Method and apparatus for encrypting radio traffic in a telecommunications network
Abstract
(57) [Summary] The general purpose communication network (100) provides an encrypted communication interface between the service network (130,132,134) and their subscribers. When communication is initiated between the subscriber communication terminal (118) and the general-purpose network (100), the terminal (118) broadcasts the stored network identifier associated with the stored public key by the general-purpose network (100). Compare with a unique identifier. If they match, the terminal (118) generates a random private key, encrypts the private key with the stored public key, and sends the encrypted private key. The general-purpose communication network (100) decrypts the private key using the private key associated with the public key. The private key is then used by the terminal (118) and the general purpose network (100) to encrypt and decrypt subsequent radio traffic. Therefore, the network (100) can maintain secure communication with the terminal (118) without knowing the identity of the terminal.

Term
Term ended
Projected expiry passed 26 August 2017, 9.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
44 claims: 44 independent, 0 dependent
- 1【特許請求の範囲】 1. 移動通信網と通信端末間の通信トラフィックを暗号化する方法であって 、該方法は、 公開鍵および前記移動通信網に関連する第1の識別子を前記通信端末に保存す るステップと、 前記通信端末に保存された前記第1の識別子を前記移動通信網から受信した第 2の識別子と比較して第1の所定の結果を作り出すステップと、 前記通信端末において秘密鍵を生成するステップと、 前記通信端末において前記秘密鍵を前記保存された公開鍵により暗号化するス テップと、 前記暗号化された秘密鍵を前記通信端末から送信するステップと、 を含む通信トラフィック暗号化方法。
- 2請求項1記載の方法であって、さらに、 前記移動通信網において前記暗号化された秘密鍵を受信するステップと、 前記公開鍵に関連するプライベート鍵により前記受信した暗号化された秘密鍵 を復号するステップと、 前記通信トラフィックを前記秘密鍵により暗号化するステップと、 を含む方法。
- 3請求項1記載の方法であって、公開鍵を保存するステップは公開鍵を先 験的に予め保存するステップを含む方法。
- 4請求項1記載の方法であって、さらに、前記通信端末から公開鍵要求を 受信したら前記移動通信網から前記公開鍵を送信するステップを含む方法。
- 5請求項4記載の方法であって、前記公開鍵を送信するステップは、さら に、前記公開鍵を認証する情報を送信するステップを含む方法。
- 6請求項4記載の方法であって、さらに、前記比較ステップが第2の所定 の結果を作り出したら、前記通信端末から前記要求を送信するステップを含む方 法。
- 7請求項1記載の方法であって、前記暗号化された秘密鍵を受信して復号 するステップは、前記移動通信網内の無線基地局において実施される方法。
- 8請求項1記載の方法であって、前記受信した暗号化された秘密鍵を復号 するステップは、前記移動通信網内の無線網コントローラにおいて実施される方 法。
- 9請求項1記載の方法であって、前記移動通信網は汎用通信網を含む方法 。
- 10請求項1記載の方法であって、前記通信端末は移動端末を含む方法。
- 11請求項1記載の方法であって、前記通信端末は固定端末を含む方法。
- 12請求項1記載の方法であって、前記通信端末は未確認通信端末を含む 方法。
- 13請求項1記載の方法であって、前記移動通信網はセルラー電話網を含 む方法。
- 14請求項1記載の方法であって、さらに、 複数のサービス網を前記移動通信網に接続するステップであって、前記通信端 末のユーザは前記複数のサービス網の少なくとも1つの加入者であるステップと 、 前記通信端末と前記複数のサービス網の少なくとも1つとの間に通信パスを提 供するステップと、 を含む方法。
- 15請求項1記載の方法であって、前記プライベート鍵および前記公開鍵 はRSAアルゴリズムにより関連づけられる方法。
- 16請求項1記載の方法であって、前記秘密鍵は対称暗号鍵を含む方法。
- 17請求項1記載の方法であって、秘密鍵を生成するステップは自然発生 乱数を発生するステップを含む方法。
- 18請求項1記載の方法であって、秘密鍵を生成するステップは、 前記通信端末においてデジタル形式の受信信号を検出するステップと、 前記検出された受信信号から少なくとも1つの低位ビットを抽出するステップ と、 を含む方法。
- 19請求項1記載の方法であって、秘密鍵を生成するステップは、 マイクロホンA/Dコンバータの出力において信号を検出するステップと、 前記検出された出力信号から少なくとも1つの低位ビットを抽出するステップ と、 を含む方法。
- 20請求項1記載の方法であって、秘密鍵を生成するステップは、 音声コーディックの出力において信号を検出するステップと、 前記検出された出力信号から少なくとも1つの低位ビットを抽出するステップ と、 を含む方法。
- 21請求項1記載の方法であって、秘密鍵を生成するステップは、 擬似乱数のシードを発生するステップと、 前記シードから擬似乱数を発生するステップと、 を含む方法。
- 22請求項1記載の方法であって、前記秘密鍵の長さは前記通信端末にお いて予め決定される方法。
- 23請求項1記載の方法であって、前記秘密鍵はさらに複数の連接された 数字を含む方法。
- 24請求項1記載の方法であって、前記公開鍵および前記第1の識別子を 保存するステップはさらに前記公開鍵に関連する期限日付を保存するステップを 含む方法。
- 25請求項24記載の方法であって、前記通信端末は前記公開鍵の期限が 切れると前記移動通信網へ公開鍵要求を送信する方法。
- 26請求項1記載の方法であって、さらに、 前記移動通信網において前記公開鍵を変えるステップと、 前記通信端末において前記変えられた公開鍵を保存するステップと、 を含む方法。
- 27請求項26記載の方法であって、前記公開鍵を変えるステップは、さ らに、前記変えられた公開鍵を前記移動通信網から所定期間ブロードキャストす るステップを含む方法。
- 28汎用通信網と第1の通信端末との間でトラフィックを暗号化する方法 であって、該方法は、 前記汎用通信網から前記第1の通信端末を含む複数の通信端末へ公開鍵をブロ ードキャストするステップと、 前記第1の通信端末において秘密鍵を生成するステップと、 前記第1の通信端末において前記秘密鍵を前記公開鍵により暗号化するステッ プと、 前記暗号化された秘密鍵を前記第1の通信端末から送信するステップと、 前記汎用通信網において前記暗号化された秘密鍵を受信するステップと、 前記受信した暗号化された秘密鍵を前記公開鍵に関連するプライベート鍵によ り復号するステップと、 前記トラフィックを前記秘密鍵により暗号化するステップと、 を含む方法。
- 29請求項28記載の方法であって、ブロードキャストするステップは、 さらに、 前記公開鍵を無線網コントローラから前記汎用通信網内の少なくとも1つの基 地局へ転送するステップと、 前記公開鍵を前記少なくとも1つの基地局から送信するステップと、 を含む方法。
- 30請求項28記載の方法であって、ブロードキャストするステップは、 前記公開鍵を前記汎用通信網内の複数の基地局から送信するステップを含む方法 。
- 31請求項28記載の方法であって、前記第1の通信端末は未確認通信端 末を含む方法。
- 32請求項28記載の方法であって、前記公開鍵をブロードキャストする ステップは、さらに、前記公開鍵を認証する情報をブロードキャストするステッ プを含む方法。
- 33請求項28記載の方法であって、前記公開鍵をブロードキャストする ステップは、さらに、前記公開鍵を認証する情報を要求に応じて送信するステッ プを含む方法。
- 34移動通信網と通信端末間の通信トラフィックを暗号化する方法であっ て、該方法は、 ディフィ-ヘルマン指数鍵交換アルゴリズムに関連する2つの数字および前記 移動通信網に関連する第1の識別子を前記通信端末において保存するステップと 、 前記通信端末に保存された前記第1の識別子を前記移動通信網から受信した第 2の識別子と比較して第1の所定の結果を作り出すステップと、 前記通信端末において第1の乱数を発生するステップと、 前記移動通信網において第2の乱数を発生するステップと、 前記第1および第2の乱数を前記ディフィーヘルマン指数鍵交換アルゴリズム への入力として使用して、前記通信端末および前記移動通信網により秘密鍵とし で使用される第3の数字を発生するステップと、 を含む通信トラフィック暗号化方法。
- 35請求項34記載の方法であって、2つの数字を保存するステップは前 記2つの数字を先験的に予め保存するステップを含む方法。
- 36請求項34記載の方法であって、さらに、前記通信端末から前記2つ の数字に対する要求を受けたら前記移動通信網から前記2つの数字を送信するス テップを含む方法。
- 37請求項36記載の方法であって、さらに、前記比較ステップが第2の 所定結果を生じたら前記通信端末から前記要求を送信するステップを含む方法。
- 38請求項34記載の方法であって、前記2つの数字および前記第1の識 別子を保存するステップは、さらに、前記2つの数字に関連する期限日付を保存 するステップを含む方法。
- 39請求項38記載の方法であって、前記2つの数字の期限が切れると、 前記通信端末は前記ディフィ-ヘルマン指数鍵交換アルゴリズムに関連する2つ の新しい数字に対する要求を送信する方法。
- 40請求項34記載の方法であって、さらに、 前記移動通信網においてディフィ-ヘルマン指数鍵交換アルゴリズムに関連す る前記2つの数字を変えるステップと、前記通信端末において前記変えられた2 つの数字を保存するステップと、を含む方法。
- 41請求項40記載の方法であって、前記2つの数字を変えるステップは 、 さらに、前記変えられた2つの数字を前記移動通信網から所定期間ブロードキャ ストするステップを含む方法。
- 42汎用通信網と第1の通信端末間のトラフィックを暗号化する方法であ って、該方法は、 指数鍵交換アルゴリズムに関連する2つの数字を前記汎用通信網から前記第1 の通信端末を含む複数の通信端末へブロードキャストするステップと、 前記第1の通信端末において第1の乱数を発生するステップと、 前記汎用通信網において第2の乱数を発生するステップと、 前記第1および第2の乱数を前記指数鍵交換アルゴリズムへの入力として使用 して、前記第1の通信端末および前記汎用通信網により秘密鍵として使用される 第3の数字を発生するステップと、 前記トラフィックを前記秘密鍵により暗号化するステップと、 を含む方法。
- 43汎用通信網と通信端末間のトラフィックを暗号化する方法に使用する システムであって、該システムは、 前記汎用通信網内に含まれるアクセス網と、 前記通信端末に接続されかつ前記アクセス網と関連づけられて、前記汎用通信 網に関連する公開鍵を保存し、秘密鍵を生成し、前記秘密鍵を前記保存された公 開暗号鍵により暗号化し、前記暗号化された秘密鍵を前記汎用通信網へ送信する アクセス網手段と、 を含むシステム。
- 44汎用通信網と通信端末間のトラフィックを暗号化するシステムであっ て、該システムは、 プライベート暗号鍵を保存し、公開暗号鍵を配送し、暗号化された秘密セショ ン鍵を復号する第1のネットワーク手段と、 前記第1のネットワーク手段に接続されて前記配送された公開暗号鍵をブロー ドキャストする第2のネットワーク手段であって、前記第1および第2のネット ワーク手段は前記汎用通信網のアクセス網と関連づけられている前記第2のネッ トワーク手段と、 前記通信端末に接続されかつ前記汎用通信網の前記アクセス網と関連づけられ て、前記ブロードキャストされた公開暗号鍵を受信し、秘密鍵を生成し、前記秘 密鍵を前記受信した公開暗号鍵により暗号化し、前記暗号化した秘密鍵を前記汎 用通信網へ送信するアクセス網手段と、 を含むシステム。
