Authentication between a cellular mobile terminal and a short range access point
Abstract
Authentication procedure between a short-range wireless network (RFP) having access points and a mobile terminal (TM) in a cellular radio network (RC), characterized in that it comprises the following steps: - transmission (E2) of a demand (RQ) that includes an address (ADTM) of the mobile terminal and an address (ADAP) of an access point (AP) located in the coverage area of the relative mobile terminal (TM) to the short-range network, from the mobile terminal to a management means (PFG) by means of the cellular network (RC), - determination (E3) of a secret code (CS) by the management means, - from the management medium (PFG), transmission (E4, E5) of a confirmation message (MC) that includes the secret code and the address of the access point extracted from the demand to the mobile terminal through the cellular network and a connection request message (MDC) that includes the secret code and the mobile terminal address extracted from the demand to the access point (AP), - request (E6) for connection of the mobile terminal to the access point designated by the address (ADAP) extracted from the confirmation message (MC) so that the mobile terminal (TM) and the access point (AP) determine a session key (KS) depending on the address (ADAP) of the access point, the address (ADTM) of the mobile terminal and the secret code (CS) extracted from the confirmation message (MC) and the request message connection (MDC), and - authentication (E7 ¿E10) of the mobile terminal (TM) by the access point (AP) according to the session key (KS).

Term
Term ended
Projected expiry passed 26 November 2023, 2.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
15 claims: 2 independent, 13 dependent
- 1ES 2 271 503 T3 REIVINDICACIONES 1. Procedimiento de autentificación entre una red inalámbrica de corto alcance (RFP) que tiene puntos de acceso y una terminal móvil (TM) en una red de radiocomunicaciones celular (RC), caracterizado porque comprende las etapas siguientes:- transmisión (E2) de una demanda (RQ) que incluye una dirección (ADTM) de la terminal móvil y una dirección (ADAP) de un punto de acceso (AP) situado en la zona de cobertura de la terminal móvil (TM) relativa a la red de corto alcance, desde la terminal móvil a un medio de gestión (PFG) por medio de la red celular (RC), - determinación (E3) de un código secreto (CS) por el medio de gestión, - desde el medio de gestión (PFG), transmisión (E4, E5) de un mensaje de confirmación (MC) que incluye el código secreto y la dirección del punto de acceso extraída de la demanda a la terminal móvil por medio de la red celular y de un mensaje de solicitud de conexión (MDC) que incluye el código secreto y la dirección de la terminal móvil extraída de la demanda al punto de acceso (AP), - solicitud (E6) de conexión de la terminal móvil al punto de acceso designado por la dirección (ADAP) extraída del mensaje de confirmación (MC) a fin de que la terminal móvil (TM) y el punto de acceso (AP) determinen una clave de sesión (KS) en función de la dirección (ADAP) del punto de acceso, de la dirección (ADTM) de la terminal móvil y del código secreto (CS) extraído del mensaje de confirmación (MC) y del mensaje de solicitud de conexión (MDC), y - autentificación (E7-E10) de la terminal móvil (TM) por el punto de acceso (AP) en función de la clave de sesión (KS).
- 2Procedimiento conforme a la reivindicación 1, según el cual la autentificación de la terminal móvil por el punto de acceso comprende una solicitud (E7) de determinación (E8) desde el punto de acceso de una respuesta (RP1) en función de la clave de sesión (KS) a la terminal móvil que transmite (E9) la respuesta al punto de acceso, por medio de la red de corto alcance, y en el punto de acceso (AP), una determinación (E8) de una respuesta (RP1) en función de la clave de sesión (KS) y una comparación (E10) de las respuestas para autorizar (E16) la abertura de una sesión entre el punto de acceso y la terminal móvil cuando al menos las respuestas comparadas son idénticas.
- 3Procedimiento conforme a la reivindicación 1 o 2, que comprende una autentificación (E11-E15) del punto de acceso (AP) por la terminal móvil (TM) en función de la clave de sesión (KS), cuando el punto de acceso ha autentificado la terminal móvil.
- 4Procedimiento conforme a la reivindicación 3, según el cual la autentificación del punto de acceso por la terminal móvil comprende una invitación (E11) del punto de acceso trasmitida a la terminal móvil (TM) a fin de que la terminal móvil autentifique el punto de acceso solicitando (E12) al punto de acceso determinar (E13) una segunda respuesta (RP2) en función de la clave de sesión (KS) y transmitir (E14) la segunda respuesta a la terminal móvil por medio de la red de corto alcance (RFP), determinando (E13) una segunda respuesta (RP2) en función de la clave de sesión (KS), y comparando (E15) las segundas respuestas (RP2) a fin de autorizar la abertura de la se8 sión solamente después de una identidad de las segundas respuestas comparadas en la terminal móvil.
