Method and system for authenticating at least one terminal requesting access to at least one resource
14 claims: 11 independent, 3 dependent
- 1少なくとも1つのリソースへのアクセスを要求する少なくとも1つの端末を認証する方法であって、前記リソース(複数可)へのアクセスは認証サーバによって管理され、ゲートウェイデバイスが一方における前記端末(複数可)と他方における前記認証サーバ及び前記リソース(複数可)との間でデータをルーティングする手段を備える、方法において、前記認証サーバは、 - 各端末について、少なくとも1つの認証情報を取得することと、 - 前記ゲートウェイデバイスに少なくとも1つのチェック関数、又はその係数を送信することと、を実行し、 各認証情報は、それぞれのチェック関数(複数可)に入力されると、該チェック関数(複数可)が所定の値を返すような値を表し、 前記ゲートウェイデバイスは、 - 前記リソース(複数可)へのアクセスを得るための第1の要求を1つの端末から受信することであって、該第1の要求は、前記端末によって提供される認証情報とともに受信されることと、 - 前記認証サーバから受信された前記チェック関数(複数可)の中から、前記受信された要求に適用可能なチェック関数を取り出すことと、 - 認証結果を取得するように、前記端末によって提供された前記認証情報を前記取り出されたチェック関数に入力することと、 - 前記認証結果が前記所定の値に等しいときは、前記リソース(複数可)へのアクセスを得るための前記第1の要求を受理することと、 - 前記認証結果が前記所定の値と異なるときは、前記リソース(複数可)へのアクセスを得るための前記第1の要求を拒絶することと、を実行 し、 前記認証サーバによって取得された各認証情報は、前記認証サーバによって送信された少なくとも1つのチェック関数の根であり、前記所定の値はゼロである ことを特徴とする、少なくとも1つのリソースへのアクセスを要求する少なくとも1つの端末を認証する方法。
- 2前記認証サーバは、 - 各端末について、前記認証情報(複数可)を求めることと、 - 前記それぞれの認証情報(複数可)を各端末に送信することと、を実行することを特徴とする、請求項1に記載の方法。
- 3前記認証サーバは、 - 端末ごとに2つ以上の認証情報を求めることであって、各認証情報は、該端末について求められた各チェック関数に入力されると、前記求められたチェック関数が前記所定の値を返すような値を表すことと、 - 前記端末に既に送信された前記認証情報とは別の認証情報を選択することと、 - 前記選択された認証情報を前記端末に送信することと、を実行し、 前記選択された認証情報を受信すると、前記端末は、前記以前に受信された認証情報を前記選択された認証情報に取り替えることを特徴とする、請求項2に記載の方法。
- 4前記認証サーバは、 - 各端末について、該端末から受信された情報から前記認証情報(複数可)を導出することと、 - 前記求められたそれぞれの認証情報(複数可)に基づいて前記チェック関数(複数可)を求めることと、を実行し、 前記端末は、 - 該端末について前記認証サーバによって実行されるのと全く同様に、該端末によって前記認証サーバに提供された情報から前記認証情報(複数可)を導出すること、を実行することを特徴とする、請求項1に記載の方法。
- 5前記方法の以下のステップ、すなわち、 - 前記リソース(複数可)へのアクセスを得るための第2の要求を前記端末から前記ゲートウェイデバイスによって受信するステップと、 - 前記リソース(複数可)へのアクセスを得るための前記端末の、前記認証サーバによる認証を前記ゲートウェイデバイスによって要求するステップと、 - 前記リソース(複数可)へのアクセスを得るための前記端末の認証が成功すると、前記リソース(複数可)へのアクセスを許可するステップと、が、事前に実行されていると、前記認証サーバは、前記チェック関数(複数可)、又はその係数を送信することを特徴とする、請求項1~ 4 のいずれか一項に記載の方法。
- 6前記認証サーバは、 - 端末ごとに2つ以上のチェック関数を求めることであって、各チェック関数は、前記端末に送信される各認証情報が、各求められたチェック関数に入力されると、該求められたチェック関数が前記所定の値を返すような値を表すようになっていることと、 - 前記ゲートウェイデバイスに既に送信された前記チェック関数とは別のチェック関数を選択することと、 - 前記選択されたチェック関数、又はその係数を前記ゲートウェイデバイスに送信することと、を実行し、 前記選択されたチェック関数、又はその係数を受信すると、前記ゲートウェイデバイスは、前記以前に受信されたチェック関数、又はその係数を前記選択されたチェック関数、又はその係数に取り替えることを特徴とする、請求項1~ 5 のいずれか一項に記載の方法。
- 7少なくとも第1の端末及び第2の端末が、前記リソース(複数可)へのアクセスを得ることを要求することができ、前記認証サーバは、 - 前記第1の端末の少なくとも1つの第1のチェック関数と、任意の第1のチェック関数に入力されると、該第1のチェック関数が前記所定の値を返す任意の値の第1の集合とを求めることと、 - 前記第2の端末の少なくとも1つの第2のチェック関数と、前記第2のチェック関数(複数可)のうちの少なくとも1つに入力されると、前記第2のチェック関数(複数可)が前記所定の値を返す任意の値の第2の集合とを求めることと、を実行し、 前記第1の集合及び前記第2の集合の交差集合は空であることを特徴とする、請求項1~ 6 のいずれか一項に記載の方法。
- 8各チェック関数は、多項式形であるか又は線形符号に基づいていることを特徴とする、請求項1~ 7 のいずれか一項に記載の方法。
- 9前記認証サーバは、端末ごとに、少なくとも1つのチェック関数、又はその係数を一時識別子とともに前記ゲートウェイデバイスに送信し、前記認証サーバは、少なくとも1つの認証情報を前記一時識別子とともに任意の端末に送信することを特徴とする、請求項1~ 8 のいずれか一項に記載の方法。
- 10前記ゲートウェイデバイスは、各端末を、前記ゲートウェイデバイスと該端末との間の通信中に識別するための第1の一時識別子を割り当て、 前記認証サーバは、端末ごとに、少なくとも1つのチェック関数、又はその係数を前記ゲートウェイデバイスに送信し、前記チェック関数は、前記ゲートウェイデバイス及び前記認証サーバによって共有される第2の一時識別子に関連付けられ、 前記ゲートウェイデバイスは、前記第1の一時識別子と前記第2の一時識別子との間の対応関係を保持することを特徴とする、請求項1~ 8 のいずれか一項に記載の方法。
- 11前記認証サーバは、 - 端末ごとに少なくとも1つのチェック関数を求めることと、 - 前記チェック関数の組み合わせとしてリソースごとにグローバルチェック関数を求めることであって、前記組み合わせは、端末ごとの少なくとも1つの求められたチェック関数を含むことと、 - 各リソースについて、前記グローバルチェック関数、又はその係数を前記ゲートウェイデバイスに送信することと、を実行し、 前記第1の要求は、所与のリソースへのアクセスを得るための要求であり、前記ゲートウェイデバイスは、 - 前記所与のリソースの前記グローバルチェック関数を取り出すことと、 - 前記認証結果を取得するために、前記端末によって提供された前記認証情報を前記取り出されたグローバルチェック関数に入力することと、 - 前記認証結果が前記所定の値に等しいときは、前記所与のリソースへのアクセスを得るための前記第1の要求を受理することと、 - 前記認証結果が前記所定の値と異なるときは、前記リソース(複数可)へのアクセスを得るための前記第1の要求を拒絶することと、を実行することを特徴とする、請求項1~ 10 のいずれか一項に記載の方法。
