Authentication in a radiotelephone network
Abstract
Authentication procedure between a first entity (MS) and a second entity (VLR, HLR, AUC) in a telecommunication network (RR), which comprises steps: - of application (E9, E9 '') of the first keys (Ki) stored respectively in the first and second entity and a random number (NA) produced by the second entity and transmitted by the second entity to the first entity respectively to first identical algorithms (AA) memorized in the first and second entity, and - compare (E10) in the second entity (VLR, HLR, AUC) a response (SRES) produced by the first algorithm memorized in the first entity and transmitted to the second entity and a response result (RSRES) produced by the first algorithm memorized in the second entity; This procedure also includes the previous steps: - to apply (E2, ES) second keys (Kj) stored respectively in the first and second entity and the random number (NA) respectively produced by the second entity and transmitted by the second entity to the first entity to second algorithms (AJ) memorized in the second entity (VLR, HLR, AUC) and the first entity (MSD), and - compare in the first entity (MS) a signature (SG) produced by the second algorithm in the second entity and transmitted with the random number (NA) to the first entity and a signature result (RSG) produced by the second algorithm in the first entity, the first key (Ki) and the random number (NA) only apply to the first algorithm (AA) in the first entity (MS) when the transmitted signature (SG) and the signature result (RSG) are identical, This procedure is characterized in that it also includes the steps: - to increase (E71) a variable (m) and disconnect (E72) the entities each time the transmitted signature (SG) and the result of signature (RSG) are different in the first entity (MS) and as long as the variable is lower to a predetermined number (M) of programmable preference, and - and refuse (E73) to establish any access to the second entity (VLR, HLR, AUC) by the first entity as long as the variable (m) is at least equal to a number default (M).

Term
Term ended
Projected expiry passed 15 February 2020, 6.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
12 claims: 5 independent, 7 dependent
- 1ES 2 344 098 T3 ES 2 344 098 T3 CLAIMS REIVINDICACIONES 1. Authentication procedure between a first entity (MS) and a second entity (VLR, HLR, AUC) in a telecommunication network (RR), comprising steps:1. Procedimiento de autentificación entre una primera entidad (MS) y una segunda entidad (VLR, HLR, AUC) en una red de telecomunicación (RR), que comprende etapas: - de aplicación (E9, E9') de las primeras claves (Ki) memorizadas respectivamente en la primera y segunda entidad y un número aleatorio (NA) producido por la segunda entidad y transmitido por la segunda entidad a la primera entidad respectivamente a primeros algoritmos idénticos (AA) memorizados en la primera y segunda entidad, y - of application (E9, E9 ') of the first keys (Ki) memorized respectively in the first and second entities and a random number (NA) produced by the second entity and transmitted by the second entity to the first entity respectively to the first algorithms identical (AA) memorized in the first and second entities, and - comparar (E10) en la segunda entidad (VLR, HLR, AUC) una respuesta (SRES) producida por el primer algoritmo memorizado en la primera entidad y transmitido a la segunda entidad y un resultado de respuesta (RSRES) producido por el primer algoritmo memorizado en la segunda entidad;- compare (E10) in the second entity (VLR, HLR, AUC) a response (SRES) produced by the first algorithm stored in the first entity and transmitted to the second entity and a response result (RSRES) produced by the first algorithm memorized in the second entity;Said procedure also includes the previous stages: dicho procedimiento comprende, además, las etapas previas: - de aplicar (E2, ES) segundas claves (Kj) memorizadas respectivamente en la primera y segunda entidad y el número aleatorio (NA) respectivamente producido por la segunda entidad y transmitido por la segunda entidad a la primera entidad a segundos algoritmos (AJ) memorizados en la segunda entidad (VLR, HLR, AUC) y la primera entidad (MSD), y - to apply (E2, ES) second keys (Kj) memorized respectively in the first and second entity and the random number (NA) respectively produced by the second entity and transmitted by the second entity to the first entity to second algorithms (AJ) memorized in the second entity (VLR, HLR, AUC) and the first entity (MSD), and - comparar en la primera entidad (MS) una firma (SG) producida por el segundo algoritmo en la segunda entidad y transmitida con el número aleatorio (NA) a la