- 5Procedimiento conforme a una cualquiera de las reivindicaciones 1 a 4, que comprende a lo máximo un número predeterminado de iteraciones (E17) de las etapas de solicitud de conexión y de autentificación (E6-E10;E6-E15) cuando la autentificación ha fracasado.
- 6Procedimiento conforme a la reivindicación 5, que comprende una iteración (E18) de las etapas (E2E17) enunciadas en la reivindicación 1 relativamente a otro punto de acceso (AP) en la zona de cobertura de la terminal móvil (TM) cuando la autentificación ha fracasado (E17) un número predeterminado de veces.
- 7Procedimiento conforme a una cualquiera de las reivindicaciones 1 a 6, que comprende en la terminal móvil (TM) una búsqueda (E1) de un punto de acceso óptimo (AP) que tiene el mayor nivel de potencia recibida por la terminal móvil entre puntos de acceso en la zona de cobertura de la terminal móvil a fin de que la terminal móvil (TM) introduzca la dirección (ADAP) del punto de acceso óptimo en la demanda (RQ).
- 8Procedimiento conforme a una cualquiera de las reivindicaciones 1 a 6, que comprende en la terminal móvil (TM) una búsqueda (E1) de puntos de acceso en la zona de cobertura de la terminal móvil a fin de introducir direcciones (ADAP) de los puntos de acceso encontrados en la demanda (RQ), y en el medio de gestión (PFG) una selección (E3) de la dirección (ADAP) de un punto de acceso óptimo (AP) entre las direcciones de punto de acceso extraídas de la demanda (RQ) según un criterio predeterminado para introducir la dirección del punto de acceso óptimo en el mensaje de confirmación (MC) transmitido a la terminal móvil y el mensaje de solicitud de conexión (MDC) transmitido al punto de acceso óptimo (AP).
- 9Procedimiento conforme a la reivindicación 8, según el cual el criterio predeterminado es relativo a una comparación de niveles de potencia (NP) de los puntos de acceso encontrados (AP) recibidos por la terminal móvil (TM) y transmitidos en asociación con las direcciones (ADAP) de los puntos de acceso encontrados en la demanda (RQ) a fin de que el medio de gestión (PFG) determine el punto de acceso que tiene el mayor nivel de potencia recibida como punto de acceso óptimo.
- 10Procedimiento conforme a la reivindicación 8 o 9, según el cual el criterio predeterminado es relativo a una comparación de cargas de tráfico de los puntos de acceso (AP) encontrados (E1) por la terminal móvil (TM) a fin de que el medio de gestión (PFG) seleccione el punto de acceso que tiene la carga más pequeña como punto de acceso óptimo.
- 11Procedimiento conforme a una cualquiera de las reivindicaciones 8 a 10, según el cual el criterio predeterminado es relativo además a una eliminación de las direcciones (ADAP) de los puntos de acceso encontrados (AP) que están situados en el exterior de una zona de localización que incluye la terminal móvil (TM) y definida en la red celular (RC), antes de la selección de la dirección del punto de acceso óptimo.
- 12Procedimiento conforme a una cualquiera de las reivindicaciones 1 a 11, caracterizado porque el código secreto (CS) determinado por el medio de gestión (PFG) es generado de manera pseudo-aleatoria y tiene una longitud superior a 16 octetos. ES 2 271 503 T3
- 13Procedimiento conforme a una cualquiera de las reivindicaciones 1 a 12, que comprende en el medio de gestión (PFG) una determinación (E3) de la clave de sesión (KS) en el lugar de las determinaciones (E6) de la clave de sesión en la terminal móvil (TM) y el punto de acceso (AP), y una introducción (E4, E5) de la clave de sesión determinada (KS) en el lugar del código secreto en el mensaje de confirmación (MC) y el mensaje de solicitud de conexión (MDC).