Independent claims44
2 paragraphs, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
Wireless traffic encryption methods and devices in telecommunications networks Background of the invention Technical field of invention The present invention generally relates to the field of wireless wireless communication, in particular terminals and mobile wireless networks. It relates to a method and a device for encrypting wireless traffic between them. Description of related technology Network due to the need for greater mobility and flexibility in telecommunications networks Ku subscribes to a wider range of telecommunications services covering larger geographic areas Need to provide to. These telecommunications services include teleservices and bears Ra service is included. Teleservice communicates with another subscriber (eg terminal, etc.) Provide the necessary hardware and software to the subscribers who make the trust. Bearer The service is two access points that provide an interface to the network It provides the capacity needed to transmit the appropriate signal between ports (eg, ports). Den Qi communication services include, for example, public land mobile telecommunications network (PLMN) and public exchange telecommunications. Talk network (PSTN), Integrated Services Digital Network (ISDN), so-called inter) -Net "access network, video on demand (VOD) network, and other suitable services It is provided to subscribers through several service networks such as the network. New mobile wireless telecommunications network in response to the need for greater mobility and flexibility Has been developed and it allows service network subscribers regardless of their geographic location. It has a generic interface that can be connected to a service network. This general-purpose access network is the Generic Access Network (G) It is called AN). Mainly for encrypting communication traffic between terminals and GAN To more easily understand the invention in question, then with respect to FIG. A brief description of N. Figure 1 shows a typical GAN connected to multiple service networks and service network subscribers. It is a perspective view of. GAN (10) shown in Figure 1 is interconnected with the transport network Includes access networks. The access network has multiple base stations (eg BS1 and BS2) is included. Each base station is in each geographical area (eg, so-called cell, C Includes wireless transmitters and receivers that provide communication coverage for 1 and C2) I'm sorry. The base station is connected to the radio network controller (RNC) 12. Explicit Not, but some base stations connect to RNC12 (eg BS1 and BS2) And another base station can be connected to one or more other RNCs. Multiple A number of RNCs can be interconnected to provide a communication path between them. Multiple service networks (eg VOD network, PLMN, PSTN, Internet ) Is each access input port (14,16,18,20,22,24 and 26) It is connected to the access network of GAN10 via. Each service network is its own standard Communicate between its internal signaling nodes using a signaling protocol .. For example, Gl, a digital cellular PLMN actually used throughout Europe obal System for Mobile communication (GSM) is Multiple Application Part (MAP) You are using a signaling protocol. As shown in Figure 1, R in the access network NC is connected to the service network through at least one access input port To. As you can see from the figure, RNC12 has access ports 20 and 2, respectively. It is connected to the PLMN and PSTN service networks via 4. There are mobile terminals 28 and 30 in the wireless coverage area of GAN10. Establish a connection with each base station (eg BS2) in the Seth network. These mobile terminals For example, cellular phones, mobile wireless phones, and perhaps digital cellular phones A personal computer (notebook, laptop, etc.) connected to the machine, or a mobile device It can be a Levi receiver (for VOD). Mobile terminal and selected sir The signal transfer between the screw networks is performed via a specific signal carrier. For example, the signal is Signal carrier SC1 and between the ruler telephone (28) and the PLMN service network Transferred via SC2. Mobile terminals (eg, 28 and 30) include access units and service network units. I'm out. The access part of the mobile terminal is the logical part of the access network, and the mobile terminal and RNC Required to establish signal carriers with 12 (eg SC2 and SC4) Signaling The user of the mobile terminal subscribes to the service network unit of the mobile terminal. It is the logical part of the service network. The service network unit of mobile terminals is the related service. Established signal carriers SC1 and SC2 (if Or send and receive signals via SC4). Signal carriers SC2 and SC4 (transfer) The wireless interface section (between the mobile terminal and the base station) is a time division multiple access (TDMA). ), Code division multiple access (CDMA), or any other type of multiple access interface It can be a chair. Service network subscribers can access each service network via GAN. Wear. GAN is a signal carrier between the service network unit of mobile terminals and the service network. Transfer messages transparently via (eg SC1 and SC2) It provides a signal carrier interface that can be sent. GAN on it Signaling connections and traffic connections for all connected service networks This function is achieved by matching the characteristics of the action. Therefore, GAN is an existing Increased coverage of the service network and increased subscriber mobility .. A unique feature of GAN is that it does not have its own