Method and device for authenticating a subscriber in a communications network
Abstract
Procedure for checking the authenticity of a first communications subscriber (203, 204) in a communications network, - in which in a first communications subscriber, using an indication of failure recognition of the first communications subscriber and information on a random indication, which has been transmitted by a second communications subscriber (209) in the communications network to the first communications subscriber, a first fault information is formed, - in which the first fault information is transmitted by the first communications subscriber to the second communications subscriber, - in which, in the second communications subscriber, using a fault acknowledgment indication from the second communications subscriber and the information on the random indication, a second fault information is formed; - in which the authenticity of the first communications subscriber is checked in the second communications subscriber, using the first fault information and the second fault information.

Term
Term ended
Projected expiry passed 31 May 2020, 6.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
11 claims: 3 independent, 8 dependent
- 1ES 2 244 451 T3 REIVINDICACIONES 1. Procedimiento para la comprobación de la autenticidad de un primer abonado de comunicaciones (203, 204) en una red de comunicaciones, - en el que en un primer abonado de comunicaciones, utilizando una indicación de reconocimiento de falta del primer abonado de comunicaciones y una información sobre una indicación aleatoria, que ha sido transmitida por un segundo abonado de comunicaciones (209) en la red de comunicaciones al primer abonado de comunicaciones, se forma una primera información de falta, - en el que la primera información de falta es transmitida por el primer abonado de comunicaciones al segundo abonado de comunicaciones, - en el que, en el segundo abonado de comunicaciones, utilizando una indicación de reconocimiento de falta del segundo abonado de comunicaciones y la información sobre la indicación aleatoria, se forma una segunda información de falta;- en el que en el segundo abonado de comunicaciones, utilizando la primera información de falta y la segunda información de falta, se comprueba la autenticidad del primer abonado de comunicaciones.
- 2Procedimiento según la reivindicación 1, en el que se calcula una diferencia entre la indicación de reconocimiento de falta del primer abonado de comunicaciones y la indicación de reconocimiento de falta del segundo abonado de comunicaciones.
- 3Procedimiento según la reivindicación 2, en el que la diferencia se limita.
- 4Procedimiento según una de las reivindicaciones 1 a 3, utilizado en el marco de un sistema de telefonía móvil.
- 5Sistema para la comprobación de la autenticidad de un primer abonado de comunicaciones (203, 204) en una red de comunicaciones, - en el que el primer abonado de comunicaciones está equipado de tal manera que, utilizando una indicación de reconocimiento de falta del primer abonado de comunicaciones y una información sobre una indicación aleatoria, que ha sido transmitida por un segundo abonado de comunicaciones (209) en la red de comunicaciones al primer abonado de comunicaciones, se forma una primera información de falta y se transmite la primera información de falta al segundo abonado de comunicaciones;- en el que el segundo abonado de comunicaciones está equipado de tal manera que, utilizando una indicación de reconocimiento de falta del segundo abonado de comunicaciones y la información sobre la indicación aleatoria, se forma una segunda información de falta y utilizando la primera información de falta y la segunda información de falta, se comprueba la autenticidad del primer abonado de comunicaciones.
- 6Sistema según la reivindicación 5, en el que el primer abonado de comunicaciones es un ofertante de servicios y/o el segundo abonado de comunicaciones un usuario de servicios en la red de comunicaciones.
- 7Sistema según la reivindicación 5 ó 6, en el que una indicación de reconocimiento de falta es un número consecutivo de secuencia.
- 8Sistema según una de las reivindicaciones 5 a 7, en el que la información sobre la indicación aleatoria es un número aleatorio.
- 9Sistema según una de las reivindicaciones 5 a 8, en el que el primer abonado de comunicaciones es un ofertante de servicios en la red de comunicaciones y/o el segundo abonado de comunicaciones es un usuario de servicios en la red de comunicaciones.
- 10Sistema según la reivindicación 9, en el que el ofertante de servicios es un operador de telefonía móvil y/o el usuario de servicios es un teléfono móvil.
- 11Sistema según una de las reivindicaciones 5 a 10, utilizado en el marco de un sistema de telefonía móvil.
Independent claims11
91 paragraphs in 3 sections, as filed
ES 2 244 451 T3
DESCRIPTION
Procedure and system for verifying the authenticity of a first communications subscriber in a communications network.