- 14Sistema de autentificación entre una red inalámbrica de corto alcance (RFP) que tiene puntos de acceso y una terminal móvil (TM) en una red de radiocomunicaciones celular (RC), caracterizado porque comprende:un medio de gestión (PFG) para determinar un código secreto (CS) en respuesta a una demanda (RQ) que incluye la dirección (ADTM) de la terminal móvil y la dirección (ADAP) de un punto de acceso (AP) situado en la zona de cobertura de la terminal móvil (TM) relativa a la red de corto alcance y que es transmitida desde la terminal móvil por medio de red celular (RC), y para transmitir un mensaje de confirmación (MC) que incluye el código secreto y la dirección del punto de acceso extraída de la demanda (RQ) a la terminal móvil (TM) por medio de la red celular (RC) y un mensaje de solicitud de conexión (MDC) que incluye el código secreto y la dirección (ADTM) de la terminal móvil extraída de la demanda en el punto de acceso (AP), la terminal móvil para solicitar una conexión al punto de acceso (AP) designado por la dirección (ADAP) extraída del mensaje de confirmación (MC) y para determinar una clave de sesión (KS) en función de la dirección (ADAP) del punto de acceso, de la dirección (ADTM) de la terminal móvil y del código secreto (CS) extraído del mensaje de confirmación (MC), y el punto de acceso (AP) para determinar la clave de sesión (KS) en función de la dirección (ADAP) del punto de acceso, de la dirección (ADTM) de la terminal móvil y del código secreto (CS) extraído del mensaje de solicitud de conexión (MDC) y para autentificar la terminal móvil en función de la clave de sesión (KS).
- 15Sistema conforme a la reivindicación 14, caracterizado porque el medio de gestión determina él mismo la clave de sesión y la introduce en lugar del código secreto en el mensaje de confirmación (MC) y el mensaje de solicitud de conexión (MDC).
Independent claims15
66 paragraphs in 4 sections, as filed
ES 2 271 503 T3
DESCRIPTION
Authentication between a cellular network mobile terminal and a short-range network access point.
The present invention generally concerns the establishment of a connection between an access point of a short-range wireless network, of the Bluetooth or Wi-Fi type, and a mobile terminal of a cellular network of the GSM type equipped with a transmitter module. receiver to communicate with a short-range network access point. It concerns more particularly the generation of a link key in the authentication of the mobile terminal and the access point in order to pair them.
With regard to the security of a specifically Bluetooth radio link, for example a user who wishes to establish a Bluetooth link between a portable personal computer and a cellular mobile terminal enters a PIN identification code as a secret key on the computer keyboards and the mobile terminal. The computer and the mobile terminal each establish a link key based on random numbers exchanged between them, the secret key, and the Bluetooth addresses of the computer and the mobile terminal. If, for example, the personal computer is considered as the authenticator of the link, it generates a random number (test) that communicates via the Bluetooth radio interface with the mobile terminal. The terminal calculates a response that depends on the random number received, the link key and the Bluetooth address of the mobile terminal in order for the computer to compare the response of the terminal with the one it has calculated, which authenticates the mobile terminal when there is identity of the compared responses.
The pairing of the computer and the terminal needs a secret key (PIN code) to share the binding key. The secret key must be long enough and absent from dictionaries so that the secret key is not exposed to attacks whose objective is to find the same to deduce the link key and another encryption key. Such attacks once again call into question the authentication and integrity of the data exchanged.
To prevent such attacks, the secret key must be relatively long, which causes a laborious and error-prone entry, specifically in the mobile terminal whose human-machine interface is limited.
Patent application US 2002/031228 A1 discloses an access device for example to open a hotel room door. The access device may be connected via a Bluetooth link to a mobile terminal of a cellular telecommunications network. The mobile terminal requires a connection to a server associated with the hotel via the cellular network or a Bluetooth link. The server then transmits a key to the mobile terminal. After a connection to the access device, the mobile terminal sends the key to the access device which compares the received key with a key memorized in the access device in order to validate it and provide access to the room. No authentication of the mobile terminal by the access device is provided.
The article by Uri Blumenthal et al., “A Scheme for Authentification and Dynamic Key Exchange in Wireless Networks”, Bell Labs Technical Journal 7 (2), P. 37-48, 2002, describes a combination of authentications for a mobile terminal that depends on a short-range "home" network where an authentication server contains a secret key also previously memorized in the mobile terminal, when it is in connection with a point access point linked to an authentication server of another short-range network called a "foreign" network. The server of the home network authenticates both the mobile terminal and the server of the foreign network on the basis of a first "authenticator" that is calculated by the mobile terminal based on the secret key, of random numbers provided by the server the foreign network and the terminal and a terminal identifier. The first authenticator is transmitted to the server of the home network through the access point and the server of the foreign network. The server of the home network recalculates the first authenticator based specifically on the memorized secret key found in correspondence with the identifier of the terminal transmitted by the server of the foreign network.
