (Elliptic Curve Cryptography) mechanism between server and wireless communication device.</li><li><figref idref="f0002">Figure 2</figref> illustrates the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-1 between server and wireless communication device.</li><li><figref idref="f0003">Figure 3</figref> illustrates the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-2 between server and wireless communication device.</li><li><figref idref="f0004">Figure 4</figref> illustrates flow diagram with performance by using lightweight EAP Protocols for secure transaction of data between wireless communication device and server.</li></ul>
DETAILED DESCRIPTION OF THE INVENTION
0029Some embodiments, illustrating its features, will now be discussed in detail. The words "comprising," "having," "containing," and "including," and other forms thereof, are intended to be equivalent in meaning and be open ended in that an item or items following any one of these words is not meant to be an exhaustive listing of such item or items, or meant to be limited to only the listed item or items. It must also be noted that as used herein and in the appended claims, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise. Although any methods, and systems similar or equivalent to those described herein can be used in the practice or testing of embodiments, the preferred methods, and systems are now described. The disclosed embodiments are merely exemplary.
0030The Extensible Authentication Protocol (EAP) is an Internet standard that provides an infrastructure for network access clients and authentication servers (RFC 3748). It has applications in wireless networks and PPP connections, EAP does not specify the authentication mechanism itself but the way it is negotiated by the communicating parties. There are attacks due to no proper authentication protocols in EAP.
0031Accordingly, the present application provides a system and method for a set of Extensible Authentication Protocols (EAPs) based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms (with a suitable permutation) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost.
0032The present application used ECC and SKE algorithms in the proposed EAP schemes. In the ECC as well SKE based EAPs, there is no certificates exchanged between wireless communication device and server. During the communication, a permutation technique (cubing a random number w.r.to a prime p = 2 mod 3)) is used between the wireless communication device and the server ends in order to avoid reply attack. The defined permutation: r → r3 = r3 mod p (where p = 2 mod 3) is a bijective map employed as a crucial role in the proposed EAPs. There are three authentication protocols proposed below that will fulfill CAAA issues.
0033<figref idref="f0001">Figure 1</figref> illustrates the secure transaction of data using EAP Protocol based on ECC (Elliptic Curve Cryptography) mechanism between server and wireless communication device. A system 100 comprises a server 110 and a wireless communication device 120 is communicatively coupled with each other via communication network, wherein the communication network can be selected from the group of Wide area network (WAN), Local Area Network (LAN) or Metropolitan Area Networks (MAN), internet, intranet, etc. In a preferred embodiment, the communication network is internet. The wireless communication device 120 can be selected from one of the group of mobile handsets, smart phones, PDAs, cellular phones, or tiny devices and the wireless communication device enabled with 2G, 3G, or 4G networks. In a preferred embodiment, the wireless communication device 120 is mobile phone.
0034A method of communication used in the above said system 100 comprising receiving, from at least one wireless communication device 120, a connection attempt to access a server 110, performing an authentication process using lightweight Extensible Authentication Protocol (EAP) based on the Elliptic Curve Cryptography (ECC) mechanism to facilitate the wireless communication device 120 prior to being allowed access to the server 110, wherein the said authentication process comprising the following steps: In the first step of the proposed method, the wireless communication device 120 initiates the communication by sending client hello message to the server 110, wherein the client hello message includes a list of encryption algorithms that the wireless communication device 120 is prepared to use and some challenge data to be used to authenticate the server 110. The message contains the following fields: <tables id="tabl0001" num="0001"><table frame="all"><tgroup cols="2"><colspec colnum="1" colname="col1" colwidth="56mm" /><colspec colnum="2" colname="col2" colwidth="32mm" /><thead><row><entry namest="col1" nameend="col2" align="center" valign="top"><b>CLIENT HELLO MESSAGE</b></entry></row><row><entry valign="top"><b>Field</b></entry><entry valign="top"><b>Length</b></entry></row></thead><tbody><row><entry>The message type (client hello)</entry><entry>8 bits</entry></row><row><entry>The SSL version number (currently 2)</entry><entry>16 bits</entry></row><row><entry>The length of the cipher list</entry><entry>16 bits</entry></row><row><entry>The length of the session identifier</entry><entry>16 bits</entry></row><row><entry>The length of the challenge data</entry><entry>16 bits</entry></row><row><entry>The cipher list</entry><entry>variable</entry></row><row><entry>The session identifier</entry><entry>16≤ data ≤ 32 bytes</entry></row><row><entry>The challenge data</entry><entry>variable</entry></row></tbody></tgroup></table></tables>
0035The session identifier is used to match the current request with a previous one, avoiding the need for repeated authenticate and key exchange if two systems have frequent communication. When keys are selected the server 110 will cache these and, if the wireless communication device 120 provides a session identifier in the client hello message the server 110 will search the cache for this session identifier. According to one exemplary embodiment, the message contains the above mentioned fields as well as additionally 'buffer memory' field having the length of 32 bits. The field and length of the client hello message can be varied based on the requirements.