- 12各リソースについて、前記グローバルチェック関数は、前記リソースへのアクセスを正当に得ることを可能にされた端末ごとの少なくとも1つのチェック関数の積として求められることを特徴とする、請求項 11 に記載の方法。
- 13各リソースについて、前記グローバルチェック関数は、前記リソースへのアクセスを正当に得ることを可能にされた端末ごとの少なくとも1つのチェック関数に、根を有しない補助関数を乗算した積として定義されることを特徴とする、請求項 12 に記載の方法。
- 14少なくとも1つのリソースへのアクセスを要求する少なくとも1つの端末を認証するためのシステムであって、前記リソース(複数可)へのアクセスを管理する認証サーバと、一方における前記端末(複数可)と他方における前記認証サーバ及び前記リソース(複数可)との間でデータをルーティングする手段を備えるゲートウェイデバイスとを備える、システムにおいて、前記認証サーバは、 - 各端末について、少なくとも1つの認証情報を取得する手段と、 - 前記ゲートウェイデバイスに少なくとも1つのチェック関数、又はその係数を送信する手段と、を備え、 - 各認証情報は、それぞれのチェック関数(複数可)に入力されると、該チェック関数(複数可)が所定の値を返すような値を表し、 前記ゲートウェイデバイスは、 - 前記リソース(複数可)へのアクセスを得るための第1の要求を受信する手段であって、該第1の要求は、認証情報とともに受信される、受信する手段と、 - 前記認証サーバから受信された前記チェック関数(複数可)の中から、前記受信された要求に適用可能なチェック関数を取り出す手段と、 - 認証結果を取得するために、前記提供された前記認証情報を前記取り出されたチェック関数に入力する手段と、 - 前記認証結果が前記所定の値に等しいときに実施される、前記リソース(複数可)へのアクセスを得るための前記第1の要求を受理する手段と、 - 前記認証結果が前記所定の値と異なるときに実施される、前記リソース(複数可)へのアクセスを得るための前記第1の要求を拒絶する手段と、を備え 、 前記認証サーバによって取得された各認証情報は、前記認証サーバによって送信された少なくとも1つのチェック関数の根であり、前記所定の値はゼロである ことを特徴とする、少なくとも1つのリソースへのアクセスを要求する少なくとも1つの端末を認証するためのシステム。
Independent claims14
105 paragraphs, as filed
Comprehensively, the present invention relates to authenticating at least one terminal requesting access to at least one resource. Access to this resource (s) is managed by an authentication server, providing a means by which the gateway device routes data between the terminal (s) on one side and the authentication server and resources (s) on the other. Be prepared.
Access to resources may be granted to the terminal by using an authentication server. Authentication servers typically manage access authorization for multiple resources.
Such resources are, for example, time and / or frequency resources for radio communication, where access control to those resources involves the establishment of handover procedures or collaboration between two radio neighborhoods. It means that it is. According to another example, such a resource is a server computing resource for a cyber-foraging application or cloud computing. According to yet another example, the resource may be data stored on a data server or information stored by another terminal such as a sensor, or an application executed by another terminal.
To enable centralized management of such resources, the gateway device comprises means for routing data between terminals, authentication servers, and the aforementioned resources. Typically, the terminal sends a request to the gateway device to gain access to a particular resource. When the gateway device detects that access to a resource by a terminal requires authentication, it asks the authentication server whether the terminal can legitimately gain access to the resource. Next, the authentication server authenticates the terminal, and if the terminal authentication fails, the authentication server rejects the request from the gateway device, and then the gateway device rejects the request from the terminal. If the terminal is successfully authenticated, the authentication server accepts the request from the gateway device, then the gateway device accepts the request from the terminal, thus granting the terminal access to the resource.