If the terminal is authenticated following a match of the first authenticators transmitted and recalculated independent of any session key, the server of the home network generates a second "authenticator" based on the secret key, the random numbers and the identifier terminal and calculates a session key based on the secret key, a third random number, and the second authenticator. The second authenticator is transmitted to the terminal through the foreign network server and the access point for the terminal to recalculate the second authenticator and authenticate the home network server when the transmitted and recalculated second authenticators are equal. After this second independent authentication of the session key, the terminal generates the session key.
All the above parameters are transmitted through the link mobile terminal - access point - server of the foreign network - server of the home network, without any link through the home network between the mobile terminal and the server of the home network, which requires that the secret key be previously memorized in the mobile terminal and the home network server in order to respect authentication security, weakening the authentications by using the same secret key to generate the session key for each session between the mobile terminal and an access point.
Patent application WO 02/07135 A1 concerns the activation of an interactive terminal connected to a telecommunication network from a mobile terminal in a radiotelephony network. The mobile terminal signals its presence in the vicinity of the terminal, specifically by transmitting a message comprising the terminal identifier and an identifier of the location area of the radiotelephony network to a management means that invites the user of the terminal to approach to the closest terminal on which the user is authenticated by means of a secret code read from a memory card, or a biometric fingerprint of the user, transmitted by the terminal to a server. Patent application WO 02/07135 A1 does not suggest any mutual authentication of the mobile terminal and the terminal through the radiotelephony network.
ES 2 271 503 T3
The invention aims to ensure the establishment of a connection between a cellular mobile terminal and an access point of a short-range wireless network without requiring the introduction of a secret key (PIN code), fully ensuring the use of such a key that can be very long and renewed in each session between the mobile terminal and an access point.
To achieve this objective, an authentication procedure that precedes a session between a short-range wireless network that has access points and a mobile terminal in a cellular radiocommunication network, is characterized in that it comprises the following steps:
- transmission of a request that includes an address of the mobile terminal and an address of an access point located in the coverage area of the mobile terminal relative to the short-range network, from the mobile terminal to a management means by means of the cellular network,
- determination of a secret code by the management means,
- from the management means, transmission of a confirmation message that includes the secret code and the address of the access point extracted from the request to the mobile terminal by means of the cellular network and of a connection request message that includes the secret code and the address of the mobile terminal extracted from the request to the access point,
- connection request from the mobile terminal to the access point designated by the address extracted from the confirmation message so that the mobile terminal and the access point determine a session key based on the address of the access point, the address of the mobile terminal and the secret code extracted from the confirmation message and the connection request message, and
- authentication of the mobile terminal by the access point based on the session key.
The authentication may comprise a request for determination from the access point of a response based on the session key to the mobile terminal that transmits the response to the access point, via the short-range network, and at the point of access. access, a determination of a response as a function of the session key and a comparison of the responses to authorize the opening of a session between the access point and the mobile terminal when at least the compared responses are identical.
Preferably, the preceding authentication of the mobile terminal by the access point is completed by an authentication of the access point by the mobile terminal based on the session key, when the access point has authenticated the mobile terminal. In that case, the method may comprise following an identity of the responses compared at the access point, an invitation transmitted to the mobile terminal in order for the mobile terminal to authenticate the access point by requesting the access point to determine a second response based on the session key and transmit the second response to the mobile terminal via the short-range network, determining a second response based on the session key and comparing the second responses in order to authorize the opening of the session only after an identity of the second responses compared at the mobile terminal.
In practice, it is preferable that the mobile terminal searches for several access points in the coverage area of the mobile terminal in order to enter addresses of the access points found in the application. The management means then selects the address of an optimal access point among the access point addresses extracted from the request according to one or more predetermined criteria to enter the address of the optimal access point in the confirmation message transmitted to the mobile terminal and the connection request message transmitted to the optimal access point.
According to a variant, the management means determines the session key instead of the session key determinations in the mobile terminal and the access point, and enters the determined session key instead of the secret code in the confirmation message. and the connection request message so that during authentication the responses to be compared are specifically determined as a function of the session key extracted from the preceding messages.
The invention also concerns an authentication system between a short-range wireless network having access points and a mobile terminal in a cellular radiocommunication network that is characterized according to claim 14.