primera entidad y un resultado de firma (RSG) producida por el segundo algoritmo en la primera entidad, la primera clave (Ki) y el número aleatorio (NA) sólo se aplican al primer algoritmo (AA) en la primera entidad (MS) cuando la firma transmitida (SG) y el resultado de firma (RSG) son idénticos, dicho procedimiento se caracteriza porque comprende, además, las etapas: - compare in the first entity (MS) a signature (SG) produced by the second algorithm in the second entity and transmitted with the random number (NA) to the first entity and a signature result (RSG) produced by the second algorithm in the first entity, the first key (Ki) and the random number (NA) only apply to the first algorithm (AA) in the first entity (MS) when the transmitted signature (SG) and the signature result (RSG) are identical , said procedure is characterized in that it also comprises the stages: - de incrementar (E71) una variable (m) y desconectar (E72) las entidades cada vez que la firma transmitida (SG) y el resultado de firma (RSG) sean diferentes en la primera entidad (MS) y mientras la variable sea inferior a un número predeterminado (M) de preferencia programable, y - to increase (E71) a variable (m) and disconnect (E72) the entities each time the transmitted signature (SG) and the signature result (RSG) are different in the first entity (MS) and while the variable is lower to a predetermined number (M) of programmable preference, and - and refuse (E73) to establish any access to the second entity (VLR, HLR, AUC) by the first entity as long as the variable (m) is at least equal to a predetermined number (M). - y rechazar (E73) establecer cualquier acceso a la segunda entidad (VLR, HLR, AUC) por la primera entidad en cuanto la variable (m) es al menos igual a un número predeterminado (M).
- 5Method according to any of claims 1 to 4, in which the random number (NA) and the signature (SG) have respectively Q bits and (PQ) bits, P is a constant integer and Q is less than or equal to P / 2 . 5. Procedimiento según cualquiera de las reivindicaciones 1 a 4, en el que el número aleatorio (NA) y la firma (SG) tienen respectivamente Q bits y (P-Q) bits, P es un entero constante y Q es inferior o igual a P/2.
- 9Method according to any of claims 6 to 8, comprising a step of not determining (E13) an encryption key (Kc) based on the random number (NA), the signature (SG) and at least one of the first and second keys (Ki, Kj) in the terminal (MS) than when the response (SRES) and the response result (RSRES) compared are identical. 9. Procedimiento según cualquiera de las reivindicaciones 6 a 8, que comprende una etapa de no determinar (E13) una clave de cifrado (Kc) en función del número aleatorio (NA), de la firma (SG) y de al menos una de las primeras y segundas claves (Ki, Kj) en el terminal (MS) que cuando la respuesta (SRES) y el resultado de respuesta (RSRES) comparados son idénticos. ES 2 344 098 T3 ES 2 344 098 T3
- 11Procedimiento según cualquiera de las reivindicaciones 1 a 10, en el que la primera clave en la primera entidad (MS) es una primera clave secreta (Kis), y la primera clave en la segunda entidad (VLR, HLR, AUC) es una clave pública (Ki) diferente de la segunda clave secreta. eleven. Method according to any of claims 1 to 10, in which the first key in the first entity (MS) is a first secret key (Kis), and the first key in the second entity (VLR, HLR, AUC) is a key public (Ki) different from the second secret key.
- 12Identity module (SIM) in a first entity (MS) comprising means (RON, EEPROM) to memorize at least the second algorithm (AJ) and at least the second key (Kj), means (ROM, EEPROM, RAM) for execute at least the steps of applying (E5) to the second algorithm (AA) and comparing (E6) the signature (SG) and the signature result (RSG) characterized in that it also comprises a counter means and means to reject (E73) set any access to the second entity (VLR, HLR, AUC) by the first entity insofar as the value (m) of said counter means is at least equal to a predetermined number (M) in accordance with any of claims 1 to 11. 12. Módulo de identidad (SIM) en una primera entidad (MS) que comprende medios (RON, EEPROM) para memorizar al menos el segundo algoritmo (AJ) y al menos la segunda clave (Kj), medios (ROM, EEPROM, RAM) para ejecutar al menos las etapas de aplicar (E5)al segundo algoritmo (AA) y comparar (E6) la firma (SG) y el resultado de firma (RSG) caracterizado porque comprende, además, un medio contador y medios para rechazar (E73) establecer cualquier acceso a la segunda entidad (VLR, HLR, AUC) por la primera entidad en cuanto el valor (m) de dicho medio contador es al menos igual a un número predeterminado (M) en conformidad con cualquiera de las reivindicaciones 1 a 11.