subscribers. GAN Moba Ilusers are permanent subscribers to their own service network, but of GAN It is only a temporary user. Therefore, GAN is the eye of these users I don't know (or don't need to) dentity. However, the moving end Problems arise when trying to encrypt the radio traffic between the terminal and the GAN. Wireless traffic (for example, voice information and data) between mobile terminals and base stations is transmitted. Typically encrypted to ensure that the information passed is kept confidential .. Some service networks (eg GSM) encrypt traffic, but most others Service network is not encrypted. Therefore, GAN is a service network that does not have that capability. Must be able to encrypt traffic to. However, GAN Since the identity of the user (service network subscriber) is not known, the subscriber end Wireless trough using cryptographic keys generated without knowing the end identity or authentication You must be able to encrypt the IC. Unfortunately, most existing mobile wireless networks You are using a cryptographic technique that uses authentication parameters to generate a cryptographic key. Paraphrase Re For example, in order to encrypt wireless traffic in a conventional mobile communication network, the eye of the user terminal You have to know the dentity. Abstract of the invention Mobile terminal and communication network without the need for the network to know the identity of the terminal It is an object of the present invention to encrypt communication between the two. Multiple migrations without the need for the network to maintain a separate encryption key for each terminal It is also an object of the present invention to encrypt the communication between the mobile terminal and the communication network. Communication between the mobile terminal and the communication network without the need for the terminal to permanently store the private encryption key Is another object of the present invention. While encrypting the communication between the mobile terminal and the communication network, the call opening time is minimized and the communication is transmitted. It is the present invention to minimize the feed delay and maximize the data throughput. Yet another purpose. According to one feature of the present invention, a network-related public key is placed on the terminal. Save, generate a secret key on the terminal, and on the terminal Encrypt the private key with the saved public key, send the encrypted private key from the terminal, The encrypted private key is received at the terminal, and the received encrypted private key is private. Decrypt with private key, private key is related to public key It is connected and communicates with the communication network by encrypting subsequent traffic with a private key. A method of encrypting communication between communication terminals is provided. The public key is not stored on the terminal If not, the terminal sends a public key request to the network. In this way, Netwa Knows the identity of the device to maintain encrypted communication with the device No need. According to another feature of the present invention, the above-mentioned purpose and other purposes are netted. A tiger between the communication network and the communication terminal by broadcasting the (asymmetric) public key from the work Achieved by methods and devices that encrypt the Fick. Public key received by terminal Be trusted. The network can be used to decrypt information encrypted with a public key Keep your private key. The terminal uses a naturally occurring random number as a secret session (symmetric) key Generated and saved, encrypted the symmetric session key with the public key, and encrypted it. Send the key to the network. The network is a session key with a private key Is decrypted, and both the network and the terminal encrypt the subsequent communication with the secret session key. To become. Here, too, the communication network is used to maintain encrypted communication with the terminal. You don't need to know the identity. A brief description of the drawing The method and apparatus of the present invention can be understood more completely by reading the following detailed description together with the attached drawings. Can be understood, here, Figure 1 shows a typical general purpose network connected to multiple service networks and service network subscribers. Perspective view of the access net. FIG. 2 shows a service network and a service network subscriber according to a preferred embodiment of the present invention. General purpose access that can implement a method of encrypting wireless traffic between Top level schematic block diagram of the net. Figure 3 is a schematic block diagram of the access network shown in Figure 2. FIG. 4 shows wireless communication between a general-purpose access network and a terminal according to a preferred embodiment of the present invention. A sequence diagram showing the methods that can be used to encrypt the message. FIG. 5 shows the public key authentication and key owner according to a preferred embodiment of the present invention. A block diagram of the methods that can be used to prove by digital signature. Detailed description of the drawing Preferred examples of the present invention and their advantages can be well understood by looking at FIGS. 1 to 5. And similar corresponding parts in different drawings are numbered the same ing. In essence, according to the preferred embodiment of the present invention, the mobile terminal is at least one public. Open key with at least one GAN unique identification character associated with it Save to memory location. GAN has its unique knowledge of all cells connected to it Broadcast another character. There is a contact between the terminal and its