For example, consider the case where a resource is involved in a handover related to the 3GPP LTE (Long Term Evolution) specification. UEs (user devices) are served by the core network via base stations, also known as eNodeBs. Each eNodeB manages a cell. A cell is an area in which a UE located in the cell can be handled by a related base station, that is, can communicate with a remote communication device by accessing the core network through the base station. Therefore, each eNodeB is considered a gateway device with means for routing data between the UE, core network entities, and nearby eNodeBs. The handover occurs when the UE moves from one cell managed by the first base station to another cell managed by the second base station. Access to cells served by a second base station is provided by a given set of subscribers (Closed Subscriber). It may be limited to CSG), which is an abbreviation for Group). In this case, the handover is performed via an authentication server called an MME (Movement Management Entity) to execute cell access control. Therefore, the MME is responsible for managing access to the resources (s) represented by the cells served by the second base station.
<p num="0006"> However, the systematic execution of authentication through the authentication server is performed between the gateway device and the authentication server, especially when there are numerous concurrent requests to gain access to the resources managed by the authentication server. It takes a lot of time and consumes a lot of network resources because it requires a lot of exchanges between them. Moreover, the systematic execution of authentication via the authentication server consumes a lot of processing resources on the authentication server side.</p><p num="0007"> It is hoped that this state-of-the-art technology will overcome the aforementioned problems.</p><p num="0008"> In particular, a solution that makes it possible to reduce the time required to perform authentication for terminals that request access through the gateway device to at least one resource whose access is managed by an authentication server connected to the gateway device. It is hoped that a plan will be provided.</p><p num="0009"> While ensuring a sufficient level of access control that may change over time, and ensuring terminal untraceability, that is, entities other than the authentication server to resources (s) by a given terminal. It is further desired to provide a solution that allows processing to be offloaded from the authentication server while ensuring that access history cannot be created.</p><p num="0010"> It is further desired to provide a solution that is easy to implement and cost effective.</p>
<p num="0011"> To this end, the present invention is a method of authenticating at least one terminal requesting access to at least one resource, where access to the resource (s) is managed by an authentication server and the gateway device is on one side. The present invention relates to a method comprising means for routing data between the terminal (s) and the authentication server and the resource (s) on the other side. In this method, the authentication server Obtaining at least one credential for each device, Sending at least one check function or its coefficient to the gateway device And When each authentication information is input to each check function (s), the check function (s) returns a predetermined value. In this method, the gateway device further The first request for gaining access to the resource (s) is to be received from one terminal, the first request being received with the authentication information provided by the terminal. , Extracting the check function applicable to the received request from the check functions (s) received from the authentication server, and To input the authentication information provided by the terminal into the retrieved check function so as to acquire the authentication result, When the authentication result is equal to the predetermined value, the first request for gaining access to the resource (s) is accepted. When the authentication result is different from the predetermined value, the first request for gaining access to the resource (s) is rejected, and Is supposed to be executed. Therefore, the time required to authenticate a terminal whose access requests access through the gateway device to the resource (s) managed by the authentication server connected to the gateway device is reduced. Moreover, a sufficient level of access control is ensured.</p><p num="0012"> According to the specific feature, the authentication server executes the request for the authentication information (s) for each terminal and the transmission of each authentication information (s) to each terminal. Therefore, the authentication server can perform authentication offload in a flexible way.</p><p num="0013"> According to a particular feature, the authentication server requests two or more authentication information for each terminal, and when each authentication information is input to each check function requested for the terminal, the request is made. Representing a value such that the checked function returns the predetermined value, selecting an authentication information different from the authentication information already transmitted to the terminal, and using the selected authentication information as the terminal. To send and execute. Further, upon receiving the selected authentication information, the terminal replaces the previously received authentication information with the selected authentication information. Therefore, non-traceability of access to resources (s) by terminals is ensured.</p><p num="0014"> According to a specific feature, the authentication server derives the authentication information (s) from the information received from the terminal for each terminal, and obtains each of the required authentication information (s). To obtain the check function (s) based on the above, and to execute. Further, the terminal executes the derivation of the authentication information (s) from the information provided to the authentication server by the terminal, just as it is executed by the authentication server for the terminal. Therefore, the authentication information (s) are not transmitted so that a device intercepts the authentication information (s) for subsequent malicious use of the authentication information (s). The risk of doing so is limited.</p><p num="0015"> According to a particular feature, each authentication information acquired by the authentication server is the root of at least one check function transmitted by the authentication server, the predetermined value being zero. Therefore, this method is easy to implement.</p><p num="0016"> According to a particular feature, the following steps of the method, i.e., receiving a second request from the terminal by the gateway device to gain access to the resource (s), and the resource (s). If the step of requesting the authentication by the authentication server of the terminal to obtain access to (possible) by the gateway device and the authentication of the terminal to obtain access to the resource (s) are successful, the above. If the step of permitting access to the resource (s) has been performed in advance, the authentication server transmits the check function (s) or its coefficient. Therefore, if authentication is performed at least once by the authentication server for the terminal, authentication offload is performed.</p><p num="0017"> According to a particular feature, the authentication server asks for two or more check functions for each terminal, where each check function is such that each authentication information sent to the terminal is a solicited check function. When input to, the obtained check function represents a value that returns the predetermined value, and a check function different from the check function already transmitted to the gateway device. The selection and the transmission of the selected check function, or its coefficients, to the gateway device is performed. Further, upon receiving the selected check function or its coefficient, the gateway device replaces the previously received check function or its coefficient with the selected check function or its coefficient. Therefore, the untraceability of access to the resource (s) by the terminal is enhanced.</p><p num="0018"> According to certain features, at least a first terminal and a second terminal can be required to gain access to the resource (s), and the authentication server is at least the first terminal. Finding one first check function and a first set of arbitrary values that, when input to any first check function, returns the predetermined value, said. When input to at least one of the second check function of the second terminal and at least one of the second check functions (s), the second check function (s) is determined. To find and execute a second set of arbitrary values that return the value of. Further, the intersection of the first set and the second set is empty. Therefore, the risk of one terminal maliciously using the authentication information of another terminal is limited or avoided.