The invention relates to a method and a system for verifying the authenticity of a first communications subscriber in a communications network.
In a communication network, data is generally transmitted between communication subscribers, for example a service provider and a service user. To protect a communications network from penetration of an unauthorized communications subscriber into the communications network, the authenticity of each communications subscriber is generally checked.
Document [1] discloses a method and a system for verifying the authenticity of a communications subscriber, in particular a service provider or a service user in a communications network.
The procedure known from document [1] and the corresponding system are based on a so-called 3G TS 33.102 version 3.0.0-Draft standard, which describes a security architecture of a mobile telephone system.
Figure 4 represents with symbols the way to proceed in verifying the authenticity of a communications subscriber, as known from document [1] and will be briefly and excerptly described below.
A data transmission is represented in FIG. 4 in each case by an arrow. The direction of an arrow indicates the direction of transmission in a data transmission.
Figure 4 shows a mobile phone system 400, including a user 401 of a communication service, eg, a mobile phone, and a provider 402 of a communication service. Provider 402 includes a selection network 403 with a selection network operator, in which user 401 locally requests a communication service, and a local network 404 with a local network operator, in which user 401 is advertised and registered.
In addition, the user 401, the selection network 403 and the local network 404 each have a central processing unit with a memory, for example a server (central computer), with whose processing unit the shape is controlled and monitored. procedure described below and in whose memory data are stored and / or data are stored.
The selection network 403 and the local network 404 are linked together by a data line, through which digital data can be transmitted. The user 401 and the selection network 403 are linked together by any transmission medium for the transmission of digital data.
In a communication 410 the user 401 is entered by selection in the selection network 403. At the beginning of the communication a check takes place both of the authenticity of the user 401 and also of the authenticity of the provider 402.
To do this, it requests, 411, the selection network 403 the so-called authentication data, with which it is possible to verify the authenticity of the user 401 and of the provider 402.
The authentication data, which is found out by the local network 404, includes a random number and a consecutive sequence number of the bidder 402. The consecutive sequence number of the bidder 402 is calculated such that a counter of the bidder 402, with each communication attempt between user 401 and bidder 402, raises the consecutive sequence number of bidder 402 by the value
1.
It is to be noted that the random number and the consecutive sequence number of the bidder 402 are only a part of the authentication data and are not to be understood as conclusive. Other authentication data are known to [1].
The local network 404 transmits the requested authentication data to the selection network 403, 412. The selection network 403 processes the received authentication data in an appropriate manner 413 and transmits the processed authentication data to the user 401,
414.
The user 401 checks, using his own consecutive sequence number, which is handled based on the consecutive sequence number of the bidder 402, and the consecutive sequence number of the bidder 402, the authenticity of the bidder 402,
415.
The procedure for verifying the authenticity of the bidder 402 is described in [1].
A result of the authenticity check of the bidder 402, “Bidder authenticity correct” 416, “Bidder authenticity correct, but a sequence error has occurred” 417 or “Bidder authenticity incorrect” 418, transmitted by the user 401 to bidder 402, 419.
When the result is "Authenticity of Bidder Correct" 416, it checks the selection network 403, as described in [1], the authenticity of the user 401, 420.
When the result is "Incorrect bidder authenticity" 418, communication is interrupted or 421 is started again.
When the result is "Bidder authenticity correct, but a sequence error has occurred" 417, a resynchronization takes place, such that the local network 404 sends 422 a resynchronization query to user 401. The user replies with a response resynchronization data, in which resynchronization data is transmitted 423 to the local network 404. Based on the resynchronization response, the consecutive section number of the provider 402 is modified, 424. The verification of the authenticity of the user 401 then takes place, as known from [1].
US-A-5 799 084 describes a procedure for verifying the authenticity of a mobile station by means of an HLR / AC, the mobile station forming a first authentication message from a random number and a sequential number, and sending it to the HLR / AC. The HLR / AC compares this message with a second authentication message calculated by the HLR / AC using a random number formed by it.
The above-described procedure has the drawback that in verifying the authenticity of a communications subscriber, in particular in verifying the authenticity of a service provider, a lot of data has to be transmitted between the communications subscribers.
In this way, the invention addresses the problem.
ES 2 244 451 T3 is basic to indicate a simplified and improved procedure, as well as a simplified and improved system, with respect to the known procedure and the known system, for verifying the authenticity of a communications subscriber in a communications network.
