Enhanced security design for cryptography in mobile communication systems
Abstract
Security enhancement method for a protected communication based on a key agreement procedure (S 1) in a mobile communication network serving a mobile terminal (100) having at least a basic cryptographic security algorithm , said method comprising the steps of: - selecting an improved version of a basic cryptographic security algorithm for the communication between the mobile terminal and the network side (S2); - modifying a basic security key resulting from the key agreement procedure based on information representative of the selected algorithm to generate an algorithm-specific security key (S3); - applying the basic cryptographic security algorithm with the algorithm-specific security key as a key input to enhance security for protected communication in said mobile communication network (S4).

Term
Term ended
Projected expiry passed 10 September 2024, 2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
36 claims: 4 independent, 32 dependent
- 15 10 15 20 25 30 35 40 45 REIVINDICACIONES 1. Método de mejora de la seguridad para una comunicación protegida basada en un procedimiento de acuerdo de clave (S1) en una red de comunicaciones de móviles que presta servicio a un terminal móvil (100) que tiene por lo menos un algoritmo de seguridad criptográfico básico, comprendiendo dicho método las etapas de:- seleccionar, en un lado de la red, una versión mejorada de un algoritmo de seguridad criptográfico básico para la comunicación entre el terminal móvil y el lado de la red (S2);-transmitir, desde el lado de la red, información representativa del algoritmo seleccionado al terminal móvil;- modificar una clave de seguridad básica resultante del procedimiento de acuerdo de clave en función de información representativa del algoritmo seleccionado para generar una clave de seguridad específica de algoritmo (S3);- aplicar el algoritmo de seguridad criptográfico básico con la clave de seguridad específica del algoritmo como entrada de clave para mejorar la seguridad para la comunicación protegida en dicha red de comunicaciones de móviles (S4).
- 2Método de la reivindicación 1, en el que dicha etapa de seleccionar una versión mejorada de un algoritmo de seguridad criptográfico básico se basa en un acuerdo entre dicho terminal móvil y dicha red.
- 3Método de la reivindicación 1, en el que dichas etapas de modificar una clave de seguridad básica y aplicar el algoritmo de seguridad criptográfico básico con la clave específica del algoritmo como entrada de clave se realizan tanto en el lado de la red como en el terminal móvil.
- 4Método de la reivindicación 1, en el que el algoritmo de seguridad básico junto con la modificación, específica del algoritmo, de dicha clave de seguridad básica se corresponden con la versión mejorada del algoritmo de seguridad.
- 5Método de la reivindicación 1, en el que dicho terminal móvil modifica la clave de seguridad básica resultante del procedimiento de acuerdo de clave en función de dicha información representativa del algoritmo seleccionado, y reenvía la clave de seguridad modificada a un motor criptográfico para el algoritmo de seguridad básico en dicho terminal móvil.
- 6Método de la reivindicación 1, en el que dicha información representativa del algoritmo seleccionado es un identificador de algoritmo que identifica la versión mejorada seleccionada del algoritmo de seguridad.
- 7Método de la reivindicación 1, en el que dicha etapa de seleccionar una versión mejorada del algoritmo de seguridad se basa en una lista de algoritmos soportados del terminal móvil y una lista de algoritmos permitidos por la red.
- 8Método de la reivindicación 1, en el que dichos algoritmos de seguridad se configuran para por lo menos una de confidencialidad de datos, integridad de datos y autenticación.
- 9Método de la reivindicación 8, en el que dichos algoritmos de seguridad se configuran para una comunicación cifrada en dicha red de comunicaciones de móviles.
- 10Método de la reivindicación 1, que comprende además las etapas de:- insertar, por parte de dicho lado de la red, información de protección contra repeticiones, en un desafío aleatorio, RAND, usado para la autenticación y el acuerdo de clave con el terminal móvil;- extraer de dicho desafío aleatorio, por parte de dicho terminal móvil, dicha información de protección contra repeticiones;y - realizar, por parte de dicho terminal móvil, una comprobación de la protección contra repeticiones basándose en la información extraída de protección contra repeticiones.
- 11Método de la reivindicación 10, en el que dicha información de protección contra repeticiones se basa en un contador o se basa en el tiempo.
- 12Método de la reivindicación 1, que comprende además las etapas de:- generar, por parte de dicho lado de la red, información de autenticación dependiente de la clave, por lo menos parcialmente basándose en una clave secreta compartida entre el terminal móvil y el lado de la red;- insertar, por parte de dicho lado de la red, dicha información de autenticación dependiente de la clave en el desafío aleatorio, RAND, usado para la autenticación y el acuerdo de clave con el terminal móvil;5 10 15 20 25 30 35 40 45 50 - extraer de dicho desafío aleatorio, por parte de dicho terminal móvil, dicha información de autenticación dependiente de la clave;y - comprobar, por parte de dicho terminal móvil, dicha información de autenticación dependiente de la clave por lo menos parcialmente basándose en dicha clave secreta compartida, para verificar la autenticidad de la red.
- 13Método de la reivindicación 12, en el que dichas etapas de generar información de autenticación dependiente de la clave y comprobar dicha información de autenticación dependiente de la clave se realizan basándose por lo menos parcialmente en un valor aleatorio iniciado desde el lado de la red y una clave derivada localmente a partir de dicha clave secreta compartida, insertándose dicho valor aleatorio en dicho desafío aleatorio, RAND, junto con dicha información de autenticación dependiente de la clave.
- 14Método de la reivindicación 12, en el que dichas etapas de generar información de autenticación dependiente de la clave y comprobar dicha información de autenticación dependiente de la clave se realizan basándose por lo menos parcialmente en dicha clave secreta compartida y por lo menos un elemento de información, insertándose dicho por lo menos un elemento de información en dicho desafío aleatorio, RAND, junto con dicha información de autenticación dependiente de la clave, protegiendo así, en cuanto a integridad, dicho por lo menos un elemento de información.
- 15Método de la reivindicación 14, en el que dicho por lo menos un elemento de información incluye información de protección contra repeticiones.
- 16Método de la reivindicación 14, en el que dicha etapa de seleccionar una versión mejorada del algoritmo de seguridad es realizada por una red visitada, dicho por lo menos un elemento de información incluye información sobre algoritmos de seguridad permitidos por una red doméstica del terminal móvil, y dicho terminal móvil comprueba si el algoritmo de seguridad seleccionado por la red visitada está permitido por la red doméstica.
- 17Método de la reivindicación 1, en el que dicha etapa de modificar una clave de seguridad básica se realiza basándose en una función de modificación criptográfica implementada por software, sensible a la clave de seguridad básica, e información representativa del algoritmo seleccionado.