GAN When started, the terminal compares the received identifier with the stored identifier and if it matches Generate a random private key and use the public key associated with that GAN identifier to generate the private key Encrypt and send the encrypted private key. GAN is a private key related to public keys Decrypt the private key using the key. The private key then encrypts subsequent radio traffic Used by terminals and GANs to convert and decrypt. GAN is a terminal It turns out that you can ensure secure communication with the terminal without knowing the identity. There will be. Moreover, GAN does not need to know the identity of such terminals Therefore, it is not necessary to maintain a database of individual terminal encryption keys. In addition, the terminal Keeps its own private key as it can generate a new private key for each communication session It doesn't have to exist. FIG. 2 shows between the service network and the service network subscribers according to a preferred embodiment of the present invention. Of a general purpose access network that can implement a method of encrypting wireless traffic It is a top-level schematic block diagram. GAN100 is illustrated and the access network Includes transport network 102 interconnected with 104. Multiple services The network (eg PLMN, ISDN, PSTN, INTERNET, VOD) Each access port (eg 106,108,110,112,114) It is connected to the transport network 102 and the access network 104 via. A The access network 104 includes multiple RNCs and associated base stations (eg, RNC (1)- Contains RNC (N)). Multiple RNCs and associated base stations are on each radio in Multiple mobile transceivers (terminals) 116,118,120 depending on the surface And 122 are connected. Each mobile terminal user has at least one service It is a subscriber to the network PLMN, etc. Mobile terminals are those in the manner described above with respect to FIG. It is possible to communicate with each service network of. In particular, RNC is a terminal and each of those sir Controls communication between screw networks. Figure 2 shows multiple mobile terminals (116, etc.) But it's just an explanation. One or more fixed wireless terminals are also GAN1 Can connect to 00 and therefore communicate with at least one service network be able to. FIG. 3 is a schematic block diagram of the access network 104 shown in FIG. Access network 104 Contains multiple RNCs (eg RNC (1) -RNC (N)). This implementation Although multiple RNCs are illustrated in the example, the present invention is practiced with only one RNC. be able to. At least one service network (eg 130,132,134) ) Is at least one access port (eg AP1, AP (N-1), A) It is connected to at least one RNC via P (N)). At least one Base stations (eg BS (1), BS (N)) are each RNC (eg RNC) It is connected to (1), RNC (N)). Multiple base stations are shown, The present invention can be implemented in only one base station. Mobile terminals (eg, cellular phones 118) are based on wireless interfaces It is connected to the local station BS (1). One terminal (118) is just for explanation It is easy to see that one or more terminals can be illustrated with. RNC (eg For example, RNC (1) -RNC (N)) is a communication line (136) for communication between them. , 138) are interconnected. Therefore, the terminal 118 is the access network 1 Any service network via 04 and GAN100 (Figure 2) (eg 130, Communication with 132,134) can be established. Access network 104 The power provided to each service network by switching to the Mana access port You can see that the valage can be expanded. That is, the terminal 118 is RNC ( 1), with service network 132 via interconnect line 136 and RNC (N-1) Can communicate. Alternatively, the service network 132 is the access port AP (1). ), Terminal 118 and service network 132 via RNC (1) Can communicate. FIG. 4 shows wireless communication between a general-purpose access network and a terminal according to a preferred embodiment of the present invention. It is a sequence diagram which shows the method which can be used to encrypt a message. Communication encryption method The 200 can be started at the GAN or the terminal. For example, this embodiment So, in step 204, GAN (eg 100) is all connected to it. Continuously broadcast unique identification characters in all cells. Terminal ( For example, 118) includes a non-volatile memory located in its GAN section. end At the end, it stores at least one public key in non-volatile memory. With each public key In addition, the terminal identifies each expiration date of the key, and the specific GAN associated with that key. The identification character is also saved. That is, each publication stored in the memory of the terminal The key is associated with a particular GAN. The terminal registers with GAN (not necessarily open call) Contact is started by not setting). The processor in the terminal receives the G Compare the AN identifier with the stored identifier and if they match (and the key has expired) The processor searches for the stored public key associated with the identified GAN. To. However, if they do not match, the terminal sends a public key transmission request to GAN. The sent public key (and its expiration date) is stored in the terminal now and later It can be used to encrypt the private key in the continuation communication session. In step 206, the terminal generates a (symmetrical) private key (discussed below). Su At Tep 208, the terminal uses the retrieved public key to encrypt the private key. In step 210, the terminal sends the encrypted private key to the identified GAN. At step 212, GAN decrypts the private key, which is done at step 214. To the GAN and terminal to encrypt traffic during subsequent communication sessions More used (see below). Alternatively, at the end of the