</p><p num="0019"> According to certain features, each check function is polynomial or based on a linear code.</p><p num="0020"> According to certain features, the authentication server sends at least one check function, or a coefficient thereof, to the gateway device together with a temporary identifier for each terminal, and the authentication server sends at least one authentication information to the temporary identifier. And send it to any terminal. Therefore, the check function is applied by the gateway device on a terminal-by-terminal basis, so the authentication server does not need to update the check function when more or less the terminal authentication offload must be set up.</p><p num="0021"> According to a particular feature, the gateway device assigns a first temporary identifier to identify each terminal during communication between the gateway device and the terminal, and the authentication server, for each terminal, At least one check function, or a coefficient thereof, is transmitted to the gateway device, the check function is associated with a second temporary identifier shared by the gateway device and the authentication server, and the gateway device is the first. It is characterized in that the correspondence between the temporary identifier of the above and the second temporary identifier is maintained. Therefore, malicious use of authentication information by an unauthenticated terminal does not provide an appropriate check function.</p><p num="0022"> According to a particular feature, the authentication server seeks at least one check function for each terminal and a global check function for each resource as a combination of the check functions, the combination being per terminal. For each resource, the global check function, or its coefficient, is transmitted to the gateway device. Further, the first request is a request to obtain access to a given resource, and the gateway device retrieves the global check function of the given resource and obtains the authentication result. To enter the authentication information provided by the terminal into the retrieved global check function, and to gain access to the given resource when the authentication result is equal to the predetermined value. Accepting the first request of When the authentication result is different from the predetermined value, the first request for gaining access to the resource (s) is rejected, and so on. Therefore, the check function is applied by the gateway device on a resource-by-resource basis, which enhances the untraceability of terminal access to the resource (s).</p><p num="0023"> According to a particular feature, for each resource, the global check function is calculated as the product of at least one check function per terminal that has been made legitimately able to gain access to the resource. Therefore, this method is easy to implement.</p><p num="0024"> According to certain features, for each resource, the global check function multiplies at least one check function per terminal, which allows legitimate access to the resource, with a rootless auxiliary function. Is defined as the product of Therefore, the check function is applied by the gateway device on a resource-by-resource basis, further enhancing the untraceability of terminal access to the resource (s).</p><p num="0025"> Further, the present invention is a system for authenticating at least one terminal requesting access to at least one resource, and is an authentication server that manages access to the resource (s), and the terminal on one side. It relates to a system comprising (s) and a gateway device comprising means for routing data between the authentication server and the resource (s) on the other side. In this system, the authentication server A means of obtaining at least one credential for each device, A means of transmitting at least one check function or its coefficient to the gateway device, and With Each authentication information represents a value such that when the check function (s) is input to each check function (s), the check function (s) returns a predetermined value. Further, in this system, the gateway device is A means of receiving a first request for gaining access to the resource (s), the first request being received with authentication information, and a means of receiving. A means for extracting a check function applicable to the received request from the check functions (s) received from the authentication server, and A means for inputting the provided authentication information into the retrieved check function in order to acquire the authentication result, and A means for accepting the first request for gaining access to the resource (s), which is performed when the authentication result is equal to the predetermined value. A means for rejecting the first request for gaining access to the resource (s), which is performed when the authentication result differs from the predetermined value. It is designed to be equipped with.</p><p num="0026"> The present invention also relates to a computer program that can be downloaded from a communication network and / or stored on a medium that can be read by a processing device. This computer program contains instructions for performing the method described above when the program is executed by a processor. The present invention also relates to an information storage means for storing a computer program containing a set of instructions, the set of instructions when the stored information is read by the information storage means and executed by a processor. Have the method described above carried out.</p><p num="0027"> The features and advantages associated with systems and computer programs are the same as already mentioned with respect to the corresponding methods described above and are not repeated here.</p><p num="0028"> The characteristics of the present invention will be further clarified by reading the following description of an example of an embodiment, the description of which will be given with reference to the accompanying drawings.</p>
<figref num="1">It is a figure which shows typically the wireless communication system which can carry out this invention.</figref><figref num="2">It is a figure which shows typically the architecture of the gateway device of a wireless communication system.</figref><figref num="3">FIG. 5 is a diagram schematically showing an exchange performed in a wireless communication system when authentication is performed by an authentication server.</figref><figref num="4">FIG. 5 is a diagram schematically showing an exchange performed in a wireless communication system when an authentication is offloaded from an authentication server to a gateway device.</figref><figref num="5A">FIG. 5 is a diagram schematically showing an algorithm executed by an authentication server for offloading authentication to a gateway device according to the first embodiment.</figref><figref num="5B">FIG. 5 is a diagram schematically showing an algorithm executed by an authentication server for offloading authentication to a gateway device according to the second embodiment.</figref><figref num="6">FIG. 5 is a diagram schematically showing an algorithm executed by an authentication server for offloading authentication to a gateway device according to a third embodiment.</figref><figref num="7">FIG. 5 is a schematic representation of a set of roots of check functions that can be used to offload authentication from an authentication server to a gateway device for a terminal.</figref><figref num="8">FIG. 5 is a diagram schematically showing a set of roots of a check function that can be used to offload authentication from an authentication server to a gateway device for a plurality of terminals.</figref>
Although embodiments of the invention are detailed below with respect to wireless communication systems, the features of the invention apply in the broader context of communication systems where access to resources is controlled by an authentication server via a gateway device. It should be noted that.
FIG. 1 schematically illustrates a wireless communication system in which the present invention can be implemented.
The wireless communication system includes an authentication server 100, a gateway 110, a device that manages at least one resource 120, and at least one terminal 130. The gateway device 110 is adapted to communicate with the authentication server 100, the device that manages the resource (s) 120, and the terminal (s) 130.