- 18Disposición para mejorar la seguridad para una comunicación protegida basada en un procedimiento de acuerdo de clave en una red de comunicaciones de móviles que presta servicio a un terminal móvil (100) que tiene por lo menos un algoritmo de seguridad básico, comprendiendo dicha disposición:- medios para seleccionar, en un lado de la red, una versión mejorada de un algoritmo (24) de seguridad criptográfico básico para la comunicación entre el terminal móvil y un lado de la red;- medios para transmitir información representativa del algoritmo seleccionado (24) desde el lado de la red al terminal móvil, - medios para modificar una clave de seguridad básica resultante del procedimiento de acuerdo de clave en función de información representativa del algoritmo seleccionado, para generar una clave de seguridad específica del algoritmo;- medios para aplicar el algoritmo (24) de seguridad criptográfico básico con la clave de seguridad específica del algoritmo como entrada de clave para mejorar la seguridad para la comunicación protegida en dicha red de comunicaciones de móviles.
- 19Disposición de la reivindicación 18, en la que dichos medios de selección comprenden medios para negociar entre dicho terminal móvil y dicha red con el fin de seleccionar una versión mejorada de un algoritmo de seguridad criptográfico básico.
- 20Disposición de la reivindicación 18, en la que dichos medios para modificar una clave de seguridad básica y dichos medios para aplicar el algoritmo de seguridad criptográfico básico con la clave de seguridad específica del algoritmo como entrada de clave están implementados tanto en el lado de la red como en el terminal móvil.
- 21Disposición de la reivindicación 18, en la que el algoritmo de seguridad básico junto con la modificación, específica del algoritmo, de dicha clave de seguridad básica se corresponden con la versión mejorada del algoritmo de seguridad.
- 22Disposición de la reivindicación 18, en la que dicho terminal móvil se puede hacer funcionar para modificar la clave de seguridad básica resultante del procedimiento de acuerdo de clave en función de la información representativa del algoritmo seleccionado, y para reenviar la clave de seguridad modificada a un motor criptográfico para el algoritmo de seguridad básico.
- 23Disposición de la reivindicación 18, en la que dichos medios para seleccionar una versión mejorada del algoritmo de seguridad funcionan basándose en una lista de algoritmos soportados del terminal móvil y una lista de algoritmos permitidos por la red. 5 10 15 20 25 30 35 40 45 50
- 24Disposición de la reivindicación 18, en la que un nodo de red se puede hacer funcionar para seleccionar una versión mejorada de un algoritmo de seguridad básico y modificar la clave de seguridad en el lado de la red, y para comunicar información representativa del algoritmo seleccionado al terminal móvil.
- 25Disposición de la reivindicación 18, en la que un primer nodo de red se puede hacer funcionar para calcular, para cada uno de una pluralidad de algoritmos de seguridad criptográficos, una clave de seguridad específica del algoritmo y para transferir el conjunto calculado de claves de seguridad específicas del algoritmo a un segundo nodo de red, pudiéndose hacer funcionar dicho segundo nodo de red para seleccionar una versión mejorada de un algoritmo de seguridad básico y para extraer una clave de seguridad a partir de dicho conjunto de claves de seguridad específicas de algoritmo.
- 26Disposición de la reivindicación 18, en la que dichos algoritmos de seguridad están configurados para una comunicación cifrada en dicha red de comunicaciones de móviles.
- 27Disposición de la reivindicación 18, que comprende además:- medios para insertar, en el lado de la red, información de protección contra repeticiones, en un desafío aleatorio, RAND, usado para la autenticación y el acuerdo de clave con el terminal móvil;- medios para extraer de dicho desafío aleatorio, en dicho terminal móvil, dicha información de protección contra repeticiones;y - medios para realizar, en dicho terminal móvil, una comprobación de la protección contra repeticiones basándose en la información extraída de protección contra repeticiones.
- 28Disposición de la reivindicación 18, que comprende además:- medios para generar, en el lado de la red, información de autenticación dependiente de la clave, por lo menos parcialmente basándose en una clave secreta compartida entre el terminal móvil y el lado de la red;- medios para insertar, en el lado de la red, dicha información de autenticación dependiente de la clave en el desafío aleatorio, RAND, usado para la autenticación y el acuerdo de clave con el terminal móvil;- medios para extraer de dicho desafío aleatorio, en dicho terminal móvil, dicha información de autenticación dependiente de la clave;y - medios para comprobar, en dicho terminal móvil, dicha información de autenticación dependiente de la clave por lo menos parcialmente basándose en dicha clave secreta compartida, para verificar la autenticidad de la red.
- 29Disposición de la reivindicación 18, en la que dichos medios para modificar una clave de seguridad básica se proporcionan como una actualización de software.
- 30Terminal móvil (100) para su funcionamiento en una red de comunicaciones de móviles, comprendiendo dicho terminal:- una funcionalidad (10) de autenticación y acuerdo de clave, AKA;- un motor para un algoritmo (24) de seguridad criptográfico básico;- medios para modificar una clave de seguridad básica a partir de dicha funcionalidad AKA en respuesta a información representativa de un algoritmo de seguridad criptográfico seleccionado, con el fin de generar una clave de seguridad específica del algoritmo para introducirla en dicho motor de algoritmo de seguridad criptográfico básico con el fin de mejorar la seguridad para una comunicación protegida en dicha red de comunicaciones de móviles, y para que el terminal móvil se pueda hacer funcionar para recibir la información representativa del algoritmo seleccionado desde un lado de la red, en el que el algoritmo de seguridad seleccionado es una versión mejorada del algoritmo de seguridad criptográfico básico.
- 31Terminal móvil de la reivindicación 30, en el que el algoritmo de seguridad criptográfico básico junto con la modificación de dicha clave de seguridad básica en una clave de seguridad específica del algoritmo se corresponden con un algoritmo de seguridad criptográfico mejorado.
- 32Terminal móvil de la reivindicación 30, en el que dichos medios para modificar una clave de seguridad básica se proporcionan como una actualización de software en el terminal móvil.
- 33Nodo (300) de red para su funcionamiento en una red de comunicaciones de móviles que presta servicio a un terminal móvil (100) que soporta por lo menos un algoritmo (24) de seguridad criptográfico básico, comprendiendo dicho nodo de red:- medios para seleccionar una versión mejorada de un algoritmo de seguridad criptográfico básico para una comunicación protegida con un terminal móvil, y - medios para comunicar, al terminal móvil, información específica del algoritmo, correspondiente al algoritmo seleccionado, y - medios para obtener, a partir de una clave de seguridad básica resultante de un procedimiento de acuerdo de clave, una clave de seguridad específica del algoritmo, correspondiente a una versión mejorada del algoritmo de 5 seguridad criptográfico básico para su introducción en el algoritmo (24) de seguridad criptográfico básico con el fin de mejorar la seguridad para una comunicación protegida en dicha red de comunicaciones de móviles, en el que la obtención se lleva a cabo en función de la información representativa del algoritmo seleccionado.
