ES2344098T3

Authentication in a radiotelephone network

Abstract

Authentication procedure between a first entity (MS) and a second entity (VLR, HLR, AUC) in a telecommunication network (RR), which comprises steps: - of application (E9, E9 '') of the first keys (Ki) stored respectively in the first and second entity and a random number (NA) produced by the second entity and transmitted by the second entity to the first entity respectively to first identical algorithms (AA) memorized in the first and second entity, and - compare (E10) in the second entity (VLR, HLR, AUC) a response (SRES) produced by the first algorithm memorized in the first entity and transmitted to the second entity and a response result (RSRES) produced by the first algorithm memorized in the second entity; This procedure also includes the previous steps: - to apply (E2, ES) second keys (Kj) stored respectively in the first and second entity and the random number (NA) respectively produced by the second entity and transmitted by the second entity to the first entity to second algorithms (AJ) memorized in the second entity (VLR, HLR, AUC) and the first entity (MSD), and - compare in the first entity (MS) a signature (SG) produced by the second algorithm in the second entity and transmitted with the random number (NA) to the first entity and a signature result (RSG) produced by the second algorithm in the first entity, the first key (Ki) and the random number (NA) only apply to the first algorithm (AA) in the first entity (MS) when the transmitted signature (SG) and the signature result (RSG) are identical, This procedure is characterized in that it also includes the steps: - to increase (E71) a variable (m) and disconnect (E72) the entities each time the transmitted signature (SG) and the result of signature (RSG) are different in the first entity (MS) and as long as the variable is lower to a predetermined number (M) of programmable preference, and - and refuse (E73) to establish any access to the second entity (VLR, HLR, AUC) by the first entity as long as the variable (m) is at least equal to a number default (M).

ES2344098T3, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 15 February 2020, 6.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