0036In the second step, the server 110 generates a random number 'r' upon receiving client hello message. According to one exemplary embodiment, the size of the random number 'r' is 100-bit. Then the server 110 computes a resultant masking process of random number { s = (r || Mask) XoR Hash(Tr_ID)} using the generated random number 'r', Mask, a transaction ID by matching hash function, wherein the Mask = 156-bits. Subsequently the server 110 encrypts a message with the resultant masking process of random number 's' thereby matching hash function, adding a nonce value for security with help of a public key 'PUB' of the wireless communication device 120 using an ECE Encryption algorithm and then the server 212 sends the encrypted message {y = ECEPUB(s), Hash(s), Nonce(r)} to the wireless communication device 120.
0037In the third step, the wireless communication device 120 retrieves the random number 'r' and the Mask { Hash(Tr_ID) XoR ECEk(y)} thereby matching hash function with help of a private key 'k' of the wireless communication device 120 upon receiving the encrypted message thereby using an ECE Decryption algorithm and subsequently the wireless communication device 120 splits the random number 'r' and the Mask and then subsequently verifies the values of the random number with the Nonce value for security and the resultant masking process of random number 's' with hash function.
0038In the fourth step, the wireless communication device 120 generates and adds the signature {signs} with message having a resultant value 'm', wherein the resultant value 'm' {m = r3 mod p = a 137-bit number} is obtained using permutation technique of the random number 'r', with respect to its private key 'k' thereby using an ECDSA-163 algorithm and subsequently the wireless communication device 120 sends the resultant message {sig_value} to the server 110.
0039In the fifth step, the server 110 verifies the signature {sig_value} of the received resultant message with help of the public key 'PUB' of the wireless communication device 120 using ECDSA-163 algorithm and subsequently the server 110 retrieves the resultant value 'm' {r3 mod p }by using permutation technique of the random number 'r'.
0040In the final step, the server 110 sends the response upon verifying the signature of the received resultant message to the wireless communication device 120.
0041Before initiating the communication in the above said system 100, initially, the server 110 registers the device and IMEI numbers of the wireless communication device 120 and then distributing customer identity and transaction identity (Cust_ID and Tr_ID) to each wireless communication devices 120 prior to being allowed access to the server 110.
0042According to one exemplary embodiment, the wireless communication device 120 is mobile phone. Accordingly, the server 110 registers mobile and IMEI numbers and distributes customer identity and transaction identity (Cust_ID and Tr_ID) to each mobile 120 prior to being allowed access to the server 110. The wireless communication device 120 uses its private key 'k' of 163-bits for Elliptic Cryptography (EC) decryption and EC signature generation and uses its public key 'PUB' for Elliptic Cryptography (EC) decryption and EC signature verification and a known Pseudo Random Number Generator (PRNG) which accepts a seed for generating the random numbers.
0043According to one embodiment, before initiating the communication in the above said system 100, initially an (Elliptic Curve Cryptography) ECC-163 set up is arranged between the wireless communication device and the server.