- 34Nodo de red de la reivindicación 33, en el que dichos medios para obtener una clave de seguridad específica del algoritmo comprenden medios para modificar una clave de seguridad básica resultante de un procedimiento de 10 acuerdo de clave en dicha red de comunicaciones de móviles en función de información representativa del algoritmo seleccionado.
- 35Nodo de red de la reivindicación 34, en el que dichos medios para modificar una clave de seguridad básica se proporcionan como una actualización de software en el nodo de red.
- 36Nodo de red de la reivindicación 33, en el que dichos medios para obtener una clave de seguridad específica 15 del algoritmo comprenden medios para seleccionar una clave de seguridad a partir de un conjunto pre-calculado de claves de seguridad específicas de algoritmo correspondientes a una pluralidad de algoritmos de seguridad.
Independent claims36
258 paragraphs in 5 sections, as filed
5
10
15
20
25
30
35
40
45
50
DESCRIPTION
Improved security design for cryptography in mobile communications systems Technical field
The present invention relates in general to cryptographic aspects in communication systems, and, more particularly, to security improvements for GSM (Global System for Mobile Communication), UMTS (Universal Mobile Telecommunications System) and communication systems Similar.
Background
In mobile communications, for example, according to GSM or UMTS regulations, security is of the utmost importance. This is closely related to the increased use of mobile communications in business relationships and for private communications. At this time it is known that, for example, GSM suffers from security problems. As recently described in reference [1], it is possible to recover the encryption key by violating the cryptographic algorithm A5 / 2. There are three basic algorithm choices for circuit switched data, A5 / 1, a5 / 2, A5 / 3, and three basic algorithms for packet data, GEA1, GEA2 and GEA3. However, it should be noted that there are also stronger 128-bit algorithms indicated as A5 / 4 and GEA4. The terminal signals its capabilities, in particular the set of cryptographic algorithms it supports, to the network. Next, the network selects which cryptographic algorithm to use. Note that this signaling is not protected. Thus, the terminal does not have the option to detect if an attacker is signaling that he should use the A5 / 2, and when he is doing so, and that this information originates from a legitimate operator.
In general, there are at least three types of attacks. The first type implies that an attacker intercepts and decrypts traffic when the system is using the violated A5 / 2 algorithm.
The second type of attack includes the interception of traffic associated with the AKA procedure to record traffic data and the RAND value that is used. Subsequently, a false base station can cause the mobile terminal to execute an AKA procedure using the previously registered RAND and then encrypt the traffic using the A5 / 2 algorithm, which allows the attacker to recover the Kc cryptographic key. Due to the simple dependence on the RAND, this key, Kc, will be the same key that was used to protect the registered traffic.
The third type of attack implies that an active man-in-the-middle forces the terminal to use the A5 / 2 algorithm, thus allowing the calculation of the cryptographic key.
The UMTS standard recommends methods that overcome most of these problems. However, a scenario is foreseen in which GSM terminals will be used for a considerable period of time until the vast majority of users have become owners of UMTS terminals. In fact, many advanced services will be available on GSM phones and users may be reluctant to change their phones until some time passes.
Additionally, although the UMTS has countermeasures that make it resistant to these attacks, there is obviously a concern that future advances in crypto-analysis will discover that similar problems also exist in it and / or in other communication systems. On the other hand, there could be an implication of security problems when traveling between different types of networks, such as GSM and UMTS networks.
Summary of the invention
The present invention overcomes these and other drawbacks of the prior art arrangements.
It is a general objective of the present invention to provide an improved security design for communication systems.
In particular, it is an object of the invention to provide security improvements for an encrypted communication that is based on key agreements in mobile communication systems such as GSM and UMTS.
A special objective is to improve key management for GSM and UMTS in order to limit the impact of the A5 / 2 violation and future attacks on other algorithms.
It has been recognized that a major defect in prior art security designs is that, although the cryptographic security key depends on a certain random challenge, the same key is used regardless of the particular security algorithm. A basic idea according to the invention is to improve or update the basic cryptographic security algorithms by means of a modification, specific to the algorithm, of the security key generated in the normal key agreement procedure of the mobile communication system.
5
10
15
20
25
30
35
40
45
50
55
For communication between the mobile terminal and the network side, it is normally selected, either by the network side or based on a mutual agreement between the mobile and the network side, an improved version of one of the basic cryptographic security algorithms supported by the mobile. Next, the basic security key resulting from the key agreement procedure between the mobile terminal and the network is modified depending on information representative of the selected algorithm to generate a specific security key of the algorithm. Finally, the basic security algorithm is applied with the specific security key of the algorithm, as a key entry to improve security for a protected communication in the mobile communication network.
As mentioned, the algorithm can be selected on the network side, in which case the network side transmits information representative of the selected algorithm to the mobile terminal. This solution is consistent, for example, with the current GSM, where the network selects the A5 / 1 through A5 / 3 algorithms.
However, alternatively, especially for other communication systems, the selection of the improved security algorithm according to the invention can be based, if desired, on an agreement between the mobile terminal and the network side, for example, executed by means of a contact entry signaling procedure, an offer-response protocol or a similar negotiation protocol.
Preferably, the original algorithms implemented in hardware remain the same (at least in the mobile terminal), and, for each original algorithm that needs a security improvement, an updated (virtual) security algorithm is defined, such as an algorithm of Enhanced encryption / cryptographic, based on the original algorithm along with the modification of the specific key of the algorithm. The modification of the key is typically performed by means of a key modification function, which processes the input key based on an algorithm identifier or similar information representative of the selected algorithm and, possibly, some additional data to generate a modified key. , which is forwarded to the original security algorithm.
If it is desirable to support, not only improved versions of security algorithms, but also maintain support for basic algorithms, for example, for interoperability related purposes, the algorithm identifier must be able to distinguish between the original basic security algorithms. and improved security algorithms.
In practice, the basic solution only requires software updates on the terminals and / or on the network system. In a preferred embodiment of the invention, the problem is basically solved by modifying the terminals and letting them signal that they (only) support updated upgraded versions of the original basic algorithms. Standardization efforts can be kept to a minimum level, since it is only necessary to normalize the modification function and algorithm identifiers.
On the network side, the algorithm selection, key modification and cryptographic security processing, such as encryption, can be implemented on a single node, or distributed on several nodes. Frequently, algorithm selection and key modification are implemented on the same node. However, alternatively, the selection of the algorithm and the modification of the key can be distributed, if desired, in more than one node of the network. For example, a node can calculate specific algorithm keys for a complete set of security algorithms, and transfer the keys to another node, which then selects an improved version of a security algorithm and extracts or derives the appropriate key from the set of keys received. Depending on the implementation of the system, real encryption or other security processing can be performed on the same node where the key was derived or on a separate node.