Authentication server 100 is responsible for authenticating devices requesting access to resource (s) 120. The gateway device 110 is responsible for providing the authenticated terminal with access to the resource (s) 120. Two or more gateway devices can provide authenticated terminals with access to the resource (s) 120. A request to access the resource (s) 120 is sent by the terminal (s) 130 to the gateway device 110. The gateway device 110 requests the authentication server 100 whether or not the terminal can legitimately obtain access to the resource (s) 120. As detailed below, the gateway device 110 may not always require authentication by the authentication server 100 for every terminal requesting access to the resource (s) 120.
The terminal 130 is, for example, a mobile terminal of a wireless communication network, and communication between the terminal 130 and the gateway device can be performed by using a wireless communication protocol.
The resource 120 is, for example, a radio time resource and / or a radio frequency resource, which means that access control to the resource 120 is a handover procedure, or two radios such as CoMP (cooperative multipoint transmission) in the 3GPP LTE specification. It means that it is related to the establishment of a collaborative method between neighbors. According to another example, resource 120 is a computing resource for a server for cyber foraging applications or cloud computing. As particularly suitable for M2M (Machine to Machine) communication, also known as MTC (Machine Type Communication), resource 120 is for data stored on a data server or information stored by another terminal such as a sensor. It may be an application run by another terminal.
In certain cases of 3GPP LTE networks, when resource 120 is involved in a handover procedure, or connection to another terminal, in this case the UE, the gateway device 110 is preferably to the eNodeB or home eNodeB device. Included, Authentication Server 100 is included in the MME (Moving Management Entity) device.
Figure 2 schematically illustrates the architecture of gateway device 110. According to the illustrated architecture, the gateway device 110 has the following components interconnected by the communication bus 210: processor, microprocessor, microcontroller, or CPU (Central Processing Unit) 200; RAM (Random Access Memory). 201; ROM (read-only memory) 202; HDD (hard disk drive) 203, or any other device adapted to read information stored by storage means; first communication interface 204; second communication interface It includes 205; and a third communication interface 206.
The first communication interface 204 allows the gateway device 110 to communicate with the authentication server 100. For example, the first communication interface 204 is an S1 interface as defined by the 3GPP specification.
The second communication interface 205 allows the gateway device 110 to communicate with the resource 120. For example, the second communication interface 204 is an X2 interface as defined by the 3GPP specification.
The third communication interface 206 allows the gateway device 110 to communicate with the terminal 130. For example, the third communication interface 206 is a Uu interface as defined by the 3GPP specification.
Authentication 100 and / or terminal 130 can be based on a similar architecture, where only the first communication interface 204 is required for the authentication server 100 to communicate with the gateway device 110, and terminal 130 with the gateway device 110. Only the third communication interface 206 is required to communicate.
The CPU 200 can execute an instruction to be loaded into the RAM 201 from the ROM 202 or from an external memory such as an SD card or HDD. After the gateway device 110 is activated, the CPU 200 can read instructions from RAM 201 and execute these instructions. These instructions form a computer program that causes the CPU 200 to perform the steps performed by the gateway device 110 in the algorithm described below.
Every step of the algorithm described below can be performed in software by executing a set of instructions or programs on a programmable computer such as a PC (personal computer), DSP (digital signal processor) or microcontroller. It can be done, or it can be implemented in hardware by a machine or dedicated component such as FPGA (Field Programmable Gate Array) or ASIC (Specific Application Integrated Circuit).
FIG. 3 schematically illustrates the exchanges made in the wireless communication system when authentication is performed by the authentication server 100.
In step S301, terminal 130 detects that it is necessary to gain access to resource 120. In the next step S302, the terminal 130 sends a request to the gateway device 110 to gain access to the resource 120. This request from terminal 130 is received and processed by gateway device 110 in the next step S303. The gateway device 110 detects that access to resource 120 by terminal 130 requires authentication. In the next step S304, the gateway device 110 requests the authentication server 100 whether or not the terminal 130 can legitimately gain access to the resource 120. This request from the gateway device 110 is received and processed by the authentication server 100 in the next step S305. The authentication server 100 authenticates the terminal 130. If the authentication of the terminal 130 fails, the authentication server 100 rejects the request from the gateway device 110, and then the gateway device 110 rejects the request from the terminal 130. Consider the case where the terminal 130 is successfully authenticated, that is, the terminal 130 can legitimately gain access to the resource 120. In other words, the authentication server 100 grants access to the resource 120. In the next step S306, the authentication server 100 sends an acknowledgment to the request received in step S305 to the gateway device 110. This response from the authentication server 100 is received and processed by the gateway device 110 in the next step S307. In the next step S308, the gateway device 110 sends an acknowledgment to the terminal 130. This response from the gateway device 110 is received and processed by terminal 130 in the next step S309. Terminal 130 is ready to gain access to resource 120.
In step S310, the gateway device 110 is ready to allow terminal 130 to gain access to resource 120. The gateway device 110 sends a first connection setup message to the terminal 130 in step S311 and a second connection setup message to the device that manages the resource 120 in step S312. The first connection setup message is received and processed by terminal 130 in step S313, and the second connection setup message is received and processed by the device managing resource 120 in step S314. Each device that manages terminal 130 and resource 120 configures itself to set up a connection. In step S316, the terminal 130 and the device managing the resource 120 exchange messages representing the terminal 130 accessing the resource 120. Such messages are processed in steps S315 and S317 by the device managing terminal 130 and resource 120, respectively.
