Method of identification, authentication and control of coverage based on the bluetooth tm standard
Abstract
Method of identification, authentication and coverage control, based on the Bluetooth standard and implemented in a system comprising: - a central entity; - a network of beacons; - a set of terminals, in which each terminal is attached, at least, to a beacon; where the method defines that for each terminal [1] there is a profile that includes an authentication service [5] and a coverage control service [6], with a unique and equal service identifier for all Bluetooth devices [ 4]. In addition, when the Bluetooth device [4] is detected by a beacon [2] of the network itself, it is connected to the coverage service [6] of the device [4], where if the identification is positive: the device [4] is consider a terminal [1] of the system; the membership of the terminal [1] to the beacon [2] is authenticated by connecting said beacon [2] to the authentication service [5] of the terminal [1] by exchanging at least four messages; after the authentication process, if it is positive, the terminal [1] is attached to the beacon [2], if it is negative, the terminal [1] belongs to the system, but is not attached to said beacon [2].

Term
0.3 yearsto projected expiry
Projected expiry 19 January 2027, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
4 claims: 4 independent, 0 dependent
- 1ES 2 303 464 A1 REIVINDICACIONES 1. Método de identificación, autentificación y control de cobertura, implementado en un sistema que comprende:- una entidad central;- una red de balizas;- un conjunto de terminales, en el que cada terminal está adscrito, al menos, a una baliza;donde dicho método está caracterizado porque para cada terminal [1] se define un perfil que incluye un servicio de autentificación [5] y un servicio de control de cobertura [6], con un identificador de servicio único e igual para todos los dispositivos Bluetooth ® [4];caracterizado además porque cuando el dispositivo Bluetooth ® [4] es detectado por una baliza [2] propia de la red, se conecta al servicio de cobertura [6] del dispositivo [4], donde si la identificación es positiva: - el dispositivo [4] se considera un terminal [1] propio del sistema;- se autentifica la pertenencia del terminal [1] a la baliza [2] mediante la conexión de dicha baliza [2] al servicio de autentificación [5] del terminal [1] intercambiándose, al menos, cuatro mensajes;- tras el proceso de autentificación, si es positivo, el terminal [1] está adscrito a la baliza [2], si es negativo, el terminal [1] pertenece al sistema, pero no está adscrito a dicha baliza [2].
- 2Método de identificación, autentificación y control de cobertura, según reivindicación primera, caracterizado porque para la identificación del dispositivo Bluetooth ® , se intercambian dos mensajes, uno de servicio disponible de la baliza [2] al terminal [1] y uno de respuesta del terminal [1] a la baliza [2].
- 3Método de identificación, autentificación y control de cobertura, según reivindicaciones anteriores, caracterizado porque en el servicio de control de cobertura [6] se monitoriza el estado del canal de sincronismo Bluetooth ® ya que, en el momento en que el terminal [1] salga de cobertura [3], este canal caerá, al igual que el servicio, generando un evento de “error en la conexión” que terminal [1] y baliza [2] capturan, conociendo de este modo que la cobertura [3] se ha perdido.
- 4Método de identificación, autentificación y control de cobertura, según reivindicaciones anteriores, caracterizado porque en la conexión al servicio de autenticación [5] se intercambian, al menos, los siguientes mensajes:- Mensaje 1: La baliza [2] le manda al terminal [1] su identificador de baliza [2], y le pide que le mande sus credenciales de usuario;- Mensaje 2: El terminal [1] recoge el identificador de la baliza [2] y busca la credencial asociada a ese identi- ficador;una vez que la encuentra, la envía de vuelta a la baliza [2] para que ésta la compruebe;- Mensaje 3: La baliza [2] comprueba la credencial contra su base de datos de usuarios y envía de vuelta un mensaje al terminal [1] informándole del resultado de dicha comprobación (Ok o KO);- Mensaje 4: El terminal [1] conoce, por fin, si está en su baliza [2] y le devuelve un ACK (reconocimiento o acknowledgement) a la baliza [2].
Independent claims4
92 paragraphs in 6 sections, as filed
ES 2 303 464 A1
DESCRIPTION
Identification, authentication and coverage control method based on the Bluetooth® standard.
Object of the invention
The object of the present invention is to define the way in which, in a beacon system that provide Bluetooth coverage<sup>®</sup>When they go into coverage, the different terminals are identified, authenticated and provided with services, in addition to how they carry out the control of the status of their coverage.