The problem is solved by the method, as well as by the system with the particularities according to the independent claims.
In the procedure for checking the authenticity of a first communication subscriber in a communication network, the first communication subscriber is formed, using an error acknowledgment indication of the first communication subscriber and information on a random indication, which has been transmitted by a second communication subscriber in the communication network to the first communication subscriber, a first fault information. The first fault information is transmitted by the first to the second communications subscriber. At the second communication subscriber in the communication network, a second fault information is formed, using a fault recognition indication of the second communication subscriber and the information on the random indication. Using the first fault information and the second fault information, the authenticity of the first communications subscriber is checked at the second communications subscriber.
In the system for verifying the authenticity of a first communications subscriber in a communications network, the first communications subscriber is set up in such a way that using an indication of recognition of failure of the first communications subscriber and information about an indication random, which has been transmitted by a second communications subscriber in the communications network to the first communications subscriber, a first fault information is formed. The first fault information is transmitted from the first to the second communications subscriber. In addition, the system presents a second communications subscriber in the communications network, which is set up in such a way that by using a fault recognition indication of the second communications subscriber and the information on the random indication, a second fault information is formed . Using the first fault information and the second fault information in the second communication subscriber, the authenticity of the first communication subscriber is checked.
Under verification of the authenticity of a communications subscriber in a communications network, steps of the procedure are understood that in the broadest sense are carried out with a verification of the right of a communications subscriber to access a communications network or to participate in a communication in a communication network.
In this way, both the steps of the procedure that are carried out in the framework of a verification of the right of a communications subscriber to access a communications network are included, as well as those steps of the procedure that are carried out within the framework of a processing. or a data management, which are used during the check.
Advantageous developments of the invention result from the dependent claims.
The improvements described below concern both the procedure and the system.
The invention and the improvements described below can be carried out both in software and in hardware, for example using a special electrical circuit.
In an improvement, the first communications operator is a service provider and / or the second communications operator is a service user in the communications network.
A consecutive sequence number is preferably used as a fault recognition indication.
In a refinement the information on the random indication is a random number.
In a refinement, the authenticity check is simplified by calculating a difference between the fault recognition indication of the first communications subscriber and the fault recognition indication of the second communications subscriber.
In a refinement, the authenticity test regarding the security of the communications network is further improved by limiting the difference.
Preferably, an improvement is used within the framework of a mobile telephone system. In the mobile telephony system, the service user (s) is / are performed as a mobile telephone and / or the service provider as the operator of the mobile telephone network.
An exemplary embodiment of the invention is represented in the figures, which will now be described in more detail.
Shown in
Figure 1 a mobile telephone system;
FIG. 2 is a diagram in which symbols are used to represent a verification of the authenticity of a communications subscriber;
Figure 3 a sequence diagram, in which individual procedural steps are represented during the verification of the authenticity of a service provider in a communication network;
Figure 4 shows a diagram in which a verification of the authenticity of a communications subscriber according to 3G TS 33.102 version 3.0.0-standard is represented with symbols.
Execution example: Mobile phone system
A mobile phone system 100 is depicted in FIG. 1. The mobile phone system 100 includes a mobile phone 101, a local selection network 102 with a selection network operator 103, and a local network 104 with a local network operator. 105.
In the local network 104, the mobile phone 101 is signaled and registered.
Furthermore, the mobile telephone 101, the selection network 102 and the local network 104 each have a central processing unit 106, 107, 108, with a memory 109, 110, 111, with which processing units 106, 107 , 108, are monitored and controlled in the manner described below and on whose memories 109, 110, 111 are stored and / or data are stored.
The selection network 102 and the local network 104 are linked together by a data line 112, through which digital data can be transmitted. The mobile phone 101 and the targeting network 102 are
ES 2 244 451 T3 linked together by any transmission medium 113 for the transmission of digital data.
Figure 2 represents the procedure in a verification of the authenticity of the mobile telephone 101 and the procedure in a verification of the authenticity of the local network 104 or the local network operator 105 with symbols, and will be briefly and abstractly described at continuation.
The transmission of the data is represented in Figure 2 by the corresponding arrows. The direction of an arrow characterizes the direction of transmission in a data transmission.
The procedure described below and represented in figure 2 with symbols is based on the so-called 3G TS 33.102 version 3.0.0-standard, which describes a security architecture of a mobile telephone system and which is described in [1].