Independent claims5
66 paragraphs in 5 sections, as filed
ES 2 344 098 T3
DESCRIPTION
Authentication in a mobile radio network.
The present invention concerns an authentication method between a mobile radiotelephone terminal and a routing subsystem, often called a fixed network, in a digital cellular radiotelephone network. More particularly, the invention improves authentication through the radio interface between a microprocessor card or module, said SIM card (Subscriber Identify Module), removable from the terminal, and an authentication center of the radiotelephony network.
A GSM-type RR digital cellular radiotelephony network, which will be referred to in the rest of the document by way of example, mainly comprises several mobile radiotelephone terminals MS and a fixed network itself through which signaling messages circulate, mainly control, data and voice as shown schematically in figure 1.
In the network RR shown in figure 1, in particular, main entities through which data destined for the SIM card of a mobile terminal MS located in a location area at a given time pass. These entities are a switch of the mobile service MSC linked to at least one telephone switch with routing autonomy CAA of the PSTN switched telephone network and that governs communications for visiting mobile terminals, including the terminal MS, which are at any given time. in the respective location area communicated by the switch MSC. A visitor location recorder VLR is connected to the switch MSC and contains characteristics, such as identity and subscription profile of the mobile terminals, in fact SIM cards in said terminals, located in the location area. A base station controller BSC connected to the switch MSC governs, in particular, the allocation of channels to mobile terminals, the power of the base station (s) and intercell handoffs of mobile terminals. A base station BTS connected to the controller BSC covers the radio cell where the terminal MS is located at a given time.
The radiotelephony network RR further comprises a nominal location recorder HLR which cooperates with an authentication center AUC and which is connected to the mobile service switches via the signaling network of the radiotelephony network RR.
The HLR recorder is essentially a database, like a VLR recorder, which contains for each terminal MS the international identity IMSI (International Mobile Subscriber Identity) of the terminal's SIM card, that is to say of the subscriber holding the SIM card, the number directory and subscription profile of the subscriber, and the number of the VLR register to which the mobile terminal is linked and updated at the time of transfers between location zones.
The authentication center AUC ensures the authentication of the subscribers and participates in the confidentiality of the data that transits the radio interface IR between the terminal MS and the base station BTS to which it is linked at the given moment. There is an authentication algorithm A3 and an algorithm A8 for determining the encryption key, sometimes merged into a single algorithm A38, according to the GSM standard, which are redundant in the SIM card of the mobile terminal MS, prior to any communication with the terminal , either during terminal commissioning or during intercellular handover. In particular, the authentication center AUC memorizes an authentication key Ki assigned only to the subscriber in correspondence with the IMSI identity of the subscription stored in the nominal location register HLR at the time of subscription subscription by the subscriber.
It is very important to authenticate the mobile radiotelephone terminal MS in order, among other things, to be able to recognize the subscriber. In order to ensure maximum flexibility, the authentication center does not authenticate the mobile terminal MS itself but the SIM chip card it contains. This card contains the key Ki assigned to the subscriber and demonstrates by means of the authentication algorithm A3 that it knows the key without revealing it. The fixed network sends a random number RAND (challenge) to the card and asks the card to enter the random number and the key in the authentication algorithm for a cryptographic calculation and to resend the result in the form of a signed response SRES ( Signed RESponse) for the GSM standard. It is very difficult for an "attacker", a malicious third person who wishes to establish radiotelephone communications charged to the account of the owner of the SIM card, to predict the value of the random number. If the key is not known, the attacker cannot provide an answer. The size of the random number prevents the attacker from memorizing all the values of the random number-signed response pair in a dictionary. The authentication procedure in the authenticated radiotelephone network, as well as the SIM card containing a key.
