Method of processing a service request in a communications system, and control unit for same
Abstract
A method of processing a service request in a communications system wherein at least part of the service request is encrypted. The method comprises the steps of receiving a service request from a communications unit, attempting to authenticate said service request, determining, in response to a failure to authenticate said service request, a number of failures that have previously occurred for said communications unit, and providing, responsive to said number, service of a limited duration to said communications unit. Also described is a control unit for processing a service request.

Term
Term ended
Projected expiry passed 19 December 2017, 8.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
21 claims: 3 independent, 18 dependent
- 1CLAIMS 1. A method of processing a service request in a communications system wherein at least part of the service request is encrypted;5 the method comprising the steps of;- receiving a service request from a communications unit, - attempting to authenticate said service request, - determining, in response to a failure to authenticate said service request, a number of failures that have previously occurred for said 10 communications unit, and - providing, responsive to said number, service of a limited duration to said communications unit.
- 10A control unit for processing a service request in a communications system wherein at least part of the service request is encrypted; the control unit comprising:- means for receiving a service request from a communications unit, - means for attempting to authenticate said service request, - means for determining, in response to a failure to authenticate said service request, a number of failures that have previously occurred for said communications unit, and - means for providing, responsive to said number, service of a limited duration to said communications unit.
- 21A method substantially as hereinbefore described and with reference to the accompanying drawing of FIG. 2. 30 22. A device substantially as hereinbefore described and with reference to the accompanying drawings. BNSDOCID:<GB_2332594A__I. RuS Office Application No: GB 9726951.8
Independent claims3
56 paragraphs in 2 sections, as filed
(71) Applicant(s)
Motorola Ireland Limited (Incorporated in Ireland)
Stokes Place, St Stephan's Green, Dublin 2, Ireland (51) (52)
INTCL<sup>6</sup>
HMM 1/66, H04Q 7/32 7/38
UK CL (Edition Q )
H4K KBHG KLL H4L LDSK
Documents Cited
EP 0776141 A2 EP 0602319 A1 (72) Inventor(s)
Timothy David OUriscoB (58) (74) Agent and/or Address for Service Sarah Gibson
Motorola Limited. European Intellectual Property Operation, Midpoint, Alencon Link. BASINGSTOKE, Hampshire, RG21 7PL. United Kingdom
Field of Search
UK CL (Edition P ) H4K KBHG KF42 KLL, H4L LDSK INT CL<sup>6</sup> H04M 1/66. HMQ 7/32 7/38 0NUNE:WPI (54) Abstract Title
Method of processing a service request in a communications system, and control unit for same (57) A method of processing a service request in a communications system wherein at least part of the service request is encrypted. The method comprises the steps of receiving a service request from a communications unit, attempting to authenticate said service request, determining, in response to a failure to authenticate said service request, a number of failures that have previously occurred for said communications unit, and providing, responsive to said number, service of a limited duration to said communications unit. Also described is a control unit for processing a service request.
G>
οσ hO co co σι co
BNSDOCID <GB_2332594A_I_>
METHOD OF PROCESSING A SERVICE REQUEST IN A COMMUNICATIONS SYSTEM, AND CONTROL UNIT FOR SAME
Field of the Invention
The present invention relates to a method of processing a service request in a communications system wherein at least part of the service request is encrypted. The present invention also relates to a control unit for processing a service request in such a communications system.
Background of the Invention
Authentication procedures are employed in communications systems in order to reduce fraudulent use. In a cellular communications system according to the TACS specification (United Kingdom Total Access Communications System), communications units, e.g. mobile telephones, are provided with a mobile identification (mobile ID) and a serial number embedded in the unit. When a request for service is made by such a communications unit, the request for service message includes the mobile ID, the serial number and the number being dialled. This request for service is transmitted to a control unit, for example a mobile services switching centre. The control unit authenticates the request for service by comparing the serial number received from the communications unit with the serial number stored, for that communications unit, in a database of the control unit. Such a procedure has been relatively easily overcome by fraudulent users, who are able to “clone” such a communications unit by capturing the mobile ID and the serial number from the airwaves, and then program these into a “clone” mobile telephone.
In an attempt to protect against such fraudulent use, a procedure has been employed in which the serial number of the communications unit is encrypted using a key. Such a key is sometimes known as a personalidentification-number (PIN) code. This key or PIN code is stored in the communications unit. In this procedure, the request for service includes the mobile ID, the dialled number and the encrypted serial number.
Under such a procedure, authentication of the call by the control unit involves decrypting the encrypted serial number by means of reference to the key or PIN code. Thus for successful authentication the key or PIN code needs to be known by the control unit as well as the communications unit. The key or PIN code is typically known by the control unit by means of being held in a database respective to the mobile ID. Under this procedure requests for service which are successfully authenticated are granted, whereas in the case of unsuccessfully authenticated requests the request is refused and the call fails.
The above described procedure provides a measure of security against fraudulent use. However, it suffers from a disadvantage that a legitimate subscriber can be prevented from making a call if the required key or PIN code is not properly known by the control unit. This situation can arise for various reasons, particularly since a service operator responsible for the control unit is usually different to the supplier of the communications unit. Also, the situation can arise when a subscriber is roaming and sends a request for service message to a control unit operated by a service operator who has not been informed of the subscriber’s key or PIN code.