The present invention falls within the field of telecommunications networks. And more specifically in the identification and authentication of mobile phone users within a beacon system that provide coverage based on the Bluetooth standard.<sup>®</sup>.
Background of the invention
It is known that abbreviations and acronyms are frequently used in the field of mobile telephony. Below is a glossary of acronyms / abbreviations, as well as a series of terms that are used throughout this specification and that are defined below:
- RF: radio frequency.
- Bluetooth®: it is the standard that defines a global standard for wireless communication, which enables the transmission of voice and data between different devices through an RF link.
- Beacon: device that provides Bluetooth® coverage to an area and that manages the checking of credentials of the different Users (see Authentication - later).
- Bluetooth® device: mobile device enabled to use Bluetooth®.
- Terminal: mobile device with Bluetooth® capabilities that interacts with the Beacon.
- User: person who uses the Terminal.
- Authentication: it is the process of determining if a User is authorized to carry out a given action. Some authentication systems include both identification and authorization, while others only include one or the other. In this case, given that the objective of the system is simply to identify the User and inform him of his coverage status, only identification will be necessary.
- Coverage: radius of action in which the Beacon is visible to a Terminal.
- Bluetooth® profile: services offered by a Bluetooth® device.
- User Credential: data that identifies a Terminal and that allows it to authenticate successfully against a specific Beacon.
Bluetooth<sup>®</sup> It is the standard that defines a global standard for wireless communication, which enables the transmission of voice and data between different equipment through an RF link. This exchange of voice and data is carried out through the execution of the different services available to the devices.
Bluetooth<sup>®</sup> defines a Bluetooth device discovery procedure<sup>®</sup>. In this way, a Bluetooth® device can “see” that other Bluetooth® devices are within range. This discovery is not automatic on mobile devices or computers, but it is the user who manually (or the application) who must update the list by launching the procedure that the Bluetooth standard<sup>®</sup> provides for it. The list includes the name that the user has given to his device, and that can be any string since in a mobile phone the user is free to change the Bluetooth name<sup>®</sup> of your device, and also the Bluetooth MAC address<sup>®</sup>, a unique identifier of the device given by the manufacturer and that cannot be changed.
Once a Bluetooth device<sup>®</sup> You have obtained a list of neighboring devices, that is to say that they are within range of action, you also have the possibility of discovering which services each of its neighbors exposes or of trying to connect directly to a service by means of the service identifier. Again it is the user, or an application, who launches the request. To carry out this task, both devices (both the querying and the queried) must implement the profile "Service Discovery Application (SDAP)" that will provide them with a service discovery service, regardless of redundancy, that both devices will know how to use.
ES 2 303 464 A1
Bluetooth® profiles define the services that a Bluetooth® device exposes and how they should be used. This definition ensures that devices that implement the same profile can communicate without interoperability problems. Examples of profiles follow:
- Generic Access (GAP))
- Service Discovery Application (SDAP)
- Serial port (SPP)
- Dial-up networking (DUN)
Bluetooth® defines, in turn, a procedure for discovering Bluetooth® devices. In this way a Bluetooth device<sup>®</sup> You can poll the Bluetoothi1 devices within your reach.
The Bluetooth standard<sup>®</sup> defines an authentication procedure based on device pairing. This pairing occurs only the first time that two devices try to connect and is used for users to allow the connection between their Bluetooth devices.<sup>®</sup> by entering a common code (PIN). In mobile telephony, it is the user who decides if his device requires this authentication to accept connection requests from other Bluetooth devices<sup>®</sup>. If no pairing is required, any other Bluetooth device<sup>® </sup>It can connect with the user's mobile phone. It is a procedure, however, quite limited since it does not allow the exchange of additional data (it is neither flexible nor versatile), the exchanged codes do not provide a high level of security and, most importantly, authenticate at the device level , not at the service level, so that once two devices are paired, any of their services can exchange data.
After pairing two Bluetooth devices<sup>®</sup> since they can start exchanging data using any of the services they have. Bluetooth® uses a Frequency Hopping system, that is, it changes the frequency at which it emits from time to time, in this way it tries to minimize interference from other systems that emit in nearby bands. Obviously, some synchronization must occur between two connected devices to always use the same frequency at any given time. For this Bluetooth<sup>®</sup> It has a service channel called synchronism. Without this channel, communication cannot take place, the loss of the synchronism channel causes the connection to a service to drop.