Instead of steps S310-S317, other steps can be performed to effectively allow terminal 130 to gain access to resource 120. A connection can be set up directly between the terminal 130 and the device that manages the resource 120, or the gateway device 110 can act as an intermediate device in such a connection due to its routing capabilities. Moreover, the gateway device 110 can send a request to set up such a connection to the device that manages the resource 120, which in turn sends the device to terminal 130 to set up the connection effectively. Deal directly. Alternatively, the gateway device 110 can send a request to unlock access to resource 120 at terminal 130 to the device that manages resource 120, and the terminal then grants such access. When the response is received from the gateway device in step S309, access to resource 120 can be gained.
In step S318, the authentication server 100 checks whether the conditions for offloading the authentication for the terminal 130 towards the gateway device 110 are met. For example, the authentication server 100 confirms whether or not a predetermined number of authentications for the terminal 130 have been successfully executed. In another example, the authentication server 100 determines to offload the authentication upon successful execution of the authentication for the terminal 130.
When the conditions for offloading authentication for terminal 130 towards gateway device 110 are met, authentication server 100 sends at least one check function or its coefficients to gateway device 110 in step S319. .. The authentication server 100 further acquires at least one authentication information subsequently provided by the terminal 130 requesting access to the resource 120. This authentication information (s) represents a value such that the check function (s) returns a predetermined value when input to the check function (s). The check function checks that the gateway device 110 can legitimately gain access to the resource 120 by the gateway device 110 when the above authentication information is provided by the terminal 130 based on this authentication information. It makes it possible to do. The check function and the first embodiment for obtaining the authentication information are detailed below with respect to FIG. 5A, and the check function and the second embodiment for obtaining the authentication information are described in detail below with respect to FIG. 5B. The check function and the third embodiment for obtaining the above authentication information are described in detail below with reference to FIG. The use of the check function by the gateway device 110 and the use of the above credentials by the terminal 130 is described below with respect to FIG.
In one embodiment, the authentication server 100 requests the authentication information (s), and in step S320, transmits the authentication information (s) to the terminal 130. The check function, or its coefficient, is received and stored by the gateway device 110 in step S321. The authentication information is received and stored by the terminal 130 in step S322.
In another embodiment, the authentication server 100 obtains the above authentication information (s) from the information received from the terminal 130. For example, the authentication server 100 uses the above authentication information (IMSI) stored in the subscriber identification number module (SIM) connected to the terminal 130, as defined by the 3GPP specifications. (Multiple) is derived. In exactly the same way, the terminal 130 can derive the above authentication information (s) from the IMSI. Therefore, in this embodiment, it is not necessary to transmit the above authentication information (s) from the authentication server 100 to the terminal 130. In this case, in S320, the authentication server 100 should send the authentication information derived from the IMSI to the gateway device 110 at that time (now on) when the terminal 130 requests to gain access to the resource 120. Information indicating that is transmitted to the terminal 130.
In one variant, instead of deciding to offload authentication following successful authentication of terminal 130, authentication server 100 makes such a decision according to criteria related to the processing load level of authentication server 100. .. In this case, steps S318 to S322 are executed following the detection that the above-mentioned determination criteria are satisfied.
FIG. 4 schematically illustrates the exchanges that take place in the wireless communication system when offloading authentication from the authentication server 100 to the gateway device 110.
In step S401, terminal 130 detects that it needs to gain access to resource 120. In the next step S402, the terminal 130 sends a request to the gateway device 110 to gain access to the resource 120. The request is accompanied by the authentication information previously received by the terminal 130 in step 322. The request from the terminal 130 and the attached authentication information are received and processed by the gateway device 110 in the next step S403. The gateway device 110 detects that access to resource 120 by terminal 130 requires authentication. The gateway device 110 further detects that authentication has been offloaded to the gateway device 110 by the authentication server 100 in order for at least the terminal 130 to gain access to the resource 120. Next, the gateway device 110 is applicable to determine whether or not the terminal 130 is authorized to access the resource 120 from the check functions (s) received from the authentication server 100. Extract the function. The gateway device 110 then inputs the authentication information provided by the terminal 130 into the retrieved check function. If the check function outputs a predetermined value as a result of applying the check function to the authentication information provided by the terminal 130, the authentication is successful. Otherwise, the check function will fail. As detailed below, this predetermined value is preferably zero. If the authentication is successful, the gateway device 110 accepts the request sent by the terminal 130. Otherwise, the gateway device 110 rejects the request sent by terminal 130. Consider the case where the authentication of the terminal 130 is successful, that is, the terminal 130 can legitimately gain access to the resource 120. In other words, the gateway device 110 grants access to the resource 120. Next step S4 At 04, the gateway device 110 transmits an acknowledgment to the request received in step S403 to the terminal 130. This response from the gateway device 110 is received and processed by terminal 130 in the next step S405.
In step S406, the gateway device 110 is ready to allow terminal 130 to gain access to resource 120. The gateway device 110 sends the first connection setup message to the terminal 130 in step S407, and sends the second connection setup message to the device that manages the resource 120 in step S408. The first connection setup message is received and processed by terminal 130 in step S410, and the second connection setup message is received and processed by the device managing resource 120 in step S411. Each device that manages terminal 130 and resource 120 configures itself to set up a connection. In step S412, the terminal 130 and the device managing the resource 120 exchange messages representing the terminal 130 accessing the resource 120. Such messages are processed in steps S411 and S413 by the device managing terminal 130 and resource 120, respectively. As described above with respect to FIG. 3, instead of steps S406-S413, other steps can be performed to effectively allow the terminal 130 to gain access to the resource 120.
FIG. 5A schematically illustrates the algorithm executed by the authentication server 100 for offloading authentication to the gateway device 110 according to the first embodiment.
In step S501, the authentication server 100 seeks at least one check function for each terminal 130 where authentication is expected to be offloaded towards the gateway device 110.