In a variant, the management means can determine the session key itself and enter it instead of the secret code in the confirmation message and the connection request message.
Other characteristics and advantages of the present invention will appear more clearly upon reading the following description of various preferred embodiments of the invention, by way of non-limiting examples, with reference to the corresponding annexed drawings in which:
Figure 1 is a schematic block diagram of a telecommunications system comprising a mobile terminal in a cellular radiocommunication network and at least one access point in a short-range wireless network to carry out the authentication procedure according to the invention; Y
Figure 2 shows main stages of an algorithm of the authentication procedure between the mobile terminal and the access point according to the invention.
The telecommunications system shown in figure 1 to carry out the authentication procedure according to the invention essentially comprises a mobile cellular terminal TM in a cellular radiocommunication network RC, one or more access points AP linked by a distribution network RD in a short-range wireless network RFP that gives access to a high-flow packet network RP, such as the Internet, and a PFG management platform of the invention. By way of example, the RC cellular network is a GSM network and the RFP short-range wireless network is a Bluetooth network.
The mobile terminal TM comprises two radio interfaces respectively with the cellular network RC and the short-range network RFP.
The access points AP and in a variant the mobile terminals each comprise a pseudo-random generator and each generate an authentication algorithm AA to produce responses RP1, RP2 each as a function of a random number, a secret code and a the address of the mobile terminal or access point in the RFP short-range network.
ES 2 271 503 T3
A session key algorithm AS is also implemented in the access points and the mobile terminal.
The cellular network RC, such as a GSM network, is schematically represented in Figure 1 by main means to which the mobile terminal TM is temporarily connected such as a base station BTS, a base station controller BSC, a switch of the MSC mobile service associated with a visitor location recorder VLR, and a nominal location recorder HLR.
The management platform PFG is linked to the nominal location register HLR, either directly as an authentication center (not shown) linked to the register HLR, or as a server through an intermediate network such as the Internet RP. The PFG platform can also be linked to a short message center SMSC (Short Mesage Service Center) when RQ requests are transmitted to it in the form of short messages by mobile terminals, and / or it can be linked to a USSD signaling message center. (Unstructured Supplementary Service Data) when RQ requests are transmitted to it in the form of USSD messages by mobile terminals. USSD messages are transmitted over the course of actual established sessions and faster than short messages. The short message center and the signaling message center will be referred to below indifferently by "CM message center". The PFG platform specifically contains a pseudo-random generator for generating CS secret codes at the request of mobile terminals, such as terminal TM. According to the invention, secret codes typically have a long length of at least sixteen octets, that is, a length greater than 128 bits.
The PFG platform contains, according to variants of the invention, a database that lists the ADAP addresses of the AP access points of various short-range wireless networks, in association with the geographical locations of the AP access points in relation to zones. localization determined ZL in the RC cellular network. It is recalled that a location area in a cellular network covers several cells respectively associated with base stations BTS and that a switch MSC manages one or more location areas.
As will be seen below, the PFG platform constitutes an intermediate management means between a mobile terminal TM and an access point AP in order to transmit a secret code CS to them to proceed with their authentication. According to variants described below, the PFG platform also serves to select an optimal access point in response to a request RQ from a mobile terminal.
In figure 1 only a short-range wireless network is shown; It will be understood that the mobile terminal TM can communicate with any short-range wireless network particularly in a public place, such as a station, a merchandise gallery, an air station, a hotel, etc. An AP radio access point is, for example, a terminal equipped with a Bluetooth radio interface to be able to communicate within a radius of a few tens of meters with mobile terminals TM, and a line interface to communicate on the one hand with other AP access points to via RD distribution network, if any, short-range wireless network, and on the other hand to offer high-flow packet communications to mobile terminals thanks to a link of the RD distribution network with the Internet RP. In certain configurations of the short-range wireless network, the RD distribution network is an intranet that is directly linked by xDSL lines to the RP Internet, or the RD distribution network is confused with the RP Internet and each access point AP is directly linked to the Internet RP via xDSL lines.
As shown in Figure 2, the authentication procedure according to a preferred embodiment of the invention essentially comprises steps E1 to E17. Initially, the mobile terminal TM has been started up and recognized by the cellular network RC in an area radio-electrically covered by it. The terminal TM in surveillance state is thus located in a location zone ZL of the RC network and a temporary identity TMSI has been assigned to it by the VLR register connected to this location zone, as is known.