Example of the secure transaction of data using EAP Protocol based on ECC (Elliptic Curve Cryptography) mechanism:
0044<ol id="ol0001" compact="compact"><li>1. Tr_ID = 35422</li><li>2. Hash(Tr_ID) = 95405401234511</li><li>3. Prime number p = 101 where p is 2 mod 3</li><li>4. Wireless communication device's private key k = 199</li><li>5. Wireless communication device's public key PUB = (232, 123)</li><li>6. Server generates a random number r = 124325</li><li>7. Server computes s = 1243255783459321 XoR 95405401234511 = 1192391475877302, where Mask = 5783459321.</li><li>8. Server uses PUB and sends {(23241,34343), 3443221, 15} to the wireless communication device</li><li>9. Wireless communication device uses k on (23241, 34343) using EC Decryption and gets s from which the wireless communication device retrieves r = 124325.</li><li>10.Wireless communication device computes m = r<sup>3</sup> mod p = 87, signs m w.r.to k using ECDSA-163 algorithm and sends the sig_value = {4547, 3434} to the server.</li><li>11. Server computes m =r<sup>3</sup> mod p = 87 and uses the public key of client for verifying the signature.</li></ol>
0045<figref idref="f0002">Figure 2</figref> illustrates the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-1 between server and wireless communication device. A system 200 comprises a server 210 and a wireless communication device 220 are communicatively coupled with each other via communication network, wherein the communication network can be selected from the group of Wide area network (WAN), Local Area Network (LAN) or Metropolitan Area Networks (MAN), internet, and intranet, etc, In a preferred embodiment, the communication network is internet. The wireless communication device 220 can be selected from one of the group of mobile handsets, smart phones, PDAs, cellular phones, or tiny devices and the wireless communication device enabled with 2G, 3G, or 4G networks. In a preferred embodiment, the wireless communication device 220 is mobile phone.
0046A method of communication used in the above said system 200 comprising receiving, from at least one wireless communication device 220, a connection attempt to access a server 210, performing an authentication process using lightweight Extensible Authentication Protocol (EAP) based on the Symmetric Key Encryption (SKE) mechanism to facilitate the wireless communication device 220 prior to being allowed access to the server 210, wherein the said authentication process comprising the following steps: In the first step of the proposed method, the wireless communication device 220 initiates the communication by sending client hello message to the server 210, wherein the client hello message includes a list of encryption algorithms that the wireless communication device 220 is prepared to use and some challenge data to be used to authenticate the server 210. The message contains the following fields: <tables id="tabl0002" num="0002"><table frame="all"><tgroup cols="2"><colspec colnum="1" colname="col1" colwidth="56mm" /><colspec colnum="2" colname="col2" colwidth="32mm" /><thead><row><entry namest="col1" nameend="col2" align="center" valign="top"><b>CLIENT HELLO MESSAGE</b></entry></row><row><entry valign="top"><b>Field</b></entry><entry valign="top"><b>Length</b></entry></row></thead><tbody><row><entry>The message type (client hello)</entry><entry>8 bits</entry></row><row><entry>The SSL version number (currently 2)</entry><entry>16 bits</entry></row><row><entry>The length of the cipher list</entry><entry>16 bits</entry></row><row><entry>The length of the session identifier</entry><entry>16 bits</entry></row><row><entry>The length of the challenge data</entry><entry>16 bits</entry></row><row><entry>The cipher list</entry><entry>variable</entry></row><row><entry>The session identifier</entry><entry>16≤ data ≤ 32 bytes</entry></row><row><entry>The challenge data</entry><entry>variable</entry></row></tbody></tgroup></table></tables>
0047The session identifier is used to match the current request with a previous one, avoiding the need for repeated authenticate and key exchange if two systems have frequent communication. When keys are selected the server 210 will cache these and, if the wireless communication device 220 provides a session identifier in the client hello message the server 210 will search the cache for this session identifier. According to one exemplary embodiment, the message contains the above mentioned fields as well as additionally 'buffer memory' field having the length of 32 bits. The field and length of the client hello message can be varied based on the requirements.