In a communication, the mobile telephone 201 is entered 210 by key in the selection network 203. At the beginning of the communication, a check takes place both of the authenticity of the mobile telephone 201 and of the authenticity of the local network 204 or of the operator. from the local network.
To do this, the selection network 203 requests authentication data with which it is possible to verify the authenticity of the user 201 and the local network 204 or the local network operator, by the local network 204, 211.
The authentication data that is found out by the local network 204 includes a random number and a consecutive sequence number of the local network 204 (see in this regard figure 3 step 310). The consecutive sequence number of the local network 204 is calculated in such a way that a counter of the local network 204 for each communication attempt between the mobile phone 201 and the local network 204 increases the consecutive sequence number of the local network 204 by the value 1.
It should be noted that the random number and the consecutive sequence number of the local network 204 are only a part of the authentication data and are not to be understood as conclusive. Other authentication details are given in [1].
The local network 204 transmits the requested authentication data to the selection network 203, 212. The selection network 203 processes the received authentication data appropriately, 213 and transmits the processed authentication data to the mobile phone 201,214.
The mobile phone 201 checks, using a consecutive sequence own number, which is handled as a function of the consecutive sequence number of the local network 204, and the consecutive sequence number of the local network 204, the authenticity of the local network 204, 215. Depending on the local network 204, the mobile phone 201 also has a meter.
The procedure for verifying the authenticity of the local network 204 is described in [1]. The procedural steps that deviate from this are described below.
As part of the verification of the authenticity of the local network 203, a so-called overflow test of the mobile phone counter 201 is carried out. This overflow test prevents the overflow of an admissible range of numbers of the mobile phone counter 201 .
The overflow test checks the following conditions:
1) Consecutive sequence number of local network 204> consecutive sequence number of mobile phone 201;
2) Local network consecutive sequence number 204 - mobile phone consecutive sequence number 201 <deviation that can be prescribed (here: 1000000);
governing the deviation that may be prescribed:
- deviation that can be prescribed large enough to exclude in normal or disturbance-free communication operation that:
consecutive sequence number of the local network 204 - consecutive sequence number of mobile phone 201> deviation that can be prescribed;
- maximum permissible consecutive sequence number of mobile phone 201 / deviation that can be prescribed large enough, to exclude that the maximum permissible consecutive sequence number of mobile phone 201 is reached during operation.
A result of the local network authenticity check 204, "correct authenticity" 216, "correct authenticity, but a sequence error has occurred" 217 or "incorrect authenticity" 218, is transmitted 419 by mobile phone 201 to the local network 204.
When the result is "correct authenticity" 216, it checks the selection network 203, as described in [1], the authenticity of the mobile phone 201, 220.
When the result is "incorrect authenticity" 218, the communication is interrupted or it is started again, 221.
When the result is "authenticity correct, but a sequence error has occurred" 217, a resynchronization 222 takes place. Resynchronization is to be understood as a modification of the consecutive sequence number of the local network 204.
For this, the mobile phone 201 transmits resynchronization data to the selection network 203, 222.
The resynchronization data includes the same random number that was transmitted in the framework of the authentication data, as well as the consecutive sequence number of the mobile phone 201 (see in this regard figure 3 step 320).
The selection network 203 processes the resynchronization data appropriately and transmits the appropriate resynchronization data to the local network 204.
Using the processed resynchronization data, the local network checks the consecutive sequence number of the mobile phone 201 and the consecutive sequence number of the local network 204 and modifies if necessary the consecutive sequence number of the local network 204, 223 ( see in this regard figure 3, step 330).
The local network 204 then transmits new authentication data, which optionally includes the modified consecutive sequence number of the local network 204, to the selection network 203.
In order to visualize the procedure described, 3 important steps 300 of the procedure are represented in FIG.
ES 2 244 451 T3
FIG. 3 shows a first step 310 in the framework of which the authentication data (first missing information) is ascertained.
In the framework of a second step 320, the resynchronization data (second fault information) is ascertained.
In the framework of a third step 330, the consecutive sequence number of the mobile phone and the consecutive sequence number of the local network are checked using the resynchronization data.
A variant of the first exemplary embodiment is described below.
In the alternative execution example, a procedure is carried out with which the local network is made more secure with respect to data loss when there is a system crash.