In step E1, the user of the terminal TM who enters the coverage area of the short-range wireless network RFP with the access points AP decides to select a Bluetooth menu on his terminal TM, and particularly a search sub-menu (inquiry mode) of AP access points. The access points AP in the form of terminals can be searched, that is, each periodically scrutinizes the presence of a mobile terminal to detect an inquiry transmitted by the mobile terminals. In this way, the mobile terminal TM receives the ADAP addresses of the access points located in the coverage area of the mobile terminal TM relative to the short-range network RFP. The terminal TM chooses among the responses to its search that it receives, the addresses of the entities of the RFP short-range network that correspond to the classes of devices associated with the access points, in order to discard any addresses that come from Any device equipped with a transmitter-receiver module compatible with the RFP network, such as a mobile telephone terminal, a PDA personal number assistant, a laptop, etc.
In step E2, the ADAP addresses of the access points available and found during the preceding search are stored in the terminal TM and entered in a request RQ to be transmitted to the management platform PFG through the fixed network of the cellular network. RC. The request RQ comprises the ADTM address of the terminal TM pre-memorized therein so that the PFG platform can communicate it to the subsequently selected access points. The request RQ comprises as the recipient address an identifier IDPFG of the platform PFG which has been pre-memorized in the mobile terminal TM. The RQ request may be in the form of a short message or a USSD signaling message and the PFG platform is then linked to the corresponding message center CM.
Once the RQ request has been automatically issued by the TM terminal and received by the PFG platform, the platform examines the list of ADAP access point addresses extracted from the RQ request in order to select the optimal access point based on of one or more predetermined criteria in step E3. The selection of the optimal access point is preceded by a verification of the user profile of the mobile terminal TM identifi4
ES 2 271 503 T3 by a permanent identifier IMSI in order to authorize it to access an access point of the short-range wireless network RFP.
According to a first variant, a predetermined criterion is relative to a comparison of power levels of reference signals emitted by the access points found by the mobile terminal TM, received by the terminal TM. In this variant, the terminal TM also includes, in association with each access point ADAP address available and found in the transmitted request RQ, a power level NP received at the terminal. The terminal then transmits the request RQ with pairs ADAP, NP to the management platform PFG which compares the received power levels NP in order to determine the highest received power level and select the access point AP associated with the highest power level received, as the optimal access point, to establish a connection with the TM terminal.
According to any variant not very similar to the preceding one, the optimal access point that has the highest power level received by the mobile terminal is searched for and selected in step E1 among available access points found in the terminal's coverage area. mobile TM, by the mobile terminal TM itself instead of the PFG platform. The RQ request only contains the ADAP address of the optimal access point AP instead of the list of the ADAP peers, NP.
According to a second variant, a predetermined criterion is relative to a comparison of traffic loads of the access points AP available and found by the mobile terminal TM so that the management platform PFG selects the access point that has the most load. small traffic as an optimal access point. The traffic loads of the access points AP of the short-range network RFP are received by the RD distribution network that communicates them periodically, through the Internet RP or a specialized line, with the PFG platform for a database update of data related to the access points.
According to a complementary variant to be combined with the first or second preceding variant, the PFG platform interrogates the nominal location recorder HLR of the RC cellular network in order to read the IDZL identifier of the location area where the TM terminal is located in the network cellular, prior to the selection of the optimal access point address. Based on the location zone indicator IDZL, the PFG platform removes the ADAP addresses from the list included in the RQ request, which designate available and found access points APs that are located outside the location zone including the mobile terminal. TM and defined in the cellular network. This complementary variant prevents a mobile terminal from being substituted at the access point by declaring itself with an address of an access point very far from the mobile terminal, in order to communicate with it. Then the optimal access point is selected by the PFG platform or simply taking the address of the first access point in the list extracted from the RQ request, or combining this variant with the variant of the power levels or traffic loads of the access points to select the access point with the highest power level or the smallest traffic load among those located in the locate area.
In step E3, likewise the pseudo-random generator in the management platform PFG determines a secret code CS that has a great length, at least equal to 128 bits.
The PFG platform then then prepares two messages.
In step E4, a confirmation message MC containing the ADAP address of the optimal access point and the produced secret code CS is set by the platform PFG for transmission to the mobile terminal TM through the cellular network RC. The MC message is of the same type as the RQ request, that is a short message SM or a USSD message, and passes through the corresponding message center CM. The secret code CS extracted from the message MC is stored in association with the optimal access point address ADAP in the mobile terminal TM. The terminal TM possesses in step E4 the secret code CS, as if, according to the prior art, the user had entered the PIN code on the keyboard of the terminal.