The invention also provides support for repetition protection, basic network authentication and / or the selection of a secure algorithm, preferably based on the encoding or insertion of information into existing AKA information such as the random challenge used in the procedure. of AKA with the mobile terminal. Authentication of the network is preferably achieved by inserting authentication information dependent on the key, such as a MAC (Message Authentication Code) that can be verified by the mobile terminal. By calculating the MAC with respect to repetition protection information and / or information on the algorithms allowed by the home network, this information will receive some integrity protection, resulting in a safe repetition protection and / or a safe algorithm selection.
Although the currently most urgent problem refers to compromised GSM algorithms, it is clear that the key modification is useful not only in GSM, but also in UMTS, CDMA or future generation systems, to preventively guarantee that later Similar problems appear (perhaps not yet discovered), since the key derivation in it is currently also independent of the algorithm. Indeed, the invention is applicable in various communications systems, including, for example, GSM / GPRS, W-LAN (Wireless Local Area Network), UMTS and IMS (IP Multimedia Subsystem) systems.
Thus, the invention provides a remedy for a defect of a basic security design in, for example, the AKA procedures of the GSM / UMTS. The proposed solution fits well into the existing protocol structure and has limited implementation consequences, which makes rapid deployment possible.
The invention offers the following advantages:
5
10
15
20
25
30
35
40
45
50
• An effective solution to a defect in a basic security design;
• It is enough to modify the key, while allowing the original algorithms implemented in hardware to remain unchanged;
• Minimum standardization effort;
• It fits well into the existing protocol structure; Y
• Limited implementation consequences, which makes rapid deployment possible.
Other advantages offered by the present invention will be appreciated by reading the following description of the embodiments of the invention.
Brief description of the drawings
The invention, together with additional objectives and advantages thereof, will be better understood in reference to the following description considered in conjunction with the accompanying drawings, in which:
Fig. 1 is a schematic block diagram illustrating a basic solution according to a preferred, exemplary embodiment of the invention with a global algorithm defined by a specific key modification of the algorithm in combination with an original basic cryptographic algorithm;
Fig. 2 is a schematic flow chart of a method for improving security for protected communication in a mobile communication system according to a preferred embodiment of the invention;
Fig. 3 is a basic, schematic signal diagram, according to a preferred exemplary embodiment of the invention;
Fig. 4 is a schematic block diagram illustrating relevant parts of a mobile terminal according to an exemplary embodiment of the invention, which implements a specific key modification of the algorithm;
Fig. 5 illustrates an exemplary network architecture, illustrating the nodes involved for different types of communication systems;
Fig. 6 is a schematic diagram illustrating an overview of the method of setting improved encryption mode and modifying the key according to a specific, exemplary embodiment of the invention; Y
Fig. 7 is a basic, schematic signal diagram, according to another preferred exemplary embodiment of the invention, which includes improvements of security algorithms with integrated repeating protection and network authentication.
Detailed description of embodiments of the invention
It may be useful to start with a brief analysis of the basic security flaws in GSM. A flaw in the current design is that the key used for all algorithms is obtained in the same way regardless of the encryption algorithm to be used. If this were not the case, the violation of the A5 / 2 would have meant just that, and the type 2 and 3 attacks mentioned in the background section could not have been used to intercept protected traffic with other algorithms.
In addition, the importance of the design error is increased by the fact that the signaling is not protected (there is no network authentication and, consequently, neither integrity nor protection against repetitions). As mentioned, this is corrected in the UMTS. It might seem that improving the security of GSM in UMTS would fix the problems. However, this requires modifications in the AuC (Authentication Center), in base stations, in terminals and in SIM cards (Subscriber Identity Module), and would be a very expensive way to solve the problems.
On the other hand, the invention provides a remedy for this type of security flaws, based mainly on a modification, specific to the algorithm, of the AKA key application material. Referring to Fig. 1, it can be seen that the key application material provided by the conventional AKA method 10 is used as input to an improved security algorithm 20, which is formed by a key modification 22 in combination with an original security algorithm 24 . In order to guarantee a key application material dependent on the algorithm as an output of the modification unit, as input to the modification unit, information representing or, otherwise identifying, a selected algorithm is applied. Although the invention does not increase the security of underlying basic algorithms as such, the key material is not as useful for attacks on any of the other algorithms. The modification of the key is normally carried out by means of a cryptographic modification function, which should at least be a unidirectional function and preferably a pseudo-random function. For example, the cryptographic modification function can be implemented as a cryptographic hash function. Optionally you can enter other related information
5
10
15
20
25
30
35
40
45
50
55
with the AKA, such as RAND and RES of the AKA procedure, to make pre-calculation attacks unfeasible, and optional context information can also be entered if other types of downward bidding attacks can be identified (bidding -down)
Security processing of security algorithms is typically related to confidentiality and data encryption, although alternatively it may refer to data integrity and / or authentication.
The modification of the key can be considered as a preprocessing of the algorithm, although it can also be seen as a post-processing of the AKA, in which the exit key of the conventional AKA procedure is subsequently processed to produce a key dependent on the algorithm. It is simply a matter of definitions.
Fig. 2 is a schematic flow chart of a method for improving security for protected communication in a mobile communication system according to a preferred embodiment of the invention. In step S1, a key agreement procedure is performed, usually as part of a complete AKA procedure that also involves authentication of the mobile terminal. In step S2, an improved version or modernization of one of the basic security algorithms is selected, on the network side or based on a mutual agreement between the mobile terminal and the network side. As previously indicated, enhanced security algorithms are often improved encryption / cryptographic algorithms in terms of security, although other types of security processes may be interesting. If the algorithm is selected on the network side, information representative of the selected algorithm is transmitted from the network side to the mobile terminal. In this case, if the mobile is in the home network, the algorithm is usually selected by the home network. If the mobile travels on a visited network, the visited network usually makes the selection of the algorithm according to a predetermined policy. The selection made by the visited network can finally be checked with respect to a home network security policy, so that the selected algorithm is accepted by the home network. Alternatively, a negotiation is carried out between the mobile terminal and the network side to decide which security algorithm to use, for example, by means of a contact-entry signaling procedure.
Anyway, in the end there is some agreement on which security algorithm to use for a protected communication with the mobile terminal. The particular order in which the algorithm agreement is made and the key agreement is not usually critical, although it may be advantageous to perform the algorithm agreement after a successful authentication of the mobile terminal. In step S3, key information, typically a basic security key, of the key agreement procedure of step S1 is modified to generate specific key information of the algorithm. In step S4, the corresponding basic security algorithm is then applied with the modified and specific key information of the algorithm as key input. By ensuring that the security key information is specific to the algorithm or dependent on the algorithm, the security for protected communication between the network and the mobile terminal is improved.