The invention described in the present invention patent is integrated into a Bluetooth beacon system<sup>®</sup>. These beacons are connected to a central entity that provides them with the credentials of its associated users. So we have a system with the following actors:
- A central entity that sends the user credentials both to the terminals and to the beacons that make up the system.
- A network of beacons each providing coverage to a specific area and storing the credentials of all the terminals associated with that beacon.
- A set of terminals (Bluetooth® devices attached to the system, each with a credential for each beacon in which it is authorized.
Beacons continuously search for Bluetooth terminals<sup>®</sup> attached to the system, that is, users of the system. The beacons, therefore, must discriminate the attached terminals from the rest of the Bluetooth devices<sup>®</sup>. However, the data that Bluetooth<sup>®</sup> provided after a device discovery does not allow us to discriminate:
to. The Bluetooth identifier<sup>®</sup> The device is defined by the user, therefore it is not unique, and can be changed at any time by the user. Furthermore, it does not provide any information beyond a user name recognizable by the owner.
b. The Bluetooth MAC address<sup>®</sup> if it is unique, provided by the manufacturer, but it does not contain information that allows us to identify whether or not the device is a system terminal. To be useful, the system should properly maintain and update a database of Bluetooth MAC addresses<sup>®</sup> terminals, which excessively complicates the provision of users.
A terminal detected by the beacon, that is, that has passed the filter and is recognized as an integral part of the system, must immediately know its new coverage status, the beacon, in turn, must control which terminals it has in coverage. Both entities, beacon and terminal must have strict control of coverage (that is, they must instantly know any entry or exit of coverage from the terminal). At the beacon, a procedure based on periodic discoveries of devices could be a valid method to control the entry and exit of terminals in coverage. This same method in the terminal is revealed as unfeasible due to the excessive battery consumption that it would entail.
ES 2 303 464 A1
Once the beacon has detected which are the real users of the system, the beacon and terminals must be able to launch the authentication procedure transparently to the user. This will allow that, upon completion, both entities know if the terminal is in the area defined by a beacon to which it is associated or not. At this point, the standard Bluetooth pairing procedure<sup>®</sup> It is necessary as a previous step to the exchange of credentials but cannot be replaced for the following reasons:
to. It cannot be done transparently to the user. The user must enter their PIN on the phone.
b. Cannot add encryption beyond that provided by Bluetooth<sup>®</sup> in the transport layer.
c. It is not extensible, we cannot make it send new parameters or data that may be necessary in future versions of the system.
By way of example, US patent application US 2002/141586 is cited, which describes a device and a method capable of communicating with other networks using Bluetooth.<sup>®</sup>, including at least one authentication functionality.
Japanese patent application JP-2003-333052 describes a way to provide location-dependent services to mobile terminals, using short-range technology such as Bluetooth.<sup>®</sup>. But no special identification and authentication of the mobile terminals is mentioned to receive these position-dependent services.
However, none of the aforementioned antecedents solve the aforementioned problems regarding:
- Identification: Beacons must be able to discriminate their own terminals from other Bluetooth devices<sup>®</sup>.
- Coverage control: Between the beacon and the terminal, any entry or exit coverage of the terminal must be known instantly.
- Authentication: The beacon and the terminals must be able to launch the authentication procedure (in a transparent way to the user) that will allow, upon completion, that both entities know if the terminal is in the area defined by a beacon to which it is associated or not.
Description of the invention
The invention refers to a method of identification, authentication and coverage control according to claim
1. Preferred embodiments of the method are defined in the dependent claims.
The present invention refers to the method used to carry out the identification, authentication and coverage control of Bluetooth devices.<sup>®</sup> attached to a system consisting of different beacons connected to a central entity that provides them with the credentials of its associated users. So, have us- a system that includes:
- A central entity that sends the User credentials to both the Terminals and the Beacons that make up the system.
- A network of Beacons each providing coverage to a specific area and storing the credentials of all Terminals associated with that Beacon.
- A set of Terminals (Bluetooth® devices attached to the system) each one with a credential for each Beacon in which it is authorized.
For the identification of the terminals, a Bluetooth profile is defined<sup>®</sup> that all terminals are required to implement. This profile includes two services: the authentication service, which we will use as a way to exchange user credentials, and the coverage control service, which we will use to monitor coverage losses immediately. Both services have a unique and the same service identifier on all devices.