session with GAN, the terminal used the public for that session. Save the unlocked key. When the terminal or GAN starts a new communication session, the terminal Searches for the saved public key from the last session with GAN and uses that public key And encrypt the private key used for subsequent sessions. Use of that stored public key If is unsuccessful, the terminal sends a new public key request to GAN. Network This technology allows networks because the channel is not dedicated to sending public keys. Luput increases favorably. However, past sessions with a particular GAN If the public key is not saved from, the terminal still requests GAN for the public key. Can be received and used to encrypt the private key used for subsequent sessions can do. Either way, it's relatively large (bit-wi: bit-wi) se) By storing the public key in the terminal instead of sending it from GAN, nothing Significantly reduces line transmission delays, saves a considerable amount of network transmission time, and saves data Throughput can be increased. FIG. 4 shows between a general purpose access network and a mobile terminal according to another embodiment of the present invention. The methods that can be used to encrypt wireless communications are also illustrated. For example, service If you want to communicate between the network and the terminal (for example, PLMN and terminal 118), service The network or terminal can start communication with the call opening message. Step In P202, when the initial connection between GAN and the terminal is established, the service network will be later. Subsequent traffic can be required to be encrypted. If so, In Tep 204, the terminal is still in the initial call opening process with one or more base stations ( For example, a public broadcast continuously from BS (1) -BS (N)) Receive the key. In this example, all RNCs have at least one public / private key pair ( The same pair in each RNC) can be kept in memory storage location. By GAN The broadcast public key is the terminal that started contact with the GAN (1) Received by 18). Preferably, both the call opening procedure and the public key transfer procedure Implemented by RNC, it is through the access port of the service network (eg, for example) , RNC (1) to AP (1) to PLMN130). Yes The base station (eg BS1) keeps the public / private key pair and ends the public key It can be configured to be broadcast or otherwise forwarded to the end. RNC broadcasts the public key in all cells within its coverage area can do. Therefore, GAN causes the terminal to request the key from GAN. The terminal registers with GAN faster because it broadcasts the public key instead of You can open a call in a fairly short time. Alternatively, multiple centers Instead of broadcasting the public key within the terminal, RNC makes contact with the terminal. The public key can be transferred directly via an established base station. However , GA by broadcasting the public key into multiple cells before opening a call The load on N dedicated traffic channels can be reduced advantageously. For all examples, the same key will be used in GAN as long as the terminal is registered in GAN. And because it is stored on the terminal, use the same public key for all subsequent communications with that GAN can do. Alternatively, according to a given method or algorithm, or G The public key can be changed periodically at the initiative of the AN operator. Operate If the user wants to change the public key periodically, store the expiration date of each public key in the terminal. And their use in connection with it will be easier. Further, in a preferred embodiment, publication When the key is changed, it will be broadcast by the fixed period GAN and the terminal will be renewed. The number of requests for a private key can be minimized. As mentioned above, in step 202, GAN is one or more asymmetric public keys. / Can maintain a private key pair. In that case, the so-called "RSA Al" You can use "Gorism" to generate public / private key pairs RS. The A algorithm causes difficulty in factoring prime numbers and large prime numbers (probability algorithm) Divide the encryption key into public and private parts in combination with ease (using rhythm) Release. In particular, the letters P and Q represent prime numbers, the letters M represent unencrypted messages, and statements. Assuming that the letter C represents the encryption form of M, the RSA algorithm can be represented by the following equation. I can do it. M<sup>E</sup>modPQ => C (encrypted message M) (1) C<sup>D</sup>modPQ => M (decryption message C) (2) Here, the (DE-1) term is a multiple of (P-1) (Q-1). In this embodiment The index E is set to 3. Public and private keys each consist of two numbers Has been done. For example, the numbers represented by (PQ, D) make up the private key, The numbers represented by (PQ, E) make up the public key. The same value for E is consistent Because it is used, only the PQ part of the number is sent upon request or broad key Can be cast and used as a public key (eg, in step 204) .. Any message encrypted with the public key by knowing the private key Can also be decrypted. Returning to FIG. 4, in step 206, the terminal (118) receives the asymmetric public key. Confidence and / or save. The terminal generates a random symmetric private key. Complete communication Four random private keys are used to preferably encrypt all sessions It can be generated by at least one of the methods. Use one method Then, the terminal takes some samples from the strength measurement of the received signal, and below that. The place bits are concatenated and the result is processed to generate a random number. The least significant bit of the received signal is ten Because it is within that noise level, a naturally