Brief Description of the Drawings
FIG. 1 is an illustration of a cellular communications system that is in accordance with the present invention.
FIG. 2 is a process flow chart of an embodiment of the present invention.
Description of a Preferred Embodiment of the Invention
FIG. 1 shows a communications unit 101, which in this example consists of a mobile telephone. The communications unit 101 shown comprises a transmitter 105 and receiver 110. Transmitter 105 and receiver 110 are connected to a control component 115 which is connected to a user interface 120. The control component 115 includes memory in which a key 125 is stored. This key is sometimes known as a personal-identification-number (PIN) code. The communications unit 101 transmits a request for service message via a control channel 130.
BNSDOCID: <GB_2332594A_I
The request for service message includes the mobile identification (mobile ID) of mobile unit 101, the number being dialled by the user, and an encrypted serial number comprising the electronic serial number of mobile unit 101 encrypted using key 125. The message is received at a base transceiver station (BTS) 150.
BTS 150 is controlled by a base station controller (BSC) 160. BTS 150 and BSC 160 together form a base station system (BSS) 170. BSS 170 is further connected to a mobile services switching centre (MSC) 195, which carries out, inter alia, call switching. A typical example by way of a MSC 195 is the Motorola product EMX 2500. It is to be understood that the BSS 170 and MSC 195 described in the present embodiment merely represent one way of implementing a message receiving and processing means of a communications system in which the present invention can be employed.
A control unit 180 is provided and serves to attempt to authenticate the service request. In this embodiment control unit 180 is located in MSC 195. It is to be understood that control unit 180 can alternatively be located in other parts of a communications system. For example control unit 180 can alternatively be located in BSS 170. Moreover the control unit can even be constituted of various component parts distributed at more than one location in a communications system.
If a call is successfully authenticated, it can be forwarded, for example from MSC 195 to a public switched telephone network (PSTN), such as PSTN 190 shown in FIG. 1.
The request for service message is processed by control unit 180 according to the process flow chart 200 of FIG. 2. Referring to FIG. 2, function box 205 shows the step of receiving a service request from communications unit 101. In the present embodiment this service request is received by MSC 195 via BSC 160 and BTS 150. Control unit 180, which as explained above is in this embodiment located at MSC 195, carries out the step of attempting to authenticate this service request, as shown in function box 210. Control unit 180 comprises a processor for processing the received
I >
request, and a memory. In the memory is a database comprising the mobile IDs of a plurality of communications units served by the communications system. The database includes for each such communications unit a mobile ID and a record of the corresponding serial number. The database is also supposed to include, for each respective mobile ID, an entry corresponding to the key 125 found in the communications unit. If, for the communications unit making the request for service, all three database entries are present and correct, then control unit 180 is able to perform successful authentication of the service request.
However, if all three entries are not present or not fully correct, then the service request is not authenticated, as shown at decision box 215 of FIG. 2. Such a failure of authentication will often he caused due as a result of there being no record of the key 125 in the database. Alternatively, the record may be present, but incorrect, possibly due to the user of communications unit 101 having changed the key without having informed the service operator. A further alternative is that fraudulent use is being attempted.
In the case of failed authentication, control unit 180 determines whether the particular communications unit, identified by its mobile ID, has previously undergone successful authentication, as shown at decision box
220 of FIG. 2. This is done in the present embodiment by further analysis of the database located in the memory of control unit 180. The database includes for each mobile identity a record of the number of failed authentications that have occurred, and also the number of successful authentications that have occurred previously. These records are updated continuously or periodically.
If the communications unit has previously undergone successful authentication, then service is refused to the communications unit as shown in function box 225 of FIG. 2. This procedure is followed because the circumstances indicate a probable attempt at fraudulent use, i.e. the original communications unit is being used but by an unauthorised user, or alternatively an attempt is being made to use a “cloned” copy of communications unit 101 with an improper key 125. Fraudulent use can be reasonably suspected because the record of earlier successful authentications indicates that the correct key was available earlier.
BNSDOCID: <GB 2332SA4A I
In the circumstances described in the above paragraph, an alternative to refusing service outright is to provide a service of limited scope. This is often known as providing a default service. Such a default service may consist of allowing only emergency calls and/or only calls to a limited number of predetermined telephone numbers.