The authentication procedure briefly comprises the following steps:
- previously, the authentication center AUC chooses several random numbers RAND and determines on the one hand several signature responses respectively as a function of the chosen numbers RAND and the key Ki assigned to the subscriber applied to the authentication algorithm A3, and on the other hand, several encryption keys respectively based on the chosen numbers RAND and the key Ki applied to the key determination algorithm A8, in order to provide triplets (random number, signature response, encryption key) to the location recorder HLR, as soon as the mobile radio service subscription is subscribed, then each time the recorder HLR has exhausted its reserve of triplets, in correspondence with the IMSI identity of the subscriber's SIM card;
ES 2 344 098 T3
- each time the VLR visitor location recorder to which the SIM card is momentarily linked requests a card authentication, the HLR recorder chooses and provides at least one triplet to the VLR recorder in order to transmit the random number of the triplet chosen to the SIM card through the fixed network and the mobile terminal MS;
- the SIM card performs a cryptographic calculation by applying the transmitted random number and the key Ki to the authentication algorithm A3 that produces the signed response SRES and returns it to the VLR register;
- the VLR register compares the signed response SRES with that obtained in the chosen triplet, and in case of equal responses, the card is authenticated.
If this authentication procedure allows the fixed network to authenticate the card, it does not allow the SIM card to authenticate the fixed network instead. No authentication is provided.
To this drawback is added another which consists of being able to choose any number that is sent to the SIM card in an unlimited number.
These two drawbacks make the SIM card vulnerable to attacks by auxiliary channels, such as attacks in current or by logical means, for example that relieve cryptanalysis.
In the field of cryptography, document EP-A-0-506-637 is mainly known about various types of attacks that recover the value of a key that is used for a cryptographic calculation.
The first and simplest of the attacks consists of recovering a random number and the result of the authentication algorithm carried out with this number and entering all the possible keys and the random number in the algorithm until obtaining the recovered result. In the case of authentication on a GSM network, this attack, called brute force, requires 2<sup>127</sup>, that is to say, a number composed of 1 followed by 38 zeros, encrypted on average to obtain the key. Despite the fact that this attack does not use the card, the calculations can be done on a microcomputer, the time it would take would be too long: with a calculating machine that performs 10,000 calculations per second, this attack would take 5.10<sup>26</sup> years.
Attacks of a second type use flaws in the conception of a cryptographic algorithm. For these attacks, it is often necessary to enter chosen messages into the algorithm and analyze the responses. This type of attack has been transferred to an algorithm, called COMP128, used in Authentication algorithm quality and A3A8 encryption key determination according to the GSM standard. On average, you need to pick 160,000 random numbers and retrieve the corresponding results. In the current GSM context, this attack can be carried out, since it is enough to recover a SIM card that will carry out the cryptographic calculation on any random number, and this as many times as the attacker wants.
Finally, a third type of attack uses “side channels”. These channels carry information about the secret data and are generally physical quantities of the implementation of the cryptographic function. A typical example of an auxiliary channel is the power consumption of the chip card. An attack that uses this channel is DPA (Differential Power Analysis) analysis and currently requires several thousand cryptographic algorithm execution with random numbers that are known but do not need to be chosen. This attack is completely feasible as soon as an attacker is in possession of a SIM card.
The invention aims to remedy the drawbacks of the aforementioned authentication procedure and, in particular, to make the last two attacks much more difficult, without modifying the material of the radiotelephony network and with some software modifications essentially related to the authentication.
To this end, an authentication procedure between a first entity and a second entity in a telecommunication network, comprising steps of applying the first keys stored respectively in the first and second entities and a random number produced by the second entity and transmitted by the second entity to the first entity respectively to first identical algorithms memorized in the first and second entity, and comparing in the second entity a response produced by the first algorithm stored in the first entity and transmitted to the second entity and a response result produced by the first algorithm stored in the second entity, It is characterized by the previous stages of application of the second keys memorized respectively in the first and second entities and the random number respectively produced by the second entity and transmitted by the second entity to the first entity to second algorithms memorized in the second entity and the first entity, and comparing in the first entity a signature produced by the second algorithm in the second entity and transmitted with the random number to the first entity and a signature result produced by the second algorithm to the first entity, the first key and the random number only they are applied to the first algorithm in the first entity when the transmitted signature and the result are identical.