12 claims: 5 independent, 7 dependent

  1. 1
    ES 2 344 098 T3 ES 2 344 098 T3 CLAIMS REIVINDICACIONES 1. Authentication procedure between a first entity (MS) and a second entity (VLR, HLR, AUC) in a telecommunication network (RR), comprising steps:1. Procedimiento de autentificación entre una primera entidad (MS) y una segunda entidad (VLR, HLR, AUC) en una red de telecomunicación (RR), que comprende etapas: - de aplicación (E9, E9') de las primeras claves (Ki) memorizadas respectivamente en la primera y segunda entidad y un número aleatorio (NA) producido por la segunda entidad y transmitido por la segunda entidad a la primera entidad respectivamente a primeros algoritmos idénticos (AA) memorizados en la primera y segunda entidad, y - of application (E9, E9 ') of the first keys (Ki) memorized respectively in the first and second entities and a random number (NA) produced by the second entity and transmitted by the second entity to the first entity respectively to the first algorithms identical (AA) memorized in the first and second entities, and - comparar (E10) en la segunda entidad (VLR, HLR, AUC) una respuesta (SRES) producida por el primer algoritmo memorizado en la primera entidad y transmitido a la segunda entidad y un resultado de respuesta (RSRES) producido por el primer algoritmo memorizado en la segunda entidad;- compare (E10) in the second entity (VLR, HLR, AUC) a response (SRES) produced by the first algorithm stored in the first entity and transmitted to the second entity and a response result (RSRES) produced by the first algorithm memorized in the second entity;Said procedure also includes the previous stages: dicho procedimiento comprende, además, las etapas previas: - de aplicar (E2, ES) segundas claves (Kj) memorizadas respectivamente en la primera y segunda entidad y el número aleatorio (NA) respectivamente producido por la segunda entidad y transmitido por la segunda entidad a la primera entidad a segundos algoritmos (AJ) memorizados en la segunda entidad (VLR, HLR, AUC) y la primera entidad (MSD), y - to apply (E2, ES) second keys (Kj) memorized respectively in the first and second entity and the random number (NA) respectively produced by the second entity and transmitted by the second entity to the first entity to second algorithms (AJ) memorized in the second entity (VLR, HLR, AUC) and the first entity (MSD), and - comparar en la primera entidad (MS) una firma (SG) producida por el segundo algoritmo en la segunda entidad y transmitida con el número aleatorio (NA) a la primera entidad y un resultado de firma (RSG) producida por el segundo algoritmo en la primera entidad, la primera clave (Ki) y el número aleatorio (NA) sólo se aplican al primer algoritmo (AA) en la primera entidad (MS) cuando la firma transmitida (SG) y el resultado de firma (RSG) son idénticos, dicho procedimiento se caracteriza porque comprende, además, las etapas: - compare in the first entity (MS) a signature (SG) produced by the second algorithm in the second entity and transmitted with the random number (NA) to the first entity and a signature result (RSG) produced by the second algorithm in the first entity, the first key (Ki) and the random number (NA) only apply to the first algorithm (AA) in the first entity (MS) when the transmitted signature (SG) and the signature result (RSG) are identical , said procedure is characterized in that it also comprises the stages: - de incrementar (E71) una variable (m) y desconectar (E72) las entidades cada vez que la firma transmitida (SG) y el resultado de firma (RSG) sean diferentes en la primera entidad (MS) y mientras la variable sea inferior a un número predeterminado (M) de preferencia programable, y - to increase (E71) a variable (m) and disconnect (E72) the entities each time the transmitted signature (SG) and the signature result (RSG) are different in the first entity (MS) and while the variable is lower to a predetermined number (M) of programmable preference, and - and refuse (E73) to establish any access to the second entity (VLR, HLR, AUC) by the first entity as long as the variable (m) is at least equal to a predetermined number (M). - y rechazar (E73) establecer cualquier acceso a la segunda entidad (VLR, HLR, AUC) por la primera entidad en cuanto la variable (m) es al menos igual a un número predeterminado (M).
  2. 5
    Method according to any of claims 1 to 4, in which the random number (NA) and the signature (SG) have respectively Q bits and (PQ) bits, P is a constant integer and Q is less than or equal to P / 2 . 5. Procedimiento según cualquiera de las reivindicaciones 1 a 4, en el que el número aleatorio (NA) y la firma (SG) tienen respectivamente Q bits y (P-Q) bits, P es un entero constante y Q es inferior o igual a P/2.
  3. 9
    Method according to any of claims 6 to 8, comprising a step of not determining (E13) an encryption key (Kc) based on the random number (NA), the signature (SG) and at least one of the first and second keys (Ki, Kj) in the terminal (MS) than when the response (SRES) and the response result (RSRES) compared are identical. 9. Procedimiento según cualquiera de las reivindicaciones 6 a 8, que comprende una etapa de no determinar (E13) una clave de cifrado (Kc) en función del número aleatorio (NA), de la firma (SG) y de al menos una de las primeras y segundas claves (Ki, Kj) en el terminal (MS) que cuando la respuesta (SRES) y el resultado de respuesta (RSRES) comparados son idénticos. ES 2 344 098 T3 ES 2 344 098 T3
  4. 11
    Procedimiento según cualquiera de las reivindicaciones 1 a 10, en el que la primera clave en la primera entidad (MS) es una primera clave secreta (Kis), y la primera clave en la segunda entidad (VLR, HLR, AUC) es una clave pública (Ki) diferente de la segunda clave secreta. eleven. Method according to any of claims 1 to 10, in which the first key in the first entity (MS) is a first secret key (Kis), and the first key in the second entity (VLR, HLR, AUC) is a key public (Ki) different from the second secret key.
  5. 12
    Identity module (SIM) in a first entity (MS) comprising means (RON, EEPROM) to memorize at least the second algorithm (AJ) and at least the second key (Kj), means (ROM, EEPROM, RAM) for execute at least the steps of applying (E5) to the second algorithm (AA) and comparing (E6) the signature (SG) and the signature result (RSG) characterized in that it also comprises a counter means and means to reject (E73) set any access to the second entity (VLR, HLR, AUC) by the first entity insofar as the value (m) of said counter means is at least equal to a predetermined number (M) in accordance with any of claims 1 to 11. 12. Módulo de identidad (SIM) en una primera entidad (MS) que comprende medios (RON, EEPROM) para memorizar al menos el segundo algoritmo (AJ) y al menos la segunda clave (Kj), medios (ROM, EEPROM, RAM) para ejecutar al menos las etapas de aplicar (E5)al segundo algoritmo (AA) y comparar (E6) la firma (SG) y el resultado de firma (RSG) caracterizado porque comprende, además, un medio contador y medios para rechazar (E73) establecer cualquier acceso a la segunda entidad (VLR, HLR, AUC) por la primera entidad en cuanto el valor (m) de dicho medio contador es al menos igual a un número predeterminado (M) en conformidad con cualquiera de las reivindicaciones 1 a 11.