In parallel to step E4, the PFG platform establishes an MDC connection request message that includes the ADTM address of the mobile terminal TM, the ADAP address of the optimal access point and the generated secret code CS destined for the access point optimal AP in the short-range wireless network, at stage E5. The MDC connection request message is in the form of an IP (Internet Protocol) packet that transits through the Internet RP towards the distribution network RD of the short-range wireless network RFP. The secret code CS extracted from the MDC message is stored in association with the ADTM address in the optimal access point AP.
In response to the ADAP address of the optimal access point AP extracted from the confirmation message MC received by the mobile terminal TM, it tends to connect to the optimal access point AP thus identified inviting the optimal access point to authenticate it. In step E6, the mobile terminal TM emits a first frame T1 containing the address of the terminal ADTM, the ADAP address of the optimal access point and a connection request and session key determination indicator DC.
The optimal access point in periodical search mode recognizes that the T1 frame is destined for it. The mobile terminal and the access point then each determine a common session key KS by applying to the session key algorithm AS the address of the mobile terminal ADTM, the ADAP address of the access point, the secret code CS and one or more RAND random numbers exchanged between them through the RFP short-range network. The secret code CS used in the mobile terminal is thus extracted in the confirmation message MC, while the secret code CS used in the access point AP is that extracted from the connection request message MDC. The mobile terminal TM and the optimal access point AP are thus paired. The session key KS is memorized in the terminal and the access point, and is used, specifically for authentication and data encryption, only until the access point AP and the mobile terminal TM are disconnected.
The authentication of the mobile terminal TM is then triggered by the optimal access point by broadcasting in response to the first frame T1,
ES 2 271 503 T3 a T2 frame that includes the optimal access point address AdAP, the ADTM address of the terminal TM, a random number RAP generated by the pseudo-random generator at the access point and a response request indicator DRP towards the mobile terminal TM, in step E7.
The procedure then proceeds to steps E8, E9 and E10 relating to an actual authentication of the mobile terminal TM by the optimal access point AP. Upon receipt of the T2 frame with the response request indicator, in step E8 the mobile terminal TM applies the RAP random number extracted from the T2 frame, the session key KS determined in step E6 and its ADTM address to the algorithm AA authentication that produces an RP1 response. Also in step E8, the optimal access point AP executes an analogous application: RP1 = AA (RAP, KS, ADTM), but in which the session key is the one that it has determined in step E6 and associated with the ADTM address. Then the mobile terminal emits, in step E9, a T3 frame that includes, in addition to the ADTM and ADAP addresses, the response RP1 = AA (RAP, KS, ADTM) that has been determined in the mobile terminal. The T3 frame is recognized by the optimal access point AP which in step E10 compares the response RP1 determined at the optimal access point with the response RP1 extracted from the received frame T3. If the responses RP1 compared are identical, the optimal access point AP authorizes the opening of a session through it from the mobile terminal TM towards the distribution network RD and the Internet RP, in step E16.
The session key KS for this open session will be used to determine the session key of a subsequent session between the mobile terminal TM and the access point AP if the session key KS has not been erased in the meantime with the expiration of a duration counting from the memorization of the KS password, predetermined by the operator that manages the access point.
According to a more complete variant relating to mutual authentication, when the optimal access point AP has authenticated the mobile terminal TM in step E10, the optimal access point AP issues in step E11 a frame T4 containing the addresses ADAP and ADTM and an indicator IA to invite the terminal TM to authenticate it.
In response to the preceding frame T4, the mobile terminal TM triggers the authentication of the optimal access point by issuing a frame T5 destined for the optimal access point of ADAP address. Frame T5 includes a random number RTM generated by the pseudo-random generator in the mobile terminal and a response request indicator DRP, in step E12. Following frame T5, in step E13 the access point AP applies the random number RTM extracted from frame T5, the session key KS determined in step E6 and its ADAP address to the authentication algorithm AA that produces a second response RP2. Also in step E13, the mobile terminal TM executes an application: RP2 = AA (RTM, KS, ADAP), but in which the session key is the one determined in step E6 and associated with the ADAP address. Then the optimal access point AP emits a T6 frame that includes, in addition to the ADAP and ADTM addresses, the response RP2 = AA (RTM, KS, ADAP) that has been determined in the optimal access point. The frame T6 is recognized by the mobile terminal TM who in step E15 compares the response RP2 determined in the mobile terminal with the response RP2 extracted from the received frame T6. If the compared responses RP2 are identical, the terminal TM confirms by sending another frame the opening of the requested session at the optimal access point AP in step E16.