According to a preferred embodiment, the first and second entities are respectively a radiotelephone terminal and a fixed network in a radiotelephony network. The stages of applying the second algorithms and comparing the signature and the signature result constitutes an authentication of the fixed network by the terminal prior to the authentication of the terminal by the fixed network, which comprises the stages of applying the first algorithm and comparing the response and the
ES 2 344 098 T3 response result. Thus, the method of the invention adds an authentication and combines it to the authentication of the terminal, only authorizing its execution when the fixed network has been authenticated by the terminal, which allows the terminal to be much less vulnerable to the last two types of attack mentioned. previously.
The random number is used to first authenticate the network, and not the terminal, at the terminal. The random number is then used to authenticate the terminal over the network. For this second authentication, it is preferable that the signature is applied with the random number produced in the first algorithm of the second entity, and the transmitted signature with the random number is applied to the first algorithm of the first entity. The random number and the signature can have respectively Q bits and (PQ) bits, P is a constant integer.
The invention makes the attacks described above very difficult, and is even virtually impossible. The attacker must spy on the activated SIM card on the network to retrieve valid random numbers, and collect a sufficient number of random numbers in order to launch an attack.
This is far from easy: the attacker cannot control the frequency of authentications in the radio network. Knowing that the authentication number of the SIM card in the GSM network is variable and depends on the networks, this can take a negligible time.
A first advantage of the invention consists in the succession of the two authentications that does not allow validating a random number to be retrieved for a card before it is activated and recognized by the network. This prevents attacks at points of sale where in the current situation, a seller can attack the cards that are in their stock and make clones before using them when the card is activated, that is, sold.
The invention makes most cryptanalysis attacks impossible and, in particular, those chosen from random numbers. Indeed, for the card to carry out a cryptographic calculation, only certified random numbers can be used, which probably do not have the format that the attacker needs.
The invention makes it very difficult to carry out attacks using auxiliary channels, since it takes a lot of hardware and a lot of time to retrieve valid random numbers. The cost of the attack, both in price and in time, makes it much less profitable and this leads to the discouragement of many pirates.
The invention thus significantly improves the security of authentication in radiotelephony networks. It does not imply a modification of the software of the SIM cards, the first entities, and nominal registrars and authentication centers, included in the second entities, without having any impact on the network infrastructure. These modifications can be made gradually without disrupting the fixed network.
The procedure may comprise steps of incrementing a variable and disconnecting the entities each time the transmitted signature and the signature result are different in the first entity, such as the terminal, and as long as the variable is less than a predetermined number of programmable preference , and refuse to establish any access to the second entity, such as the fixed medium, by the first entity as long as the variable is at least equal to a predetermined number. The step of refusing to establish any access can be concomitant to authorize a use of the first entity only internally or to prohibit any use of the first entity.
Particularly within the framework of a radiotelephony network, a means of authentication and registration of terminal identity in the fixed network determines several triplets each comprising a random number and a signature, as well as a response result corresponding to the number random, before the step of applying the second keys in the terminal. Before the authentications, that is, before the stages of applying, an encryption key is determined based on the random number, the signature and at least one of the first and second keys in the fixed network, which includes the authentication center. As a result of the authentications, a step of determining an encryption key only based on the random number, the signature and at least one of the first and second keys in the terminal is envisaged only when the response and the response result compared they are identical.
According to other variants, the security of the data exchanged between the first and second entities is further increased, the second key in the second entity is a second secret key, and the second key in the first entity is a different public key from the second key secret. Similarly, the first key in the first entity is a first secret key, and the first key in the second entity is a different public key from the first secret key.
The invention also concerns an identity module, such as a subscriber identity card, in a first entity, such as a mobile radio terminal, characterized in that it comprises means for storing at least the second algorithm and at least the second key, and means for executing at least the steps of applying to the second algorithm and comparing the signature and the signature result in accordance with the invention.
Other features and advantages of the invention will appear more clearly when the following description of various preferred embodiments of the invention is read with reference to the corresponding annexed drawings in which:
- Figure 1 is a block-schematic diagram of a digital cellular radiotelephony network; Y
ES 2 344 098 T3
figure 2 shows steps of an authentication procedure according to the invention.
The method of the invention is described below within the framework of the GSM-type RR radiotelephony network, already present with reference to Figure 1, which only undergoes modifications and software additions essentially in the AUC authentication center, as well as in SIM cards of mobile terminals.