occurring true random number is generated. Second The random number generation method is generated at the input of the A / D converter connected to the microphone. Use a random noise signal. Again, using this method, the secret It is possible to generate a true random number that naturally occurs for a secret key. How to generate the third random number The method takes a sample from the phase measurement of the received signal for the terminal and sets the lower bits. It is to connect and process the result to generate a random number. The fourth random number generation method is the terminal A sample is taken from the coding part of the voice codec, and the lower bits are connected. It is to touch and process the result to generate a random number. Alternatively, use the random number generated at the terminal as a seed for the pseudo-random number generator. can do. The seed is encrypted with the public key from GAN and sent to GAN Be done. Seeds are used simultaneously in GAN and terminals to generate pseudo-random numbers. The pseudo-random numbers generated in this way are used by the GAN and the terminal for subsequent communication sessions. Can be used as a private key. The session key can be periodically changed to a different number in the pseudo-random sequence. example For example, the session key is used after a certain amount of data is encrypted or when the traffic is a certain amount. It can be changed for several reasons, such as after inter-encryption. Terminal if Or GAN can initiate a change of private key, or a given method or algo You can change the key according to the rhythm. For example, a request to change the secret session key Sends a "session key change request" message, or of the sent message It can be executed by setting the "section key change request" bit in the header. Furthermore, a shorter session key is generated by the pseudo-random number generation method described above. You can use a non-complex encryption algorithm. Therefore, GAN A considerable amount of processing power can be saved, especially in terminals. With security The terminal is used for the length of the session key to make a trade-off with the calculation request. Can be configured to select. For example, the processor of a terminal is its length Now generate a session key or use it from the output of a pseudo-random number generator The length of the secret session key can be selected by specifying the number of keys. Ah In other words, the terminal can specify the output range of the pseudo-random number generator and set the predetermined length. Wear. Another method can be used to generate a pseudo-random number for the secret session key .. For example, a Lagged Fibonacci type pseudo Using a similar random number generator, the nth number N in the pseudo-random number sequence<sub>n</sub>Is calculated as follows be able to. N<sub>n</sub>= (N<sub>nk</sub>-N<sub>n-1</sub>) modM (3) Here, k and l are so-called delays, and M defines the range of pseudo-random numbers generated. Determine. Maximum delay must be between 1000 and 10000 for optimal results Not. If a relatively long key is desired, multiple pseudos created by Equation 3 Random numbers can be concatenated to create longer keys. Pseudo created by Equation 3 Set M to 1 if the similar random number is a floating point number between 0 and 1. Can be done. Such a floating-point pseudo-random number bit pattern is used as a symmetric encryption key. Can be used. Another pseudo-random number generator that can be used to generate a secret session key is 0 and 1 It is based on an algorithm that produces pseudo-random numbers that are evenly distributed between and. Special To, pseudo-random number N<sub>n</sub>Seed X<sub>o o</sub>, Y<sub>o o</sub>And Z<sub>o o</sub>To an integer value between 1 and 30000 Initially set. Next, the pseudo-random number is calculated as follows. X<sub>n</sub>=171<sup>*</sup>(X<sub>n-1</sub>mod177)-(2<sup>*</sup>X<sub>n-1</sub>/ 177) (4) Y<sub>n</sub>=172<sup>*</sup>(Y<sub>n-1</sub>mod176)-(35<sup>*</sup>Y<sub>n-1</sub>/ 176) (5) Z<sub>n</sub>=170<sup>*</sup>(Z<sub>n-1</sub>mod178)-(63<sup>*</sup>Z<sub>n-1</sub>/ 178) (6) X<sub>n</sub>, Y<sub>n</sub>And Z<sub>n</sub>If each value of is less than zero, then X<sub>n</sub><sub></sub>Is X<sub>n</sub>Set equal to +30269, Y<sub>n</sub>Is Y<sub>n</sub>Set equal to +30307 , Or Z<sub>n</sub>Is Z<sub>n</sub>Set equal to +30323. Pseudo-random number N<sub>n</sub>Is ((X<sub>n</sub>/ 30269 + Y<sub>n</sub>/ 30307 + Z<sub>n</sub>/ 30323) equal to amodl) X<sub>n</sub>, Y<sub>n</sub>And Z<sub>n</sub>Is a floating point number and amod is due to these numbers It means that it can be factored. Floating point numbers generated by this algorithm The characters form a bit pattern suitable for use as a symmetric encryption key. like this The key length can be extended by concatenating a plurality of generated pseudo-random numbers. Returning to the method shown in FIG. 4, in step 208, preferably the RS described above. Using the A algorithm, the terminal encrypts the secret symmetric key with the public key. For example , The secret symmetric key generated in the terminal shall be represented by the letter SK. RSA Using Equation 1 of the algorithm, the private key is encrypted as follows: M<sup>E</sup>modPQ => C Here, (PQ, E) represents the public key, M is equal to SK, and C is the encryption bar of SK. -John. The index E is equal to 3. In a preferred embodiment, the terminal message-formatted the encrypted private key. , It contains headers and message fields. Header is Messe -Provides control information related to the encrypted private key that follows in the field. He One bit in the header is that the message field following the header is encrypted Can be set to display. That is, the secret key