The modification of the specific key of the algorithm and the use of the modified key information is preferably implemented in the mobile terminal as well as in the network side, but at least in the terminal side. Considering the high number of mobile terminals that may be affected by a compromised security algorithm, it may be very advantageous to implement the modification of the key in software, and simply to perform a software modernization of the terminals. This means that the original algorithms implemented in hardware can remain unchanged, significantly limiting the consequences of the implementation. The modification of the key is typically performed by means of a key modification function, implemented in software, such as a unidirectional cryptographic hash function, which processes the input key based on an algorithm identifier and, possibly, some additional data, to generate a modified key, which is then forwarded to the original security algorithm. Similarly, the relevant network node or nodes can be updated through software upgrades.
Basically, the invention suggests a modification of the key application material produced in conventional AKA procedures, such as the GSM AKA and the UMTS AKA, to generate algorithm-dependent keys. Although the invention is generally applicable in various communication systems including GSM, GPRS, W-LAN, CDMA, UMTS, IMS or future generation systems, the invention will be described below mainly in the context of GSM / GPRS AKA procedures. and from the UMTS.
A specific example for the GSM AKA:
Kc '= Modify_GSM (Kc, Id_Algoritmo, [RAND, RES, Other_info_context])
and for the UMTS:
Ck ', Ik' = Modify_UMTS (Ck, Ik, Id_Algoritmo, [RAND, RES, Other_info_context])
where the Modify_GSM () and Modify_UMTS () functions are cryptographic functions, for example, based on MD5, SHA1 or some variant thereof, which perform a truncation respectively at the 64/128 bits to the left. In the case of UMTS, it is also possible to use some function that takes both Ck and Ik as an input to produce a 256-bit output. The RAND can be introduced to get pre attacks
5
10
15
20
25
30
35
calculation are not viable. For transfers between MSCs and similar transfers in other systems, the RAND is then typically transferred along with the conventional transfer information from the old MSC to the new MSC.
The invention will now be described mainly in reference to the scenario in which the algorithm is selected on the network side. However, it should be understood that it is also feasible to implement a basic contact entry signaling procedure or a similar negotiation mechanism in which the mobile terminal and the network side agree on which security algorithm to use. for protected communication.
It may be useful to describe the general signaling between the terminal and the network side according to a preferred exemplary embodiment of the invention, referring to Fig. 3.
one. The terminal indicates which updated algorithms it supports, as well as a user ID or subscriber.
The network side (which involves the home network and / or the network visited in the manner and at the time required by a conventional AKA procedure) initiates authentication and the key agreement creating a RAND, calculating an expected response and a or more keys. On the basis of the subscriber ID, on the network side the relevant secret and shared subscriber key can be retrieved to allow AKA calculations.
2. The network sends the RAND to the terminal.
3. The terminal enters the RAND in the GSM SIM, the UMTS SIM, the ISIM or similar functionality and, based on a shared subscriber key, obtains a RES response and one or more keys.
Four. The terminal sends the RES to the network side.
5. The network side checks the RES to authenticate the terminal. When the mobile is in the home network, the home network checks the RES for an expected response XRES. When the mobile terminal is in a visited network, the visited network normally checks the RES for comparison with an XRES received from the home network. In GSM terminology, both RES and XRES are normally referred to as SRES.
6. In this example, the network side (home network or visited network depending on where the mobile is located) preferably selects one of the updated algorithms supported by the terminal and initiates encryption. Naturally, the network side must also support the selected enhanced security algorithm.
7. The network side sends the algorithm ID to the terminal.
8. The terminal initiates encryption based on the selected updated algorithm that includes a key modification dependent on the algorithm.
If it is desirable to support, not only the improved versions of the security algorithms, but also maintain a support for the basic algorithms, for example, for reasons related to interoperability, the algorithm identifier must be able to distinguish between the original basic security algorithms and improved security algorithms.
The following Table I illustrates a possible example of algorithm identifiers for basic GSM / GPRS cryptographic algorithms and a corresponding set of enhanced cryptographic algorithms:
Basic Security Algorithms: Algorithm ID
A5 / 11
A5 / 22
A5 / kk
GEA1k + 1
GEA2k + 2
GEAmk + m
Enhanced Security Algorithms: Algorithm ID
A5 / 1 '(k + m) +1
A5 / 2 '(k + m) +2
A5 / k '(k + m) + k
GEA1 '(k + m + K) +1
GEA2 '(k + m + k) +2
Enhanced Security Algorithms: Algorithm ID
GEAm '(k + m + K) + m
In this way, new improved cryptographic algorithms have been defined, represented in this case by As / 1 ', As / 2', ..., A5 / k ', ..., GEA1', GEA2 ', ..., GEAm 'for the particular case of GSM and GPRS encryption. Generally speaking, it is assumed that there is a number, k, of A5 algorithms and a number, m, of GEA algorithms, where normally k = m = 4. As previously described, each of the improved algorithms is formed by modifying the specific key of the algorithm in combination with the corresponding basic algorithm. If, for some reason, the network selects a basic security algorithm, the AKA key will be transparently transferred without modification to the basic algorithm.
Naturally, other ways of differentiating algorithm identifiers can be used, for example, based on binary or hexadecimal representations.
10 For example, since GSM is currently specified so that it supports up to eight algorithms, a simple way would be to let A5 / j, where j = 5, 6, 7 and 8 indicate respectively AS / 1 ', AS / 2 ', AS / 3' and A5 / 4 '. In relation to the 128-bit A5 / 4 and also GEA4 algorithms, it may not be necessary to provide improved variants, since they are considered, at least at present, very resistant.
If it is desired to support only the updated improved algorithms, a possible example of algorithm identifiers for the proposed enhanced GSM / GPRS cryptographic algorithms is given in the following Table II.
Enhanced security algorithms: Algorithm ID:
A5 / 1'1
A5 / 2'2
A5 / k'k
GEA1'k + 1
GEA2'k + 2
GEAm'k + m
An exemplary solution is to modernize the terminals and let them signal that they only support the updated version of the basic (current) algorithms. This can be done by defining new cryptographic algorithms, for example, AS / 1 ', A5 / 2', ..., A5 / k ', GEA1', GeA2 ', ..., GEAm' for the particular case of GSM and GPRS, or by means of an indication in the signaling of general capabilities of the terminal.
twenty An example of a complete procedure can be described as:
one. The terminal signals the support of A5 / x ', A5 / y', ..., and also sends the user ID or subscriber.
2. The network sends the RAND to the terminal.
3. The terminal enters the RAND in the SIM and obtains RES and Kc.
Four. The terminal sends the RES to the network.
25 5. The network checks the RES.
6. After successful authentication, the network selects a supported algorithm, for example, A5 / y ', and starts encryption with the use of A5 / y'.
7. The network sends the algorithm identifier of A5 / y 'to the terminal.
5
10
15
20
25
30
35
40
45
50
55
60
8. The terminal starts encryption with the use of the updated algorithm A5 / y '= (key modification and A5 / y). In practice, this typically means that the terminal calculates the modified key to be used by performing Kc '= Modify (Kc, identifier_A5 / y', [RES], [RAND]) and applies the modified key Kc 'to the original hardware algorithm A5 /Y.