0048In the second step, the server 210 generates a random number 'r' upon receiving client hello message and prime number 'p' (= 2 mod 3). According to one exemplary embodiment, the size of the random number 'r' is 192-bit and the size of the prime number 'p' is 64-bit. Subsequently the server 210 computes a resultant masking process of random number {s = (r || Mask) XoR Hash(Tr_Id, SIM no) XoR Hash(Cust_Id, Mobile no)} using the generated random number 'r', Mask, a transaction ID, Customer ID, Device Number by matching hash function, a nonce value for security, wherein the Mask = 64-bits. The server 210 encrypts a message with the resultant masking process of random number 's', a resultant masking value 'y1' using hash function, further adding a nonce value for security and then the server 210 sends the encrypted message {s, y1 = Encr(p), Hash(y1), Nonce(y1)} to the wireless communication device 220.
0049In the third step, the wireless communication device 220 retrieves the random number 'r' and the Mask {Hash(Tr_Id, SIM no) XoR Hash(Cust_Id, Mobile no) XoR s} by matching hash function upon receiving the encrypted message and subsequently the wireless communication device 220 splits the Mask and the random number 'r' which is used to decrypt the {y1}, upon recovering the prime number 'p', verifies the hash value of the received resultant masking value {Hash( yl)}. Then the wireless communication device 220 computes a resultant value {r3 =(r mod p)3 mod p}, which is obtained using permutation technique of the random number and subsequently the wireless communication device 220 encrypts a message {y3 = r3 XoR y2, Hash(y2), Nonce(y3)} with a new second random number y2 by matching hash function and further adding a nonce value for security and then the wireless communication device 220 sends the resultant encrypted message to the server 210, wherein the second new random number 'y2' is generated using the Pseudo Random Number Generator (PRNG) method.
0050In the fourth step, the server 210 computes a cubing value of the random number {r3} and subsequently the server 210 gets the second new random number {'y2' by y3XoR r3} using the cubing value of the random number and XOR function and then the server 210 verifies the hash value of the received message {Hash (y2)} and Nonce value of the received resultant encrypted message {Nonce (y3).
0051In the final step, the server 210 sends the response upon verifying hash value of the received message {Hash (y2)} and Nonce value of the received resultant encrypted message {Nonce (y3)} to the wireless communication device 220.
0052Before initiating the communication in the above said system 200, initially, the server 210 registers the device and IMEI numbers of the wireless communication device 220 and then distributing customer identity and transaction identity (Cust_ID and Tr_ID) to each wireless communication devices 220 prior to being allowed access to the server 210.
0053According to one exemplary embodiment, the wireless communication device 220 is mobile phone. Accordingly the server 210 registers mobile and IMEI numbers and distributes customer identity and transaction identity (Cust_ID and Tr_ID) to each mobile 220 prior to being allowed access to the server 210 and subsequently the server 210 uses AES-CTR-192-bit algorithm for encrypting a message and a known Pseudo Random Number Generator (PRNG) which accepts a seed for generating the random numbers.
Example of the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-1:
0054<ol id="ol0002" compact="compact"><li>1. Cust_ID = 2323; Tr_ID = 3542234</li><li>2. Mobile no = 9885076432; IMEI = 74398483299329</li><li>3. Hash(Tr_ID, SIM no) = 12495405401234511; Hash(Cust_ID, Mobile no) = 232311212121</li><li>4. Server generates a 192-bit random number r = 12432534343 and a 64-bit prime no p = 101 where p is 2 mod 3</li><li>5. Server computes r||Mask = 124325343435783459321 and s = 66391475877301.</li><li>6. Server uses r to find Enc<sub>r</sub>(p) = 43484349 and sends {124330942610003772911, 43484349, 232321, 14}to the wireless communication device</li><li>7. Wireless communication device retrieves r||Mask = 124325343435783459321 by Hash (Tr_ID, SIM no) XoR Hash(Cust_ID, Mobile no) XoR s and splits r = 12432534343 and Mask = 5783459321.</li><li>8. Wireless communication device computes r<sup>3</sup>=r<sup>3</sup> mod p = 41, generates a random number y<sub>2</sub> = 145 and sends (184, 343435, 4} to the server, where Hash (145) = 343435.</li><li>9. Server computes r<sup>3</sup> = r<sup>3</sup> mod p = 41, gets y<sub>2</sub> = 145 by y<sub>3</sub> XoR r<sup>3</sup> and verifies Hash(y<sub>2</sub>) and Nonce(y<sub>3</sub>).</li></ol>
0055<figref idref="f0003">Figure 3</figref> illustrates the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-2 between server and wireless communication device. A system 300 comprises a server 310 and a wireless communication device 320 are communicatively coupled with each other via communication network, wherein the communication network can be selected from the group of Wide area network (WAN), Local Area Network (LAN) or Metropolitan Area Networks (MAN), internet, and intranet, etc. In a preferred embodiment, the communication network is internet. The wireless communication device 320 can be selected from one of the group of mobile handsets, smart phones, PDAs, cellular phones, or tiny devices and the wireless communication device enabled with 2G, 3G, or 4G networks. In a preferred embodiment, the wireless communication device 320 is mobile phone.