Once the Bluetooth device<sup>®</sup> has been detected by the beacon, it tries to connect to the device's coverage service, using the unique service identifier defined for that service. If the connection request fails, then the Bluetooth® device is not its own terminal. If, on the other hand, the beacon manages to connect to the service identified by said service identifier, the next thing to do is make sure that it is really the coverage control service and not one with the same service identifier. They exchange two messages, one of service available from the beacon to the terminal and another of response from the terminal to the beacon. Once this process is complete, we know if the Bluetooth device<sup>®</sup> is, or not, a terminal. In the event that it is, we are connected to your coverage control service.
ES 2 303 464 A1
The advantages offered by this system are, on the one hand, the possibility of discrimination of the terminals from the rest of Bluetooth® devices since the terminals will have (ex factory) certain Bluetooth® services with unique service identifiers, where said identifiers They cannot be changed without reconfiguring the internal software of the terminal that is not accessible to the user. Therefore, it is not possible to leave the terminal undetectable before a beacon by a user.
Another advantage it offers is that the beacon allows to discriminate the terminals from the rest of Bluetooth devices<sup>® </sup>with hardly any collaboration from them. This means saving device battery power, which is a critical development parameter in this field of technology.
A third advantage is that the beacon will never attempt to pair with a Bluetooth device<sup>®</sup> outside the system, since you must have previously identified the terminal as such. The procedure is as follows:
- If an error occurs when trying to connect to the coverage control service of the Bluetooth® device, the device does not find out and the beacon checks that it was not a terminal.
- If it does not give an error then, and only if it is the first time that both entities have seen each other, Bluetooth® will start the standard pairing procedure. The user will enter the predefined PIN and the process will continue normally until the connection is completed.
The coverage control service is a warning service. In this service, no more data is exchanged after the identification of the terminal. However, both beacon and terminal must monitor the status of said channel very carefully since the moment the terminal goes out of coverage, the Bluetooth synchronism channel<sup>®</sup> will fall, the coverage control service, in turn, will also drop, generating an event that both devices will be able to capture (connection error), thus knowing immediately that coverage has been lost.
The advantages offered by the coverage control service are, on the one hand, the simplification of this control, since the monitoring of the coverage service makes unnecessary a system based on pings or on successive executions of the device discovery service, which are more complicated. to maintain and implement.
On the other hand, it allows both the beacon and the terminal to detect coverage losses instantly, capturing the "service connection error" event instead of successively executing the device discovery service or using a ping-based system. with the associated latency errors and with the battery power consumption that it would entail.
Finally, it allows the area under coverage of the beacon to be enlarged since, since there is no data exchange, the disconnection of the coverage service only depends on the availability of the synchronism channel of the system itself, optimized according to the Bluetooth® standard and more stable than a connection with data to be processed and interpreted, such as pings.
Authentication occurs after ensuring that the Bluetooth device<sup>®</sup> it is a terminal and ensure your coverage control. The next step is to check if it is a terminal associated with this beacon or not. To do this, the beacon launches the authentication process. That is, it connects to the authentication service that the terminal must necessarily expose, since it is a device associated with the system. Four messages are exchanged in the authentication process:
Message 1: The beacon sends the terminal its beacon identifier, and asks it to send its user credentials.
Message 2: The terminal collects the identifier of the beacon and looks for the credential associated with that identifier.
Once it finds it, it sends it back to the beacon for it to check.
Message 3: The beacon checks the credential against its user database and sends a message back to the terminal, informing it of the result of said check (OK or KO).
Message 4: The terminal finally knows if it is at its beacon and returns an ACK (acknowledgment or acknowledgment) to the beacon.
The advantages of authentication are, firstly, that it defines a single way of exchanging data with the beacon, so that only the terminals can do so in a totally transparent way to the user.
Another advantage is that it is extensible, that is, new parameters can be added to exchange or more security if necessary.
Similarly, it allows additional authentication to Bluetooth pairing.<sup>®</sup> defined by the standard. In other words, it allows authentication at the application level, regardless of the application to which it serves with this method. The use of this authentication is, therefore, more flexible, allowing periodic or arbitrary re-authentications to be carried out after a certain time and triggered by the beacon.
ES 2 303 464 A1
Brief description of the drawings
A series of drawings that help to better understand the invention and that expressly relate to an embodiment of said invention that is presented as an illustrative but not limiting example of this invention will now be described very briefly.
Figure 1 shows a diagram of the system with the method object of the present invention implemented.