In the following description, a fixed network is considered as the chain of entities linked to the mobile radiotelephone terminal considered MS from the radio interface IR, comprising the base station BTS, the station controller BTS, the switch MSC with the location recorder of the VLR visitors, and the HLR-AUC pair.
It is recalled that a mobile radiotelephone terminal MS of a subscriber comprises a removable microprocessor module, said card with a SIM chip linked to a bus of the digital circuit, with a microprocessor in the terminal, the bus communicates the keyboard, the screen and peripheral sockets of the mobile terminal. As shown in figure 1, the SIM chip card mainly contains a microprocessor, a ROM memory that includes the card operating system and specific application algorithms, a non-volatile memory EEPROM that contains all the characteristics linked to the subscriber, such as the IMSI identity, the subscription profile, the list of numbers of people called with their names, security data, such as password and confidential code, etc., and a RAM memory used to process the data to be received and transmitted to the digital circuit of the terminal. In particular, the algorithms for authentication and determination of the encryption key and the keys and other parameters linked to these algorithms are governed and written in the ROM and EEPROM memories.
With reference to Figure 2, the authentication procedure according to the invention follows a communication of the SIM card of the radiotelephone terminal MS with the subnetwork BTS, BSC, MSC and VLR included in the radiotelephony network RR and temporarily linked to the terminal radiotelephone MS, and precedes an encryption key determination.
The process shown in Figure 2 essentially comprises steps from E0 to E14. In figure 2, the blocks in dotted lines are relative to stages E0, E2, E9 ', E90, E20, E11 and E110, which are essentially carried out in the fixed network, independently of any authentication request, and at least prior to the request for authentication considered in step E3 according to the illustrated embodiment.
Initially, in a step E0, it is considered that the mobile terminal has memorized in the ROM and EEPROM memories of its SIM card, its IMSI identity, that is, the identity of the subscriber holding the SIM card, if necessary, the temporary identity TMSI of the card allocated by the link switch MSC, a first authentication key Ki with a first authentication algorithm AA to authenticate the terminal by the network, an encryption key determination algorithm AC, an encryption / decryption algorithm, and according to the invention a second key Kj with a second authentication algorithm AJ to authenticate the network by the SIM card, as well as an integer variable m initially equal to 0 and a higher integer terminal M of it. These initial data, with the exception of the integers m and M, and algorithms are also stored in the initial stage E0 in the fixed network. The keys Ki and Kj for each subscriber are memorized in the authentication center AUC in correspondence with the subscriber identity IMSI, the temporary identity is only attributed by the visitor location register VLR linked to the mobile service switch MSC to which it is linked the mobile terminal MS. The two authentication algorithms AA and AJU and the encryption key determination algorithm AC are stored in the authentication center AUC, and the encryption / decryption algorithm is installed in the base station BTS. As we can see below, the AUC authentication center provides triplets [(NA, SG), RSRES, Kc] to the nominal location register HLR.
During a request for access to the mobile service by the terminal, eg. ex. after the start-up of the mobile terminal MS, or for an update of the location of the terminal, or prior to a telephone communication, or periodically to authenticate the SIM card at the request of the VLR recorder, the terminal MS exchanges signals with the attachment subnetwork so as to dedicate a communication channel to the terminal MS and to declare the terminal identity to the subnetwork by the terminal MS by transmitting the IMSI identity of the terminal's SIM card to the location register of the devices. VLR visitors, or where appropriate the TMSI temporary identity with the identity of the LAI location area relative to the last communication established. These exchanges to dedicate a channel to the terminal MS are illustrated in a simplified way by step E1 in Figure 2.
The following steps E2 to E8 deal with the authentication of the network by the SIM card which is added by the invention and which is implemented essentially partly in the AUC authentication center and the HLR and VLR registers and partly in the ROM and EEPROM memories. SIM card.
Previously, at the AUC center, a pseudo-random generator supplied several Q-bit random numbers NA. The key Kj different from the key Ki and stored in the center AUC and each random number NA of Q bits are applied to the input of the network authentication algorithm AJ in the center AUC in step E2. As a variant, the keys Kj and Ki can be identical. The algorithm AJ is p. ex. of type DES (Data Encryption Standard) and produces signatures of random number SG to (PQ) bits. The random numbers NA and the corresponding signatures SG are written to the HLR registrar in association with the IMSI identity of the SIM card, and at least one pair (NA, SG) chosen by the HLR registrar is transmitted to the VLR registrar to which it is linked the terminal in step E20.