In a variant, the session key KS is not determined separately by the mobile terminal TM and the optimal access point AP in step E6 but is previously determined by the management platform PFG, in step E3. The platform randomly generates a session key KS of the same size as that according to the previously described embodiment.
However, to ensure consistency, the platform may contain the AS session key algorithm. At the end of step E3, the platform has selected the optimal access point and has associated the ADAP address of the optimal access point with the ADTM address of the mobile terminal extracted from the RQ request, which allows it to determine the session key applying the ADAP and ADTM addresses, the CS secret code and one or more RAND random numbers to the AS algorithm, that is:
KS = AS (ADAP, ADTM, CS, RAND).
In steps E4 and E5, the management platform PFG introduces the determined session key KS in place of the secret code CS in the confirmation message MC transmitted to the mobile terminal and in the connection request message MDC transmitted to the point of optimal access for optimal access point and mobile terminal to use session key KS for authentication E6 to E10 or E6 to E15 and then open session in step E16, step E6 not understanding the determination of the session key KS.
As indicated in step E17, if the authentication of the mobile terminal by the optimal access point has failed, that is, if the responses RP1 compared in step E10 are different, or if the mutual authentication has failed, that is, if the RP2 responses compared in step E15 are different, An attempt to open a session is repeated by executing steps E6 to E10 according to the authentication of the terminal by the optimal access point, or steps E6 to E15 according to the mutual authentication variant.
In practice, the connection request, response determination and response comparison steps E6aE10 orE6aE15 can be repeated a maximum of N times while the compared responses RP1 or RP2 are different, N being a predetermined number of iterations, for example the same to
3.
If after N connection request iterations in step E17, the authentication has failed, that is, the compared responses are still different, the procedure can automatically return to step E2 in order to execute the following steps E3 to E17 relatively in the next step. ADAP address of another access point selected according to predetermined criteria, for example from the list included in the RQ request, as indicated in an intermediate step E18. Selecting this other access point in the list naturally excludes the last optimal access point that has been previously
ES 2 271 503 T3 selected and for which N connection attempts have failed. The other optimal access point selected is located in the coverage area of the mobile terminal TM relative to the RFP short-range network and may be the access point with the highest received power level or the smallest traffic load in the remaining list, or the one that succeeds the last selected optimal access point in the list.
Although the invention has been described for a cellular network of the GSM type and a short-range wireless network of the Bluetooth type, the invention is equally applicable in the context of a radio communication network for mobiles of the UMTS type or more generally of the third generation type. , and other short-range wireless networks for example of the type according to the IEEE 802.11b standard and according to the other standards following that, in other words, for networks also called Wi-Fi networks (Wireless Fidelity).
Contents4
2 sheets
Sheet 1 Sheet 2
9 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 03292926 | European Patent Office (EPO) | A | |
| 03292926 | – | – | – |
| EP20030292926 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| EP1536592A1 | European Patent Office (EPO) | A1 | |
| US2005130627A1 | United States of America | A1 | |
| EP1536592B1 | European Patent Office (EPO) | B1 | |
| AT336125T | Austria | T | |
| ATE336125T1 | Austria | T1 | |
| DE60307482D1 | Germany | D1 | |
| DE60307482T2 | Germany | T2 | |
| ES2271503T3This record | Spain | T3 | |
| US7590246B2 | United States of America | B2 |
Numbers
- Publication
- 2271503
- Publication, DOCDB
- 2271503
- Publication, EPODOC
- ES2271503T
- Application
- 3292926
- Application, DOCDB
- 03292926
- Application, EPODOC
- ES20030292926T
Titles2
- Spanish
- AUTENTIFICACION ENTRE UNA TERMINAL MOVIL DE RED CELULAR Y UN PUNTO DE ACCESO DE LA RED DE CORTO ALCANCE.
- English
- AUTHENTIFICATION BETWEEN A MOBILE CELLULAR NETWORK TERMINAL AND A SHORT REACH NETWORK ACCESS POINT.
Classification
- CPC, 9
- H04W12/06
- H04L63/0869
- H04L63/18
- H04W84/18
- H04W88/06
- H04L2463/061
- H04W12/71
- H04W12/73
- H04W12/50
- IPC, 3
- H04L12 28
- H04L12 56
- H04W12 00