Description of a preferred embodiment of the invention
As can be seen in the attached figures, the system where the identification, authentication and coverage control method is implemented comprises:
- A central entity: Sends the user credentials both to the terminals [1] and to the beacons [2].
- A network of beacons [2]: Each one provides coverage [3] to a specific area and stores the credentials of all the terminals [1] associated with that beacon [2].
- A set of terminals [1]: The terminals [1] are Bluetooth® devices [4] attached to the system, each one with a credential for each beacon [2] in which it is authorized.
For terminals [1] a profile is defined that includes two services, with a unique and equal service identifier for all devices [4]. These services are:
- The authentication service [5]: It is used as a means of exchanging user credentials.
- The coverage control service [6]: It is used to monitor coverage losses immediately.
When the Bluetooth device<sup>®</sup> [4] is detected by the beacon [2], an attempt is made to connect to the coverage service of the device [4], using the unique service identifier service defined by this service. Two things can happen:
- Connection: Then it will make sure that it is really the coverage control service and not one with the same identifier. Two messages are exchanged, one of service available from beacon [2] to terminal [1] and one of response from terminal [1] to beacon [2]. With this we will know if the Bluetooth® device [4] is a terminal [1] of the system itself. In the event that it is, we are connected to your coverage control service [6].
- No connection: The Bluetooth® device [4] is not a terminal [1] belonging to the system.
The coverage control service [6] is a warning service. In this service [6] no more data is exchanged after the identification of the terminal [1], however, both beacon [2] and terminal [1] must monitor the status of the Bluetooth® synchronism channel, since at the time when terminal [1] goes out of coverage [3], this channel will go down, like the service, generating an "connection error" event that both devices [1] and [2] will be able to capture, knowing this so coverage [3] has been lost.
After determining that the Bluetooth® device [4] is indeed a terminal [1], and ensuring its coverage control, the method that is the object of the present invention describes the next stage, which is the process of checking the assignment of the terminal [1] to the beacon [2]. To do this, first, the beacon [2] launches the authentication process, that is, it connects to the authentication service [5] of the terminal [1]. In this process, four messages are exchanged:
Message 1: Beacon [2] sends terminal [1] its beacon identifier [2], and asks it to send its user credentials.
Message 2: The terminal [1] collects the identifier of the beacon [2] and searches for the credential associated with that identifier. Once it finds it, it sends it back to the beacon [2] for it to check.
Message 3: The beacon [2] checks the credential against its user database and sends a message back to the terminal [1], informing it of the result of said check (OK or KO).
Message 4: Terminal [1] finally knows if it is at its beacon [2] and returns an ACK (acknowledgment) to beacon [2].
Contents6
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| ES2686904A1 | Cited by | Spain | – | Search report |
| WO0201804A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report |
| EP1370050A1 | Cites | European Patent Office (EPO) | A | Search report |
| US2002194500A1 | Cites | United States of America | A | Search report |
| US2003197488A1 | Cites | United States of America | A | Search report |
| US2005180425A1 | Cites | United States of America | A | Search report |
| US2006029015A1 | Cites | United States of America | A | Search report |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200700160 | Spain | A | |
| ES20070000160 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| WO2008087241A1 | World Intellectual Property Organization (WIPO) | A1 | |
| ES2303464A1This record | Spain | A1 | |
| ES2303464B1 | Spain | B1 | |
| EP2131599A1 | European Patent Office (EPO) | A1 | |
| US2010210242A1 | United States of America | A1 | |
| US8229358B2 | United States of America | B2 | |
| EP2131599A4 | European Patent Office (EPO) | A4 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Search report publishedEC2A | EC2A |
Numbers
- Publication
- 2303464
- Publication, DOCDB
- 2303464
- Publication, EPODOC
- ES2303464
- Application
- 160
- Application, DOCDB
- 200700160
- Application, EPODOC
- ES20070000160
Titles2
- Spanish
- METODO DE IDENTIFICACION, AUTENTIFICACION Y CONTROL DE COBERTURA BASADO EN EL ESTANDAR BLUETOOTH
- English
- METHOD OF IDENTIFICATION, AUTHENTICATION AND CONTROL OF COVERAGE BASED ON THE BLUETOOTH STANDARD
Classification
- CPC, 6
- H04W12/06
- H04W76/10
- H04L63/08
- H04W84/18
- H04W8/005
- H04W48/00
- IPC, 2
- H04W12 06
- H04W84 18