In step S502, for each terminal 130, the authentication server 100 seeks at least one authentication information associated with the solicited check function (s). For each terminal 130, each authentication information represents a value such that the associated check function returns a predetermined value when input to any associated check function.
Preferably, such a predetermined value is zero. That is, each authentication information represents the root of the check function.
In one variant, steps S501 and S502 are inverted. In this case, the authentication server 100 asks for at least one authentication information for each terminal 130, and then asks for at least one check function associated with this authentication information (s). Each credential represents a value such that the associated check function returns a predetermined value when entered into any associated check function.
Consider terminal i. Check function f<sub>i</sub>When entered in (), check function f<sub>i</sub>C is a set of all values for which () returns a given value α<sub>i</sub>Will be shown in. In a preferred embodiment, α = 0. Check function f<sub>i</sub>Each authentication information associated with () represents the value x that solves the following system.<maths num="1"><img id="000002" he="10" wi="34" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Consider another terminal j. Check function f<sub>j</sub>When entered in (), check function f<sub>j</sub>C is a set of all values for which () returns a given value α<sub>j</sub>Will be shown in. Aggregate to prevent terminal j from effectively gaining access to resource 120 due to credentials provided to terminal i and maliciously used by terminal j to gain access to resource 120. C<sub>i</sub>And C<sub>j</sub>The intersection of should be empty.<maths num="2"><img id="000003" he="5" wi="40" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Therefore, in step S503, the authentication server 100 ensures that each authentication of one terminal cannot be associated with a check function of another terminal.
In the next step S504, the authentication server 100 associates the temporary identifier for each terminal 130 with the authentication information (s) for the terminal 130 and the check function (s) for the terminal 130.
In step S505, the authentication server 100 transmits at least one obtained check function, or a coefficient thereof, to at least one gateway device such as the gateway device 110. The authentication server 100 transmits one required check function, or a coefficient thereof, for each terminal 130 for which authentication offload is enabled. At the same time, the authentication server 100 sends the temporary identifier associated with each check function to the gateway device (s).
Moreover, in addition to this, the authentication server 100 can transmit a predetermined value α to the gateway device (s).
In step S506, the authentication server 100 transmits at least one requested authentication information to each terminal 130 for which authentication offload is enabled. At the same time, the authentication server 100 transmits the temporary identifier associated with each authentication information to the terminal (s) 130.
Therefore, consider that one terminal received the temporary identifier i and another terminal received a different temporary identifier j, and set C.<sub>i</sub>And C<sub>j</sub>Given that the intersection of is empty, the terminal that received the temporary identifier j has the value x C.<sub>i</sub>Malicious use of the credentials that represents will result in the request to gain access to resource 120 being denied.
The temporary identifier is temporary in that the authentication server 100 is expected to change the temporary identifier periodically or upon detection of a predetermined event. Such a predetermined event is, for example, the detection of a terminal that maliciously uses authentication information. That is, it is the detection of the terminal using the authentication information that the gateway device 110 does not acquire a predetermined value even if the authentication information is input to the check function selected by the gateway device 110. When the temporary identifier is changed, the authentication server 100 sends the newly defined temporary identifier to the gateway device (s) together with the check function associated with this temporary identifier, and at least this newly defined temporary identifier is sent. Send to terminal 130. For example, this temporary identifier is a temporary mobile subscriber identification number (TMSI) as defined by the 3GPP mobile management specification. TMSI is the most commonly transmitted identification number between a mobile terminal and a wireless communication network. The TMSI is randomly assigned by this VLR to any mobile terminal in the area managed by the Area Location Register (VLR) when the mobile terminal is turned on. The scope of TMSI remains local to the area managed by the VLR, and therefore TMSI is expected to be updated each time the mobile terminal moves to a different area. According to 3GPP's mobility management specifications, TMSI can be further modified at any time to prevent subscribers from being identified and tracked by eavesdroppers on wireless channels or within wireless communication systems.
After executing the algorithm of FIG. 5A, when the terminal 130 subsequently provides the authentication information to the gateway device 110 together with the temporary identifier, the gateway device 110 applies the check function associated with the temporary identifier to the authentication information. When the check function returns a given value α, the terminal 130 is successfully authenticated and access to the resource (s) 120 is granted. Otherwise, authentication of terminal 130 will fail and access to resource (s) 120 will be denied.
Therefore, considering that one terminal has received the temporary identifier i and another terminal has not yet been authenticated by the authentication server 100, the other terminal above has the value x C.<sub>i</sub>If the authentication information and the temporary identifier i are used maliciously, the request for access to the resource 120 is rejected if the validity of the temporary identifier i has expired.
The algorithm in Figure 5A ensures that the gateway device 110 does not know the true identification number of terminal 130, while tracking any resources that allow the gateway device 110 to gain access. Guarantee that you cannot do. Therefore, it is not possible for the gateway device 110 to track the terminal 130.
FIG. 5B schematically illustrates the algorithm performed by the authentication server to offload authentication to the gateway device according to the second embodiment.
In step S511, the gateway device 110 detects that the terminal 130 is in an area managed by the gateway device 110. The gateway device 110 then assigns a first temporary identifier to the terminal 130. This first temporary identifier is then used to identify terminal 130 during communication between the gateway device 110 and terminal 130.
In step S512, the gateway device 110 requests the authentication server 100 to authenticate the terminal 130. The gateway device 110 or the authentication server 100 assigns a second temporary identifier to the terminal 130. This second temporary identifier is then used to identify the terminal 130 during communication between the gateway device 110 and the authentication server 100. The first temporary identifier and the second temporary identifier can be the same. When the first temporary identifier and the second temporary identifier are not the same, the gateway device 110 maintains a correspondence between the first identifier and the second identifier.