0056A method of communication used in the above said system 300 comprising receiving, from at least one wireless communication device 320, a connection attempt to access a server 310, performing an authentication process using lightweight Extensible Authentication Protocol (EAP) based on the Symmetric Key Encryption (SKE) mechanism to facilitate the wireless communication device 320 prior to being allowed access to the server 310, wherein the said authentication process comprising the following steps: In the first step of the proposed method, the wireless communication device 320 initiates the communication by sending client hello message to the server 310, wherein the client hello message includes a list of encryption algorithms that the wireless communication device 320 is prepared to use and some challenge data to be used to authenticate the server 310. The message contains the following fields: <tables id="tabl0003" num="0003"><table frame="all"><tgroup cols="2"><colspec colnum="1" colname="col1" colwidth="56mm" /><colspec colnum="2" colname="col2" colwidth="32mm" /><thead><row><entry namest="col1" nameend="col2" align="center" valign="top"><b>CLIENT HELLO MESSAGE</b></entry></row><row><entry valign="top"><b>Field</b></entry><entry valign="top"><b>Length</b></entry></row></thead><tbody><row><entry>The message type (client hello)</entry><entry>8 bits</entry></row><row><entry>The SSL version number (currently 2)</entry><entry>16 bits</entry></row><row><entry>The length of the cipher list</entry><entry>16 bits</entry></row><row><entry>The length of the session identifier</entry><entry>16 bits</entry></row><row><entry>The length of the challenge data</entry><entry>16 bits</entry></row><row><entry>The cipher list</entry><entry>variable</entry></row><row><entry>The session identifier</entry><entry>16≤ data ≤ 32 bytes</entry></row><row><entry>The challenge data</entry><entry>variable</entry></row></tbody></tgroup></table></tables>
0057The session identifier is used to match the current request with a previous one, avoiding the need for repeated authenticate and key exchange if two systems have frequent communication. When keys are selected the server 310 will cache these and, if the wireless communication device 320 provides a session identifier in the client hello message the server 310 will search the cache for this session identifier. According to one exemplary embodiment, the message contains the above mentioned fields as well as additionally 'buffer memory' field having the length of 32 bits. The field and length of the client hello message can be varied based on the requirements.
0058In the second step, the server 310 generates a random number 'r' upon receiving client hello message and prime number 'p' (= 2 mod 3). According to one exemplary embodiment, the size of the random number 'r' is 192-bit and the size of the prime number 'p' is 64-bit. Subsequently the server 310 computes first resultant masking value {y1 = (r || Mask1) } XoR Hash(Tr_Id, SIM no) XoR Hash(Cust_Id, Mobile no)} using the generated random number by matching hash function, Mask1 and other parameters, wherein the Mask = 64-bits, then computes second resultant masking value {y2 =(p || Mask2) XoR Hash(Tr_Id, Cust_Id, SIM no, IMEI)} using generated random number by matching hash function, Mask2 and other parameters, wherein the Mask = 64-bits; subsequently the server 310 encrypts a message with the first resultant masking value y1 and the prime number by matching hash function and adding a nonce value for security, second resultant masking value y2 and then the server 310 sends the encrypted message {y1, y2, Hash(y1 || p), Nonce(y1)} to the wireless communication device 320.