The present embodiment will now be described in terms of the steps followed when, contrary to the above, the outcome of the determining step shown at decision box 220 of FIG. 2 is that the communication unit had not previously undergone successful authentication. In this event control unit 180 next carries out the step of determining what number of failed authentications have previously occurred for the particular communications unit, as shown in function box 225 of FIG. 2. The number of authentication failures that have occurred is compared to a prerequisite number. In the present embodiment, the prerequisite number is set at one. In other words, in the present embodiment function step 230 determines whether this is the first failure of authentication that has taken place. If this is indeed the case, the next step is that of providing a service of limited duration to the communications unit, as shown at function box 235 of FIG. 2. This is advantageous in that since this is the first failed authentication and since no previous calls have undergone successful authentication, it can be considered likely that the user is the legitimate user. Consequently, providing a full level service but of limited duration is advantageous compared to providing a service of either limited scope or indeed refusing service totally. The limited duration consists of a predetermined period of time, for example one week. The limited duration can alternatively consist of a predetermined number of calls, for example four calls. Yet another alternative is for the limited duration to consist of a predetermined cost of calls. Such a predetermined costs of calls may be set to cover a reasonable number of local calls, but no long distance calls. It will be appreciated that the exact nature of the limited duration set is chosen by the operator of the system according to the standard usage of that system. The nature of the limited duration could also be chosen according to the exact circumstances or details of the legitimate user of a particular communications unit. For example, business users may be permitted a different duration compared to private users.
BNSDOCID: <GB_2332594A.
In the present embodiment, a further step can be carried out, namely that of transmitting information related to said failure to authenticate said service request, to said communications unit, as shown in function box 240 of FIG. 2. One possibility is to transmit the information immediately prior to the enabling of limited duration service. The information may be transmitted in text form or speech form. The information will be related to the authentication failure. It can provide details of the failure that has occurred and an explanation of possible reasons therefor. It may also include information informing the user of the communication unit of steps he may take to remedy the authentication failure. In particular, the user may be directed to telephone a particular telephone number of the service operator. This telephone call may be prompted by an automatic dial facility referred to in the information transmitted.
According to the method described above, a service of limited duration is provided. In order to specify this limited duration, the control unit 180 records the date and time of the authentication failure.
Referring back to function box 230 the case will now be considered when the number of failures is more then the pre-requisite number. Since in this embodiment the pre-requisite number is set at 1, this simply means that the authentication failure is the second or further one to have taken place. In this situation two possibilities arise. The first possibility is that the limited duration previously initiated is still running, i.e. it has not expired. The second possibility is that the limited duration has expired.
The step of determining whether the limited duration has expired is shown at decision box 245 in FIG. 2. Such determination is implemented by standard processing means of the control unit 180, making use of the time and date recorded when the limited duration was initiated, as well as the factor of the particular form or specification of the limited duration. In each particular case the exact means for implementing this is chosen by the operator according to means well known in the art, the choice being dependent inter alia on whether the limited duration is of the predetermined time form, the predetermined number of calls form, or the cost of calls form.
BNSDOCID: <GB_2332594A_I.
If it is determined that the limited duration has expired, then the next step that is performed is that of refusing service to said communications unit, as shown in function box 250. An alternative to refusing service outright is to provide a service of limited scope, which is often known as providing a default service. Such a default service may consist of allowing only emergency calls and/or only calls to a limited number of other predetermined telephone numbers.
Reference is again made to decision box 230 which shows the step of determining whether the number of failures is less than or equal to a prerequisite number. In the embodiment described above, the pre-requisite number was set at 1. However, it is to be appreciated that the present invention can be implemented with a pre-requisite number set to numbers other than one. When the pre-requisite number is set at 2 , for example, this will mean that the user of communications unit 101 will in effect have the limited duration re-set on the second occurrence of authentication failure. This provides even more possibility for the user to make use of the communications unit in the situation that the authentication failure has arisen for legitimate reasons. It will be appreciated that a trade-off exists between on the one hand the provision of service to a legitimate user and on the other hand the level of security against fraudulent use. Indeed, it will be appreciated that in each of the steps of the embodiment described above, such a trade-off is involved. Thus when the present invention is implemented a wide range of choices are available to the system operator for fine tuning such trade-offs, according to the service operator’s particular needs.
Moreover, although the present embodiment relates to an authentication procedure involving a particular example of a mobile ID and an encrypted serial number, the present invention is not limited to such a scenario. It is instead applicable to any authentication procedure of a communications system involving the possibility that a legitimate user has for some reason or other failed to have his call, or other request, successfully authenticated.
In particular, encryption of some parameter or characteristic instead of a serial number is included. Furthermore, the invention is applicable to
BNSDOCID: <GB_2332594A_I.
communication systems in which the communications unit is other than that particularly described in the above embodiment, or wherein the infrastructure of the communication system itself is other then that particularly described above. The present invention is also not limited to an analogue communication system and could be advantageously applied to digital communication systems.
BNSDOCID: <GB_2332594A_I_>
Contents2
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1742411A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1362452A4 | Cited by | European Patent Office (EPO) | Search report |
| EP1362452A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0602319A1 | Cites | European Patent Office (EPO) | Search report |
| EP0776141A2 | Cites | European Patent Office (EPO) | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 9726951 | United Kingdom | A | |
| GB19970026951 | – | – | – |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Patent ceased through non-payment of renewal feeCeasedPCNP | PCNP |
Numbers
- Publication, DOCDB
- 2332594
- Publication, EPODOC
- GB2332594
- Application
- 9726951
- Application, DOCDB
- 9726951
- Application, EPODOC
- GB19970026951
Titles
- English
- Method of processing a service request in a communications system, and control unit for same
Classification
- CPC, 4
- H04W12/06
- H04W12/12
- H04W12/00512
- H04W12/1206