As mentioned above, the modification function should be at least one unidirectional function, preferably a pseudo-random function. A conventional cryptographic hash function with key, MD5, SHA-1, or some variant thereof, for example, HMAC can be used. If desired, it is even possible to change (increase / decrease) the size of the basic AKA key by means of the modification function. For example, a key processing and / or concatenation of key material can be used to increase the size of the final key. For example, the modification unit can invoke the SIM a second time using the RAND plus a predetermined constant as a new random challenge and concatenate the first AKA key with the second AKA key to generate a new double size key, which subsequently It can be made specific to the algorithm by means of a cryptographic unidirectional function. Another example involves processing the AKA key, for example, shifting bits, to generate a processed AKA key, which can then be concatenated with the original AKA key to increase the size of the key. Naturally, the modification unit may include other security enhancement functions that can be combined with the specific key modification of the algorithm proposed by the invention.
Fig. 4 is a schematic block diagram of the relevant parts of a mobile terminal according to an exemplary embodiment of the invention, which implements a specific key modification of the algorithm. Normally, AKA functionality 10 is implemented in a conventional identity module (IM) 15 such as the GSM SIM card, although alternatively it can be provided anywhere else in mobile terminal 100. Next, the output key (s) of the AKA is optionally forwarded, together with the RAND, the RES and / or context information, to the key modification module 22 of the invention. The key modification module 22 processes the output key (s) of the AKA in response to an algorithm identifier representative of the security algorithm selected to generate a security key specific to the algorithm. This modified key is then transferred to the basic security algorithm 24, exemplified in this case by a cryptographic algorithm, such as, for example, any of the original algorithms A5 / 1, A5 / 2, A5 / 3, GEA1, GEA2 and GEA3. Obviously, the basic security algorithm 24 also receives the information to be protected by the security algorithm. In the case of encryption, the so-called "clean text" data is encrypted by the security algorithm based on the algorithm-specific security key to generate encrypted output data. The key modification module 22 is normally implemented as terminal software / hardware, preferably using the general terminal capabilities corresponding to the mobile 100. As mentioned, it is advantageous to implement the modification of the key as a software modernization based on a cryptographic modification function suitable for execution by the terminal's processing hardware. However, if any mobile designer / manufacturer wants all cryptographic functions to be in hardware, there is nothing to prevent a hardware implementation of the key modification. For example, new GSM phones may be provided with an additional hardware module for modifying the key that is arranged to cooperate with the AKA module and the basic, common cryptographic encryption algorithm. The cryptographic algorithm 24 is typically performed on terminal hardware, preferably near the RX / TX chain 30. The identity module 15 may be any tamper-resistant identity module known in the art, including conventional SIM cards used in GSM mobile phones (Global System for Mobile Communications), SIM UMTS (Universal Mobile Telecommunications System) (USIM ), SIM WAP (Wireless Applications Protocol), also known as WIM, ISIM (IP Multimedia Subsystem Identity Module) and, more generally, UICC modules (Universal Integrated Circuit Card). AKA functionality must not necessarily be implemented in an identity module, or at least not in a hardware module such as the common SIM. It is even possible to emulate a complete identity module that includes AKA functionality in software.
As mentioned, the invention can be applied both when the mobile terminal is in its home network and when traveling in a visited network, provided that the home network and the visited network, respectively, support improved security algorithms (It is enough that the home network has knowledge of the existence of the algorithms). Because the latter case, when the mobile travels in a roaming network in a visited network, is somewhat more complex, an exemplary network architecture will be briefly described that includes both a home network and a visited network in reference to Fig. In addition to a general network architecture, Fig. 5 also illustrates the nodes involved for each of a series of exemplary communication systems.
The global network architecture includes a mobile terminal 100, a network access point 200, one or more nodes 300 called security enablers in the visited network and one or more subscriber management network nodes 400 in the home network. The network access point can be, for example, a BTS node (Base Transceiver Station), a B node or a W-LAN access point, depending on the communication system considered. Basically, the security enabling nodes 300 in the visited network must provide support for user authentication, in which the mobile terminals are authenticated with respect to the network in order to gain access to the network services. This authentication can also serve as a basis for user billing. The basic security protocols of current communication systems normally involve a challenge-response and key-agreement (AKA) authentication procedure. The AKA procedure is based on the
5
10
15
20
25
30
35
40
45
50
55
60
more frequently in symmetric cryptography that uses a secret key shared between the mobile terminal and the home network, as previously described. In the mobile terminal 100, the shared secret key is normally stored in a subscriber identity module, such as the GSM SIM, the USIM, the ISIM, the WIM, or, more generally, in a UICC. In the home network, one or more network nodes 400 manage the subscribers and related security information. The subscriber management node (s) 400 of the home network communicates with the security enabler (s) 300 in the visited network, usually transferring information related to the AKA and optionally also Security policy information from the home network to the visited network. According to an exemplary embodiment of the invention, the security enabler (s) also includes a functionality to select a security algorithm suitable for a protected communication with the mobile terminal. Preferably, the security enabler node (s) 300 is implemented with a key modification function to modify the output key (s) of the normal AKA (s) depending on the algorithm selected with the in order to provide support for the improved security algorithms, in accordance with the invention. These security enablers can also include real cryptographic engines for security processing, such as encryption. However, in some systems such as GSM, encryption is implemented in the actual base transceiver station that acts as an access point to the network.
Algorithm selection, key modification, and real encryption can be implemented on a single node, or distributed on several nodes. Frequently, algorithm selection and key modification are implemented on the same node. However, alternatively, the selection of the algorithm and the modification of the key can be distributed, if desired, in multiple network nodes. Depending on the system implementation, the actual encryption or other security processing may be located together or not with the key generation functionality. In the latter case, the specific algorithm key, modified, to be used in the encryption algorithm may have to be transferred to an independent node, in which encryption is performed.
For a GSM system, the security enable nodes typically correspond to the BSC (Base Station Controller) and the MSC / VLR (Mobile Switching Center / Visited Position Register). On the side of the home network, the HLR / AuC (Home Positions Registration / Authentication Center) of the GSM network will normally manage subscribers and security-related information. Naturally, the subscriber enabling network node (s) 300 may be an HLR / AuC of a home operator, possibly involving an AAA server (Authorization, Authentication and Accounting) that may be located jointly or not with the authentication center. However, it can also be an intermediary that acts as a general authentication center, or identity center, for a number of different network operators. Basically, on the network side, the proposed solution only requires the extension of the algorithm identifiers and the implementation of a specific algorithm key modification in a suitable place in the BSC or in the MSC / VLR. In GSM, the actual encryption is executed on the BTS base station. This means that the modified key must be forwarded from the BSC to the base station for actual encryption. Therefore, the BTS can also be considered as part of the security enabler (s). Conventional authentication and key agreement parameters are typically obtained from the HLR / AuC.