0059In the third step, the wireless communication device 320 retrieves the random number 'r' and the Mask1 {Hash(Tr_Id, SIM no) XoR Hash(Cust_Id, Mobile no) XoR y1} by matching hash function upon receiving the encrypted message and subsequently the wireless communication device 320 splits the Mask1 and the random number 'r'. Similarly, the wireless communication device 320 upon extracting the prime number 'p', then verifies hash value of the first resultant masking value y1 with the extracted prime number 'p' {Hash(y1 || p)}, Nonce function with the first resultant masking value y1, {Nonce(y1)}, then the wireless communication device 320 computes a resultant value {r3 =(r mod p)3 mod p}, which is obtained using permutation technique of the random number, then generates a 102-bit private key "k" using the Deterministic Random Sequence Generation (DRSG) algorithm DRSG(r,t1, t2) where t1 = 0 and t2 = Nonce(r3). Then the wireless communication device 320 encrypts a message {Enck(r3XoR k) || Nonce(k))} with the cubing value of the random number and further adding a nonce value for security and then the wireless communication device 320 sends the resultant encrypted message to the server 310.
0060In the fourth step, the server 310 retrieves the private key 'k' by cubing value of the random number {r3} and subsequently the server 310 gets a resultant value, which is obtained from XOR function of the private key 'k' of the wireless communication device 320 with cubing value of the random number {r3} through decryption, then the server 310 splits the cubing value of the random number {r3} and the private key 'k'. Subsequently the server 310 verifies the private key with Nonce value for security {Nonce (k)} from the received encrypted message.
0061In the final step, the server 310 sends the response upon verifying the private key with Nonce value for security {Nonce (k)} from the received encrypted message to the wireless communication device 320.
0062Before initiating the communication in the above said system 300, initially, the server 310 registers the device and IMEI numbers of the wireless communication device 320 and then distributing customer identity and transaction identity (Cust_ID and Tr_ID) to each wireless communication devices 320 prior to being allowed access to the server 310.
0063According to one exemplary embodiment, the wireless communication device 320 is mobile phone. Accordingly, the server 310 registers mobile and IMEI numbers and distributes customer identity and transaction identity (Cust_ID and Tr_ID) to each mobile 320 prior to being allowed access to the server 310 and subsequently the server 310 uses AES-CTR-192-bit algorithm for encrypting a message and a known Pseudo Random Number Generator (PRNG) which accepts a seed for generating the random numbers.
Example of the secure transaction of data using EAP Protocol based on SKE (Symmetric Key Encryption) mechanism-2:
0064<ol id="ol0003" compact="compact"><li>1. Cust_ID=2323; Tr_ID = 3542234</li><li>2. Mobile no = 9885076432; IMEI = 74398483299329</li><li>3. Hash(Tr_ID, SIM no) = 12495405401234511; Hash(Cust_ID, Mobile no) = 232311212121; Hash(Tr_ID, Cust_ID, SIM no, IMEI) = 34343421122</li><li>4. Prime number p = 101 where p is 2 mod 3</li><li>5. Server generates a random number r = 124325, Mask1 = 5783459 and Mask2 = 53434116432</li><li>6. Server computes y<sub>1</sub> = 32423423 and y<sub>2</sub> = 43556121</li><li>7. Server sends { 32423423, 43556121, 1343444, 15)</li><li>8. Wireless communication device retrieves 1243255783459 by doing Hash(Tr_Id, SIM no) XoR Hash(Cust_Id, Mobile no) XoR y<sub>1</sub> and finds r = 124325 and Mask1 = 5783459</li><li>9. Server uses k to find Enc<sub>k</sub>(s) = 43434343 and sends {66391475877301, 43434343, 232321, 18} to the wireless communication device.</li><li>10. Wireless communication device uses k to get s and finds r = 124325 and Mask = 5783459321 by Hash (Tr_ID, SIM no) XoR Hash (Cust_ID, Mobile no) XoR s.</li><li>11.Wireless communication device computes r<sup>3</sup>=r<sup>3</sup> mod p = 87, generates y<sub>2</sub> = 145 and sends (198, 343434, 4} to the server.</li><li>12.Server computes r<sup>3</sup> = r<sup>3</sup> mod p = 87, gets y<sub>2</sub> = 145 by y<sub>3</sub> XoR r<sup>3</sup> and verifies Hash(y<sub>2</sub>) and Nonce(y<sub>3</sub>).</li></ol>
0065According to one embodiment, the hash function is matched, in the above proposed systems and methods in order to maintain a secure communication to avoid phishing and replay attacks and according to another embodiment, the nonce value is added, in the above mentioned systems and methods in order to maintain a secure communication to avoid phishing and replay attacks. Further, hashing and nonce methods are used to avoid Initial Counter Prediction and Time Memory Trade Off attacks.