ES 2 344 098 T3
When the visitor location recorder VLR decides to proceed with the authentication of the fixed network by the SIM card according to the invention, the chosen pair (MA, SG) is successively entered into authentication request messages in step E3 transmitted respectively by the switch MSC, the controller BSC and finally the base station BTS towards the mobile terminal MS via the radio interface IR. The integer P, with P> Q, is chosen so as not to modify the length of the authentication messages according to the standard in force in the Radiotelephony network RR, in this case, the length of the messages containing a RAND number. The integer P is typically equal to 128, be a pair size (NA, SG) equal to 16 octets. The integer Q denoting the number of bits in the random number NA can be greater or less than P / 2; however, the integers P and Q can satisfy the equality P / 2 = Q.
In the SIM card of the mobile terminal MS, the random number NA and the signature SG are written in the RAM of the SIM card in step E4 in response to the authentication request messages transmitted by the attachment base station BTS. Immediately, in the next stage E5, the random number NA and the key Kj are applied to the algorithm AJ contained in the ROM and EEPROM memories of the SIM card, in a manner analogous to the development of the algorithm AJ in stage E2 in the center of AUC authentication. The RSG result produced by the algorithm AJ is compared with the signature SG transmitted by the authentication center AUC and is read in step E6.
If in step E6, RSG is different from SG, the variable m is compared to the predetermined integer M, typically equal to about 10, in step E7. While m <M, the variable m is incremented by one unit in a counter and the SIM card does not carry out the next step E9 of production of the SRES signature response every time that SG is different from RSG as a result of an authentication request message , and consequently the dedicated signaling channel is released so that the access requested to the mobile service by the terminal is not established when releasing the radio resources, as indicated in steps E71 and E72. The counter is contained in the SIM card, and the integer M is programmable so that the operator providing the SIM card can select the integer M.
When the variable m reaches the upper terminal M in step E7, access to the mobile service is not established naturally as before, but also any new authentication is systematically rejected, as indicated in step E73. This means that the SIM card is probably in the course of "attack" by a malicious third party for fraudulent use of the subscriber's account assigned by the network to the SIM card. In this case, the invention recommends two variants.
According to a first variant, the SIM card authorizes the subscriber to use the radiotelephone terminal MS only for local controls internal to the terminal. For example, local controls are used to consult the directory of call numbers via the keyboard or the voice recognition means of the terminal, without authorizing the establishment of any type of telephone communication.
According to a second variant, the SIM card blocks any action of the subscriber by means of the keyboard, and / or the voice recognition means, and puts the terminal out of service, that is, the SIM card becomes "mute"; the SIM card no longer accepts any command and the MS terminal is unusable.
If we go back to step E6, when the RSG result equals the signature SG, the received random number NA and signature SG and the authentication key Ki are read in step E8 in order to apply them to the known authentication algorithm AA in step E9. At this level, authentication proceeds in much the same way as a known SIM card. The AA algorithm provides a signed response SRES (Signed RESponse) which is included in a message transmitted to the attachment base station BTS, which relays it to the VLR register by the base station BTS, the BCS controller and the switch MSC.
Previously, before the authentication request E3 and therefore before carrying out steps E3 to E9 on the SIM card, the VLR and HLR registrars have memorized for the subscriber the NA number and the SG signature, and the authentication center AUC has applied, after step E20, and for each of said random numbers NA, the random number NA, the corresponding signature SG and the first key Ki to the algorithm AA of a step E9 '. The AA algorithm produces a signed response result rSreS for each pair (NA, SG). Concomitantly with step E20, the results RSRES are written to the one-step register HLR E90 and the pair (NA, SG) chosen by the register is transmitted with the corresponding result RSRES to the register VLR which has memorized them.
As soon as the signed response SRES transmitted by the mobile terminal MS after step E9 is received, the register VLR reads the result of signed response RSRES from step E91 and compares it with the received SRES from step E10. If these two variables are not identical, the VLR register orders the attach switch MSC to disconnect the terminal and the fixed network in step E101, preventing the latter from continuing its request for access to the mobile service.