fee for the message Only Ludo is encrypted. Message headers are sent in plain text. Therefore The header indicates whether the subsequent message field is encrypted and is dark. When it is issued, only that part of the message is decrypted, so it smells like RNC. It can save a considerable amount of network processing time. In step 210, the terminal (118) contours the encrypted private key (C). It is sent to GAN via the base station (for example, BS (1)). Preferred Examples Then, this private key is used for subsequent communication. Alternatively, the subsequent communication session At any time inside, the terminal generates a new private key and encrypts it with the public key. , A new encrypted private key can be sent to GAN. Specific private key is set Private keys are not allowed by reducing the amount of time used for The likelihood of being destroyed by the is also reduced, increasing the security of the session. .. In step 212, the RNC (eg, RNC (1)) is encrypted from the base station. Receives the converted private key (C) and uses the private key part of the RSA algorithm. Decrypt the private key with. For example, using Equation 2 (above) of the RSA algorithm, The received encrypted private key (C) is decrypted as follows. C<sup>D</sup>modPQ => M Here, (PQ, D) represents the private key, and M is equal to SK (private key). In step 214, subsequent radio traffic between the RNC and the terminal becomes the private key. More encrypted and decrypted, which is currently known to both RNCs and terminals .. Using known symmetric encryption algorithms, for example, 1,2 or 3 pass D ata Encryption Standard (DES) algorithm, also Or Fast Encipherment Algrorithm (FEAL) ) Etc. can be used to encrypt and decrypt subsequent radio traffic .. Yet another encryption, publish / ply using the RSA algorithm Instead of generating a Bate key pair, the so-called Diffie-Hellmann "exponential key exchange" a You can use the algorithm to get the device and GAN to accept the secret session key. Wear. When using this encryption method, two numbers (α, q) are in the GAN It will be saved. At the start of the communication session, RNC sends two numbers directly to the terminal ( Or broadcast the numbers). The numbers α and q meet the following criteria: Need to be. q determines the (Galois) finite field GF (q) = 1,2, ..., q-1 It is a large prime number, and α is a fixed primitive element of GF (q). element). That is, (α<sup>X</sup>The index (X) of modq) is GF (q) ) Creates all the elements 1,2, ..., q-1. Generates acceptance of secret session key In order to do so, the two numbers (α, q) are sent directly from the GAN to the terminal (or maybe). Will be broadcast). Alternatively, the two numbers are the terminal's non-volatile memory Can already be resident in. The terminal (118) is a random number X<sub>T</sub>(1 <X<sub>T</sub><q-1) Occurs and Y<sub>T</sub>= α<sup>X</sup><sub>T</sub>Calculate the value of modq. GAN (for example, RNC or Is a base station) is a random number XG (1 <X)<sub>G</sub>Generate <q-1) and Y<sub>G</sub>= α<sup>X</sup><sub>G</sub>The value of modq calculate. Random numbers are naturally generated, terminals using the method described above for true random number generation Can occur in. Y<sub>T</sub>And Y<sub>G</sub>Is transferred to each GAN and terminal unencrypted. Number Y<sub>G</sub>To When receiving, the terminal is K<sub>S</sub>= Y<sub>G</sub><sup>X</sup><sub>T</sub>modq = α<sup>X</sup><sub>G</sub><sup>X</sup><sub>T</sub>Calculate the value of modq. Number Y<sub>T</sub>When you receive, GAN is K<sub>S</sub>= Y<sub>T</sub><sup>X</sup><sub>G</sub>modq = α<sup>X</sup><sub>T</sub><sup>X</sup><sub>G</sub>Calculate the value of modq .. X<sub>T</sub>The number is kept secret on the terminal, X<sub>G</sub>Numbers are secret in GAN Remained, but K<sub>s</sub>The value of is now known on both the terminal and the GAN. did K<sub>S</sub>The number in is used by both parties as a communication session encryption key. Permitted X for users who cannot<sub>T</sub>Or X<sub>G</sub>Y without knowing any of<sub>T</sub>And Y<sub>G</sub>From key K<sub>S</sub>Total You have to calculate, which is an unmanageable calculation process. Index key exchange algorithm The significant security advantage of using Zum is that GAN is a secret private There is no need to maintain key data on a permanent basis. In summary, when the communication session is first started between the GAN and the terminal, the terminal Is continuously broadcast by GAN and retrieved from the terminal's internal memory Or receive the asymmetric public key requested by GAN. GAN is the public key Maintain a private key that can be used to decrypt information encrypted by. The terminal generates and stores a naturally occurring random number as a secret session (symmetric) key, and stores it as a symmetric key. Yo Encrypt the key with the public key and send the encrypted session key to GAN. GAN Decryption of session key with private key, both GAN and terminal communicate subsequent Is encrypted with the secret session key. Transfer the public key from GAN to the terminal at the start of communication The main technical advantage of sending is that GAN encrypts the communication with the terminal. You don't have to know your last identity. However, it is not allowed Problems arise when a new user attempts to send a public key to a terminal under the guise of GAN. On the spot In that case, as described below, the terminal receives the public key and GAN identity. Can be configured to authenticate. For example, when the public key is transferred from GAN to the terminal, the key becomes the public key "certificate". Can be transferred more. This certificate is booked by the relevant public key and its owner It is proof that it is a thing. "Trusted" third party certifies public