Strengths of EAP Protocol based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms:
0066<ol id="ol0004" compact="compact"><li>1. From Base station to GPRS core network via Network subsystems, our EAP (Protocol 1: EAP based on ECC mechanism) works in a speedy manner due to the usage of ECC-163 bits between the nodes.</li><li>2. In the protocol 1(EAP based on ECC mechanism), it is difficult to generate a signed message by an attacker; since the permutation</li><li>3. r → r<sup>3</sup> = r<sup>3</sup> mod p (where p = 2 mod 3) is random.</li><li>4. Similarly, it is difficult to predict a random number r (supplied by the server) in protocols 1, 2 and 3 (EAPs based on ECC mechanism and SKE mechanisms 1 & 2); since the mapping r → r<sup>3</sup> = r<sup>3</sup> mod p is bijective.</li><li>5. The protocols (EAPs based on ECC mechanism and SKE mechanisms 1 & 2) are compatible to 2G, 3G or 4G mobile networks.</li><li>6. No key agreement between different domains and key expiration are not there in our protocols (EAPs based on ECC mechanism and SKE mechanisms 1 & 2).</li><li>7. EAPs are suitable for WLANs and WMANs and are better than the existing EAPs which are vulnerable to a number of attacks - dictionary attack, plain text attack, chosen plain text attack, even man in the middle attack.</li></ol>
0067The application is described in the example given below which is provided only to illustrate the application and therefore should not be construed to limit the scope of the application.
Requirements:
0068<b>EAP Application Environment is as mentioned below:</b><b>a) Software Environment</b><tables id="tabl0004" num="0004"><table frame="all"><title>TABLE 1:</title><tgroup cols="2"><colspec colnum="1" colname="col1" colwidth="33mm" /><colspec colnum="2" colname="col2" colwidth="38mm" /><thead><row><entry align="center" valign="middle"><b>Operating System</b></entry><entry align="center" valign="top">Windows XP/ 2003 SP3</entry></row></thead><tbody><row><entry align="center" valign="middle"><b>Software/Tools</b></entry><entry align="center">WTK2.5.2, Log4Net</entry></row></tbody></tgroup></table></tables><b>b) Hardware Environment</b><tables id="tabl0005" num="0005"><table frame="all"><title>TABLE 2:</title><tgroup cols="2"><colspec colnum="1" colname="col1" colwidth="33mm" /><colspec colnum="2" colname="col2" colwidth="90mm" /><thead><row><entry align="center" valign="top"><b>Workstation Client</b></entry><entry align="center" valign="top">Windows XP with SP3</entry></row></thead><tbody><row><entry align="center"><b>Test Server</b></entry><entry align="center">4 GB RAM, Intel Core 2 vPro 160 GB HDD, E6550 as processor</entry></row><row><entry align="center" valign="middle"><b>Mobile</b></entry><entry align="center">J2ME enabled Mobile with GPRS connectivity.</entry></row></tbody></tgroup></table></tables>
0069<b>Initial Test Set-up</b><ol id="ol0005" compact="compact"><li><b>a) EAP Client:</b><ol id="ol0006" compact="compact"><li>1) Basically EAP client will Installed in Mobile devices (for e.g. Nokia N79, E75, 5800-ExpressMusic, 6210 Navigator).</li><li>2) It is a J2ME Code which will do the encryption & decryption of data.</li><li>3) It will contact the server and communicate through a secure channel.</li></ol></li><li><b>b) EAP Server:</b><ol id="ol0007" compact="compact"><li>1) A server application built using .NET framework, which is used for decryption & encryption of data.</li><li>2) Decrypts the Client request and send the response back in encrypted format.</li></ol></li></ol>
EAP Application Flow Diagram with performance
0070<figref idref="f0004">Figure 4</figref> illustrates flow diagram with performance 400 by using lightweight EAP Protocols for secure transaction of data between wireless communication device and server. In the first step, client 420 initiates the communication by sending client hello message to the server 410 {1 → Clientlnitiate() - request}. In the second step, the server 410 sends hexadecimal sequence as a response upon receiving the client hello message from the client 420 {2 → Hexa decimal sequence(response)}. In the third step, the client 420 sends request message using the EAP protocol to server 410 for initiating secure transaction of data between them {3 → EAP Protocol()- request }. In the fourth step, the server 410 sends the response upon validating the protocol to the client 420 {4 → true/false (response). In the final step, if the response is 'true" then the secure transaction of data process starts between the client and the server, otherwise, the response is 'false", the communication ends between them.