For a GPRS / GSM system, both the key modification and the encryption are typically implemented in the SGSN node (GPRS Service Support Node), which also manages the authentication of subscribers in the visited network. The BSS (Base Station System) GSM with its BTS base station therefore has a more passive role in this context, compared to the case of pure GSM.
For a 3GPP W-LAN system, the security enable nodes typically correspond to the AAA proxy node and the WSN / FA (W-LAN Service Node), which interacts with the W- Access Point (AP) LAN Conventional authentication and key agreement parameters are obtained from the HLR / AuC and an AAA server.
For a UMTS system, the access point is NodeB, and the security enable nodes correspond to the RNC (Radio Network Controller) and the MSC nodes. In the home network, the HLR / AuC takes care of the necessary interaction with the MSC and RNC nodes.
For a Multimedia IP sub-system, the CSCF (Call Status Control Function) node Proxy corresponds to the security enabler node, and may include a specific key modification of the algorithm to improve security for a control signaling at the application level. In future generations of the IMS system, user data can also be protected using a key modification according to the invention. In the home network, an HSS (Domestic Subscriber System) node provides the required authentication and password agreement parameters, and the Service CSCF normally authenticates IMS subscribers.
Fig. 6 is a schematic diagram illustrating an overview of the establishment of the improved encryption mode and the key modification procedure according to an exemplary embodiment of the invention, in relation to the specific case of GSM. In a MS class mark similar to that standardized on TS24.008, a list of algorithms supported by the mobile is transferred from the mobile terminal 100 to the BSS (Base Station System), preferably to the BSC 310 through the station BTS 200 base, assuming that the decision or negotiation of the algorithm takes place in the BSC. The list of supported algorithms preferably includes at least the improved security algorithms A5 / 1 ', A5 / 2', A5 / 3 ', although possibly also the basic algorithms A5 / 1, A5 / 2 and A5 / 3. The MSC 320 transfers a list of algorithms allowed by the security policy of the network visited to the
5
10
15
20
25
30
35
40
45
50
55
BSS system and, more particularly, to BSC 310 in a CMC (Encryption Mode Order) order similar to that standardized in TS48.008. Next, the BSS system, and especially the BSC 310, normally selects an algorithm for protected communication with the mobile terminal based on the list of supported algorithms and the list of allowed algorithms and, if an improved security algorithm is selected, preferably Obtain a security key specific to the algorithm. The BSS system also transmits an algorithm identifier corresponding to the selected algorithm to the mobile terminal in a CMC radio interface command similar to that standardized in TS 44.018. For example, obtaining the key can be achieved by calculating the modified key in the BSC 310 depending on the algorithm selected. Alternatively, the MSC 320 calculates modified algorithm-specific keys for all algorithms allowed by the visited network and transfers them, preferably in relation to the CMC order, to the BSC, which in turn selects the algorithm and extracts the appropriate key from The calculated set of keys. In GSM, the actual encryption is done through the BTS 200 base station of the BSS system. In this case, the mobile terminal 100 is provided with a key modification functionality according to the invention and applies the algorithm identifier, possibly together with additional information, in the key modification function to generate a corresponding algorithm specific key, which will be used for encryption.
As previously mentioned, the selection of the algorithm made by the visited network can be checked with respect to a security policy of the home network, so that it can be guaranteed that the selected algorithm is accepted by the home network. Normally, this means that a list of algorithms allowed by the home network is transferred to the mobile terminal. This information is preferably protected in terms of integrity so that the mobile can be sure that the information has not been unduly manipulated, as will be described later.
The invention also preferably provides support for repetition protection, basic network authentication and / or secure selection of algorithms, preferably based on the encoding or insertion of information in existing AKA information such as the random challenge RAND used in the AKA procedure. With the mobile terminal. If modifications can also be accepted in the AuC or the corresponding node on the side of the home network, repetition protection, network authentication as well as other security improvements can be achieved as will be described later.
The RAND value is assumed to be random, but it is possible to use a few RAND bits to signal some additional information from the home network (AuC) to the terminal in order to further improve security. The above embodiments fix the problems with the key exclusivity by algorithm, but in general they do not eliminate the problems with the repetition or lack of network authentication. The exemplary solution below achieves this with minimal additional changes (only in the AuC and the terminal) and without new signaling.
Fig. 7 is a basic and schematic signal diagram according to another preferred exemplary embodiment of the invention, including improvements to the security algorithm with integrated repeating protection and network authentication. To simplify, the following example is related to the case of GSM, although the mechanisms described are not limited thereto, as the experts will easily understand.
one. The terminal indicates which updated algorithms it supports, preferably together with its subscriber ID, the visited network and the MSC / VLR node.
2. The visited network forwards the subscriber ID to the home network, and, more particularly, to the HLR / AuC or the corresponding node.
3. In this particular embodiment, the AuC forms RAND values as follows. (Assuming that RAND normally has a size of 128).
A. The AuC maintains for each mobile (SIM) a counter, c, of the number of authentications performed for said mobile. This counter can have, for example, a size of t = 16 bits, which is allowed to be reset in module 2A16. Counter c is a representative example of repetition protection information.
B. A random value R of (128-tm) bits is generated in the AuC, where m is subsequently determined.
C. The value r = R || c || 00 ... 0 (as many zeros as necessary to get the size of r to be 128 bits, that is, m bits) is passed through the generation function GSM password, obtaining a k key. Alternatively, some other filling scheme can be used. More generally, r is a function f of R and c and possibly also other optional information.
D. The value RAND = r || MAC (k, r) is formed and it is used to generate the encryption key Kc and the expected response XRES. In this case, MAC (Message Authentication Code) is a message authentication function, for example, HMAC, truncated to m bits, for example, m = 32. The MAC is a representative example of network authentication information.
4-5. The RAND is sent to the mobile in the usual way (and Kc, XRES is sent to the visited network).
5
10
15
20
25
30
35
40
45
6. The AuC increases c by one. On the terminal side, the following actions are preferably performed:
A. The mobile also maintains a counter c ', of the number of authentications it has made.
B. When the mobile receives RAND, it extracts ryc from it.
C. The mobile checks that c is "ahead" (see below) of its local c 'value. If not, abort the protocol.
D. If not, the mobile then sends r to the SIM, and obtains k (reusing the SIM).
E. The mobile checks if MAC is correct by calculating XMAC (k, r) and comparing MAC and XMAC. If MAC is not correct, the mobile aborts the protocol.
F. On the other hand, if the MAC is correct, the authenticity of the network has been verified. The mobile also updates its counter by setting c '= c.
7. The mobile invokes the SIM again, but now with the complete RAND as input to obtain RES and Kc.
8. The terminal sends RES to the network side.
9. The visited network normally checks RES by comparison with the XRES received from the home network, to authenticate the terminal.