Otherwise, the authentication center AUC validates the authentication of the SIM card in step E10, which has succeeded the authentication (step E5) of the network RR by the SIM card according to the invention, to authorize the encryption and decryption of the messages subsequently exchanged between the mobile terminal MS and the BTS-BSC-MSC subnetwork.
Previously, the authentication center AUC has applied the pairs (NA, SG) that correspond to said several random numbers NC and the key of the algorithm for determining the encryption key Al of a step E11 in order to produce encryption keys Kc, which are memorized in the VLR register of a stage E110 concomitant to the
ES 2 344 098 T3 stages E20 and E90. Thus, several triplets [(NA, SG), RSRES, Kc] are previously stored in the nominal location register HRL, and at least one of them chosen is written in the VLR register in association with the IMSI / TMSI identity of the SIM card.
After step E10, the switch MSC decides to go into encryption mode by transmitting an encryption authorization message with the key Kc, relieved by the entities BSC and BTS, towards the mobile terminal MS, the key Kc is extracted from the station of base BTS.
On the other hand, following the execution of the authentication step E9, the SIM card reads in step E12 the random number nA and SG and also the authentication key Ki in order to apply them to the encryption algorithm AC to determine a key encryption Kc in step E13.
Finally, in steps E14 and E14 ', the terminal MS and the attachment subnetwork, particularly the attachment base station BTS, which contains an identical encryption and decryption algorithm for that content on the SIM card and which has memorized the determined key Kc , they can exchange encrypted and decrypted messages with the Kc key.
As variants, the second keys Kj, or the first and second keys Ki and Kj are read and applied respectively to the algorithms AC, instead of the first keys Ki in steps E13 and E11.
According to other variants, the key Kj attributed to the SIM card in the AUC authentication center is a secret private key Kjs, and the key Kj contained in the SIM card is a public key different from the key Kj and which has a complex link with the secret key Kjs. The network authentication algorithm AJ is asymmetric and makes it possible to verify the signature SG by comparison with the RSG result of step E6, despite the fact that the SIM card, and therefore any malicious person, does not know the secret key Kjs.
Similarly, the key Ki in the SIM card is replaced by a secret key Kis, and the key Ki in the authentication center AUC is a public key, the card authentication algorithm AS is then asymmetric.
Although the invention has been described according to preferred embodiments with reference to a radiotelephony network between a mobile radiotelephone terminal and the fixed network of the radiotelephony network, the authentication method of the invention can be applied to a telecommunication network of relatively any two entities , each needing to authenticate the other, each entity can be a set of linked predetermined entities.
Contents5
2 sheets
Sheet 1 Sheet 2
16 members in 11 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 9902276 | France | A | |
| 9902276 | France | A | |
| 990227600905142 | – | – | – |
| FR19990002276 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| FR2790177A1 | France | A1 | |
| WO0051386A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2677600A | Australia | A | |
| FR2790177B1 | France | B1 | |
| EP1157575A1 | European Patent Office (EPO) | A1 | |
| BR0008436A | Brazil | A | |
| CN1341338A | China | A | |
| JP2004500736A | Japan | A | |
| CN1205833C | China | C | |
| EP1157575B1 | European Patent Office (EPO) | B1 | |
| AT464757T | Austria | T | |
| ATE464757T1 | Austria | T1 | |
| DE60044185D1 | Germany | D1 | |
| ES2344098T3This record | Spain | T3 | |
| JP4636423B2 | Japan | B2 | |
| US8280053B1 | United States of America | B1 |
Numbers
- Publication, DOCDB
- 2344098
- Publication, EPODOC
- ES2344098T
- Application
- 905142
- Application, DOCDB
- 00905142
- Application, EPODOC
- ES20000905142T
Titles2
- English
- AUTHENTICATION IN A MOBILE RADIOTELEFONIA NETWORK.
- Spanish
- AUTENTIFICACION EN UNA RED DE RADIOTELEFONIA MOVIL.
Classification
- CPC, 4
- H04W12/06
- H04L9/3271
- H04L63/1466
- H04L2209/80
- IPC, 3
- H04W12 06
- G06F21 44
- H04L9 32