Test Results:
0071Nokia handset series N79, E75, 5800 and 6210 support these EAP Client modules. As per the performance, Nokia has done 'EAP flow' and the server checks the authentication response in < 0.5 ms. This is a remarkable performance compared to certificate based transactions where the authentication response from server end takes > 1 sec.
0072The preceding description has been presented with reference to various embodiments. Persons skilled in the art and technology to which this application pertains will appreciate that alterations and changes in the described structures and methods of operation can be practiced without meaningfully departing from the principle and scope.
Contents5
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN107425971A | Cited by | China | Search report |
| CN110574335A | Cited by | China | Search report |
| US10104055B2 | Cited by | United States of America | Search report |
| US2017346801A1 | Cited by | United States of America | Pre-grant |
| US2006098819A1 | Cites | United States of America | Applicant |
| US2007189527A1 | Cites | United States of America | Applicant |
| US2009180612A1 | Cites | United States of America | Applicant |
| US2010031051A1 | Cites | United States of America | Applicant |
| US6189098B1 | Cites | United States of America | Applicant |
| US6563928B1 | Cites | United States of America | Applicant |
| US6658476B1 | Cites | United States of America | Applicant |
| US7243232B2 | Cites | United States of America | Applicant |
| US7716482B2 | Cites | United States of America | Applicant |
9 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 1976MU2010 | India | A | |
| MU19762010 | India | – | |
| 1976MU2010 | – | – | – |
| IN2010MUM1976 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| CN102315937A | China | A | |
| US2012008775A1 | United States of America | A1 | |
| JP2012019511A | Japan | A | |
| EP2416524A2This record | European Patent Office (EPO) | A2 | |
| JP5307191B2 | Japan | B2 | |
| US8842833B2 | United States of America | B2 | |
| CN102315937B | China | B | |
| EP2416524A3 | European Patent Office (EPO) | A3 | |
| EP2416524B1 | European Patent Office (EPO) | B1 |
78 legal events, as 9 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | NL | |
| Ip right lapsedLapsedST27 STATUS EVENT CODE: U-0-0-H10-H13 (AS PROVIDED BY THE NATIONAL OFFICE)H13 | H13 | CH | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Deletion acc. to par. 5 (withdrawal of the translation of the ep patent)MK05 | MK05 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Translation for ep filed (entry of ep into country)FP | FP | NL | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Designated contracting statesAK | AK | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Request for examination filed (corrected)R17P | R17P | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2416524
- Publication, DOCDB
- 2416524
- Publication, EPODOC
- EP2416524
- Application
- 111678249
- Application, DOCDB
- 11167824
- Application, EPODOC
- EP20110167824
Titles3
- German
- System und Verfahren zur sicheren Übertragung von Daten zwischen einem drahtlosen Kommunikationsgerät und einem Server
- English
- System and method for secure transaction of data between wireless communication device and server
- French
- Système et procédé de transaction sécurisée de données entre un dispositif de communication sans fil et un serveur
Classification
- CPC, 10
- H04L9/3271
- H04L9/3066
- H04L9/3247
- H04L2209/04
- H04L2209/56
- H04L2209/80
- H04L63/08
- H04L63/162
- H04W12/06
- G06F2207/7242
- IPC, 1
- H04L9 32
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- Montenegro