10. The visited network selects one of the updated improved algorithms supported by the terminal and starts encryption.
eleven. The visited network sends the algorithm ID to the terminal.
12. The terminal initiates encryption based on the selected updated algorithm that includes a key modification dependent on the algorithm.
The mobile can now communicate with the visited network. Note that, due to the pseudo-random properties of the MAC function, the reduction of the relative entropy of RAND is small, basically only the bits corresponding to the counter are lost.
To check if c is "ahead", a normal arithmetic of sequential numbers is used. Two values of t bits, a and b, are compared as follows. Yes
a> by ab <2A (t-1),
or
a <b but ba> 2A (t-1)
then it is said that a is "in front" of b, in any other case it is not. An alternative solution could be to use a time indication as repetition protection information instead of a counter.
Since the MAC is calculated on r which includes the value c, some integrity protection will also occur for this data. It is noted that if an attacker modifies the protection information against repetitions, the MAC cannot be verified and the protocol will be aborted. However, regardless of whether or not a MAC is used, the RAND value will no longer be the same, resulting in an incorrect RES that does not match the expected XRES response on the network side. Therefore, there is no possibility of satisfactory user authentication if someone has improperly manipulated the RAND value.
Alternatively, the aspects of repetition protection and network authentication can be separated and executed independently of each other. For the protection against repetitions, a counter value or a time indication can be encoded, or it can be otherwise inserted in the RAND value. For a basic network authentication, authentication information of the key, such as a MAC code or the like, is calculated on the network side, and it is transmitted to the mobile terminal for verification.
Other improvements are also possible by combining the above fundamentals with some additional ideas that have already been proposed, for example, in the contribution [2]. For example, a few additional RAND bits can be assigned to signal a security policy from the home network to the mobile.
In the invention, for example, the j: th bit of RAND can be set to 1 if and only if it is allowed to use the algorithm number j (according to certain agreed algorithm numbering) by the mobile. In this way, a complete list of algorithms allowed by the home network can be communicated in the RAND. The mobile terminal can then check if the algorithm selected by the visited network is accepted by the home network. If not, the mobile terminal will abort the protocol. It is also possible and desirable to provide protection from
5
10
15
20
25
integrity by calculating a MAC about the information about security algorithms allowed by the home network.
Therefore, if desired, repetition protection, network authentication and secure algorithm selection can all be integrated, for example, leaving the value r = R || c || allowed algorithms || 00 .. .0 (as many zeros as required to make r have, for example, a 128-bit size). RAND value = r || MAC (k, r) is formed and used to generate the encryption key Kc, and the expected response XRES. The value r, the counter value c as well as the information about algorithms allowed by the home network are extracted by the mobile, and the MAC is checked.
An advantage of the invention is that the solution can coexist with other proposals, including those that are set out in general in the references [2, 3]. Although the proposals [2, 3] do improve several security aspects, none of them provide the desired key separation. This means that if the X and Y algorithms are both allowed and supported, then the mobile can potentially end up running both X and Y with the same key, Kc.
Compared to the basic embodiments of key modification, in the protection against repetitions, network authentication and / or the secure selection of algorithms, the only additional node that needs modifications is the HLR / AuC on the network side. In third generation networks, the CSCF (Call Status Control Function) node in the Multimedia IP sub-system needs to be updated in the basic key modification embodiments, and with the protection against repetitions, network authentication and / or The secure selection of algorithms, the HSS (Domestic Subscriber System) node also requires modification.
The embodiments described above are simply offered as examples.
References
[1] "Instant Ciphertext-Only Cryptanalysis of GSM Encrypted Communication" by Barkan, Biham, and Keller, Proceedings of Crypto 2003, Lecture Notes in Computer Science vol. 2729, Springer-Verlag.
[2] "Cipher key separation for A / Gb security enhancements", S3-030463, 3GPP S3 # 29, July 15-18, 2003, San Francisco, USA.
[3] "Enhanced Security for A / Gb", S3-030361, 3GPP S3 # 29, July 15-18, 2003, San Francisco, USA.
Contents5
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
28 members in 11 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 505748P | United States of America | – | |
| 50574803 | United States of America | P | |
| 50574803 | United States of America | P | |
| 2004001300 | Sweden | W | |
| 2004001300 | Sweden | W | |
| 505748P | – | – | – |
| PCTSE2004001300 | – | – | – |
| US20030505748P | – | – | – |
| WO2004SE01300 | – | – | – |
Members28
| Document | Office | Kind | |
|---|---|---|---|
| WO2005032201A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2005111666A1 | United States of America | A1 | |
| EP1671511A1 | European Patent Office (EPO) | A1 | |
| CN1857024A | China | A | |
| JP2007507157A | Japan | A | |
| HK1095689A | Hong Kong, China | A | |
| HK1095689A1 | Hong Kong, China | A1 | |
| US7660417B2 | United States of America | B2 | |
| JP4688808B2 | Japan | B2 | |
| EP1671511B1 | European Patent Office (EPO) | B1 | |
| AT514294T | Austria | T | |
| ATE514294T2 | Austria | T2 | |
| EP2357858A1 | European Patent Office (EPO) | A1 | |
| CN1857024B | China | B | |
| DK1671511T3 | Denmark | T3 | |
| ES2367692T3 | Spain | T3 | |
| EP2357858B1 | European Patent Office (EPO) | B1 | |
| AT552709T | Austria | T | |
| ATE552709T1 | Austria | T1 | |
| PT2357858E | Portugal | E | |
| ES2384634T3 | Spain | T3 | |
| PL2357858T3 | Poland | T3 | |
| EP1671511B2 | European Patent Office (EPO) | B2 | |
| EP2357858B3 | European Patent Office (EPO) | B3 | |
| DK1671511T4 | Denmark | T4 | |
| ES2367692T5This record | Spain | T5 | |
| ES2384634T7 | Spain | T7 | |
| PL2357858T6 | Poland | T6 |
Numbers
- Publication
- 2367692
- Publication, DOCDB
- 2367692
- Publication, EPODOC
- ES2367692T
- Application
- 4775405
- Application, DOCDB
- 04775405
- Application, EPODOC
- ES20040775405T
Titles2
- Spanish
- Diseño de seguridad mejorado para criptografía en sistemas de comunicaciones de móviles
- English
- Enhanced security design for cryptography in mobile communications systems
Classification
- CPC, 13
- H04L9/0844
- H04L63/0428
- H04L63/06
- H04W12/02
- H04L9/3273
- H04L2209/80
- H04W12/037
- H04W12/033
- H04W12/041
- H04W12/0433
- H04W12/0431
- H04W12/062
- H04W12/069
- IPC, 7
- H04L9 08
- H04L9 32
- H04W12 02
- H04W12 04
- H04L9 00
- H04L29 06
- H04W12 00