key Can be published together, it has a third party identity and It contains a "digital signature" that authenticates the public key. The certificate is also of GAN If the identity and certificate have an expiration date, they can also be included. In one aspect of the invention, GAN sends the certificate and public key to the terminal. So In the case of, the third-party public key is pre-stored on the subscriber terminal (a priori). FIG. 5 shows the authentication of the public key and its owner by digital signature according to the present invention. It is a block diagram of a method that can be used to prove. For public key certificate The method of digitally signing and verifying its authentication (300) begins in step 302. Is done. Cryptography of the owner of the public key transferred to the terminal in step 302 A "certificate" containing unaltered information is prepared by a trusted third party Is done. Unencrypted information also includes public key and certificate expiration. Ste In P304, the "unsigned" certificate is an irrevocable algorithm (eg, c). Processing algorithm) and message die in step 306 A gest is created, which is a digest of the information contained on the certificate, ie It is a shortened version. In step 308, the digest information is different public Encrypted by the private key of the open / private key pair. Preferably, said This key pair is derived using an RSA algorithm similar to Equations 1 and 2. Therefore, in step 310, the original unencrypted information (communication security). (Including the public key used for the certificate) and the private key of the certificate issuer A digitally signed public key certificate containing the currently encrypted digest information Be created. Next, the digitally signed public key certificate should contact GAN. Transferred to the starting terminal. Upon receiving the digitally signed certificate in step 312, the device pro Sessa parses the unencrypted and encrypted parts of the document To do. In step 314, the unencrypted information is used in step 304 It is processed using the same algorithm as the hashing algorithm used. Ste A second digest version of the unencrypted information in P316 Is created in the terminal. In step 318, the terminal processor is Search the memory for the saved certificate issuer's public key and use the RSA algorithm. Use to decrypt the encrypted digest information from the certificate. Therefore, Another of the unencrypted digested information in step 320 Two versions are produced. In step 322, the terminal is encrypted Not compared two versions of the digested information and the compared information is the same If so, the certificate signature and session public key are presumed to be genuine. Proven The public key can be used by the terminal to encrypt the private session key. Preferred embodiments of the method and apparatus of the present invention are shown in the accompanying drawings and described in the above detailed description. As has been clarified, the present invention is not limited to the disclosed examples and is claimed. Various reconstructions, modifications and replacements without departing from the spirit of the invention specified in Is possible.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2007148701A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2007529147A | Cited by | Japan | Search report |
| JP2005136897A | Cited by | Japan | Examiner |
| JP2007110719A | Cited by | Japan | Examiner |
| JP2007306568A | Cited by | Japan | Search report |
| US8792416B2 | Cited by | United States of America | Applicant |
| JP2002215030A | Cited by | Japan | Search report |
| US7928018B2 | Cited by | United States of America | Applicant |
| JP2008538671A | Cited by | Japan | Search report |
| US8750924B2 | Cited by | United States of America | Applicant |
| JP2007529147A | Cited by | Japan | Search report |
16 members in 10 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 08708796 | United States of America | – | |
| 70879696 | United States of America | A | |
| 70879696 | United States of America | A | |
| 9701407 | Sweden | W | |
| 9701407 | Sweden | W | |
| 708796 | – | – | – |
| PCTSE199701407 | – | – | – |
| US19960708796 | – | – | – |
| WO1997SE01407 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| CA2264809A1 | Canada | A1 | |
| WO9810561A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3955697A | Australia | A | |
| US5850444A | United States of America | A | |
| EP0923827A1 | European Patent Office (EPO) | A1 | |
| CN1236517A | China | A | |
| AU718924B2 | Australia | B2 | |
| TW395106B | Taiwan Province of China | B | |
| KR20000068513A | Republic of Korea | A | |
| JP2001500327AThis record | Japan | A | |
| CN1123159C | China | C | |
| EP0923827B1 | European Patent Office (EPO) | B1 | |
| DE69733262D1 | Germany | D1 | |
| DE69733262T2 | Germany | T2 | |
| CA2264809C | Canada | C | |
| JP4112623B2 | Japan | B2 |
24 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Notification of revocation of power of attorneyJAPANESE INTERMEDIATE CODE: A7425RD05 | RD05 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2001-500327
- Publication, DOCDB
- 2001500327
- Publication, EPODOC
- JP2001500327
- Application
- 10512543
- Application, DOCDB
- 51254398
- Application, EPODOC
- JP19980512543
Titles2
- Japanese
- 電気通信網における無線トラフィック暗号化方法および装置
- English
- PROBLEM TO BE SOLVED: To provide a wireless traffic encryption method and device in a telecommunications network
Classification
- CPC, 9
- H04L9/0841
- H04W12/08
- G06Q20/027
- H04L9/30
- H04W88/02
- H04L9/0825
- H04L2209/80
- H04W12/03
- H04L9/08
- IPC, 4
- G09C1 00
- H04L9 08
- H04L9 30
- H04W88 02
Designated states5
- Regional, 5
- Sweden
- Togo
- Zimbabwe
- Turkmenistan
- Yugoslavia, later Serbia and Montenegro (until 2006)