For this, the current consecutive sequence number of the local network is stored in each case at previously determined time intervals in the memory of the local network. A consecutive sequence number of the local network that has been lost in a system failure of the local network, is recovered again in the sense that to the value of the consecutive sequence number memorized is added a load value that can be predetermined . The load value that can be predetermined is dimensioned such that the sum of the consecutive sequence number of the mobile phone and the deviation that can be predetermined is not exceeded.
In the alternative execution example, the load value that can be predetermined is determined such that an average number, determined from experimental values during a communication network operation, of authentication tests during a day of the local network, multiplied by a factor with the value 10.
The following publication is cited in this document:
[1] 3G TS 33.102 version 3.0.0 - standard draft, Partnership project 3<sup>to</sup> generation, Technical specification of group services and system aspects, 3G security, security architecture, 05/1999.
Contents3
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
49 members in 10 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 19927271 | Germany | A | |
| 19991027271 | Germany | – |
Members49
| Document | Office | Kind | |
|---|---|---|---|
| WO0078078A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU5805100A | Australia | A | |
| KR20020019087A | Republic of Korea | A | |
| EP1186193A1 | European Patent Office (EPO) | A1 | |
| BR0011703A | Brazil | A | |
| CN1369183A | China | A | |
| JP2003501979A | Japan | A | |
| AU760714B2 | Australia | B2 | |
| EP1326469A2 | European Patent Office (EPO) | A2 | |
| EP1326470A2 | European Patent Office (EPO) | A2 | |
| KR20030059824A | Republic of Korea | A | |
| KR20030062415A | Republic of Korea | A | |
| CN1130099C | China | C | |
| US2003229784A1 | United States of America | A1 | |
| EP1326469A3 | European Patent Office (EPO) | A3 | |
| EP1326470A3 | European Patent Office (EPO) | A3 | |
| JP2004007690A | Japan | A | |
| US2004006714A1 | United States of America | A1 | |
| JP2004032730A | Japan | A | |
| CN1516494A | China | A | |
| CN1516495A | China | A | |
| EP1186193B1 | European Patent Office (EPO) | B1 | |
| EP1326470B1 | European Patent Office (EPO) | B1 | |
| DE50010928D1 | Germany | D1 | |
| DE50010940D1 | Germany | D1 | |
| ES2244451T3This record | Spain | T3 | |
| ES2244843T3 | Spain | T3 | |
| US6980796B1 | United States of America | B1 | |
| KR100576956B1 | Republic of Korea | B1 | |
| KR100576957B1 | Republic of Korea | B1 | |
| KR100578685B1 | Republic of Korea | B1 | |
| EP1326469B1 | European Patent Office (EPO) | B1 | |
| DE50013577D1 | Germany | D1 | |
| US7139550B2 | United States of America | B2 | |
| ES2272824T3 | Spain | T3 | |
| CN1314277C | China | C | |
| CN1316834C | China | C | |
| JP3924465B2 | Japan | B2 | |
| JP4272920B2 | Japan | B2 | |
| USRE40791E | United States of America | E | |
| JP4650994B2 | Japan | B2 | |
| US8565429B2 | United States of America | B2 | |
| BRPI0017414B1 | Brazil | B1 | |
| BR0017415B1 | Brazil | B1 | |
| BRPI0017415B1 | Brazil | B1 | |
| BR0011703B1 | Brazil | B1 | |
| BRPI0011703B1 | Brazil | B1 | |
| BRPI0017415B8 | Brazil | B8 | |
| BRPI0017414B8 | Brazil | B8 |
Numbers
- Publication
- 2244451
- Application
- 943674
Titles2
- Spanish
- PROCEDIMIENTO Y SISTEMA PARA LA COMPROBACION DE LA AUTENTICIDAD DE UN PRIMER ABONADO DE COMUNICACIONES EN UNA RED DE COMUNICACIONES.
- English
- PROCEDURE AND SYSTEM FOR THE VERIFICATION OF THE AUTHENTICITY OF A FIRST COMMUNICATIONS SUBSCRIBER IN A COMMUNICATIONS NETWORK.
Classification
- CPC, 4
- H04L63/126
- H04W12/06
- H04L69/40
- H04W12/108
- IPC, 8
- G06F21 20
- G06F11 30
- G09C1 00
- H04L9 00
- H04L9 32
- H04L12 28
- H04W12 06
- H04W12 10