In step S513, the gateway device 110 allows the setup of a secure connection between the terminal 130 and the authentication server 100. This secure connection allows the terminal 130 to provide the authentication server with information that identifies the subscriber using the terminal, such as TMSI or IMSI. Next, in the next step S514, the authentication server 100 identifies this subscriber and extracts related subscriber information such as the right to access the resource (s) 120.
In step S515, the authentication server 100 seeks at least one check function for terminal 130 and at least one authentication associated with the found check function (s), as described above for steps S501 and S502. Ask for information.
In step S516, the authentication server 100 sends at least one required check function, or a coefficient thereof, to the gateway device 110. Therefore, these check functions are associated with a second temporary identifier. The authentication server 100 also transmits at least one requested authentication information to the terminal 130 with a secure connection.
After executing the algorithm of FIG. 5B, when the terminal 130 subsequently provides the authentication information to the gateway device 110, the gateway device 110 is applicable by the correspondence between the first temporary identifier and the first identifier and the second identifier. Check function is taken out. When the check function returns a given value α, the terminal 130 is successfully authenticated and access to the resource (s) 120 is granted. Otherwise, authentication of terminal 130 will fail and access to resource (s) 120 will be denied.
Therefore, the value x C associated with terminal i<sub>i</sub>Given the malicious use of the credential representing the device by terminal j, the result is that the request to gain access to resource 120 is denied. This is because the above credentials cannot be associated with an appropriate check function.
Similar to the algorithm of FIG. 5A, the algorithm of FIG. 5B ensures that the gateway device 110 does not know the true identification number of terminal 130, and the gateway device 110 allows terminal 130 to gain access. Guarantee that it is not possible to track any resource that has been identified. Therefore, it is not possible for the gateway device 110 to track the terminal 130.
From the above description, it should be understood that for each associated check function, the authentication server 100 can request more than one authentication information for each terminal 130. It should also be understood that the authentication server 100 can request two or more check functions for each associated authentication information for each terminal 130. This allows the authentication server 100 to change the credentials of terminal 130 and / or the associated check function.
The two check functions of one terminal 130 may have little in common an input value that implies returning a given value α. Therefore, changing the credentials of terminal 130 is one check function f<sub>i, 1</sub>Another check function f from ()<sub>i, 2</sub>The authentication information used by terminal 130 when switching asynchronously to () is x C<sub>i, 1</sub>And x C<sub>i, 2</sub>This switching is possible by ensuring that it represents a value x such that Consistent with the above description, C<sub>i, 1</sub>Is the check function f<sub>i, 1</sub>When entered in (), check function f<sub>i, 1</sub>Indicates a set of all values for which () returns a given value α, C<sub>i, 2</sub>Is the check function f<sub>i, 2</sub>When entered in (), check function f<sub>i, 2</sub>Shows a set of all values for which () returns a given value α. An explanatory example is shown in FIG.
Figure 7 shows each check function f that can be used to offload authentication from the authentication server 100 to the gateway device 110 for one terminal 130.<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>Set of roots in () C<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Is roughly represented. Each set is schematically represented by its own circle. Set C, as shown in Figure 7.<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Partially overlap each other. Therefore, set C<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Cross set C<sub>1</sub>Is each check function f<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>It consists of roots common to (). Therefore, for terminal 130 the value x C<sub>1</sub>By selecting the authentication information that represents, the authentication server 100 can use any check function f.<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>() Can be selected. In this case, the situation in which the update of the authentication information by the terminal 130 and the update of the associated check function by the gateway device 110 are not ensured is managed. Such a situation occurs, for example, when terminal 130 is in an idle mode period, and when awakening terminal 130 attempts to gain access to resource 120. During the idle mode, the authentication server 100 performs an authentication offload update, which is therefore not received by the terminal 130 in idle mode. When the authentication server performs an authentication offload update, the authentication information stored by terminal 130 has the value x C.<sub>1</sub>In the case of, the terminal 130 succeeds in gaining access to the resource 120.
In other words, the authentication server 100 selects a new check function for terminal 130, and the terminal 130 responds with a value x C before requesting an update by the gateway device 110.<sub>1</sub>Guarantee that you remember the authentication information that represents.
In a preferred embodiment, the authentication server 100 has a value x C.<sub>1</sub>It only provides the terminal 130 with the authentication information that represents. If terminal 130 derives credentials from the IMSI, the credentials are preferably the value x C.<sub>1</sub>This allows the authentication server 100 to independently change the applicable check function.
In this preferred embodiment, given the case where terminal i should not receive authentication information that results in successful authentication by using the check function obtained for another terminal j, the following constraints should be met: ..<maths num="3"><img id="000004" he="13" wi="53" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The two check functions of each of the two terminals 130 may have some input values in common, implying that they return a given value α. However, the credentials sent to each terminal 130 are in common with a set of values that imply returns a given value α when entered into any check function associated with any other terminal 130. Should not be. An explanatory example is shown in FIG.
FIG. 8 shows each check function f that can be used to offload authentication from the authentication server 100 to the gateway device 110 for the first terminal 130.<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>Set of roots in () C<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Is roughly represented. FIG. 8 shows each check function f that can be used to offload authentication from the authentication server 100 to the gateway device 110 for the second terminal 130.<sub>2,1</sub>(), f<sub>2,2</sub>(), f<sub>2,3</sub>Set of roots in () C<sub>2,1</sub>, C<sub>2,2</sub>, C<sub>2,3</sub>Is more generally represented. Each set is schematically represented by its own circle. Set C, as shown in Figure 8.<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Partially overlap each other. Therefore, set C<sub>1,1</sub>, C<sub>1,2</sub>, C<sub>1,3</sub>Cross set C<sub>1</sub>Is each check function f<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>It consists of roots common to (). Therefore, for the first terminal 130, the value x C<sub>1</sub>By selecting the authentication information that represents, the authentication server 100 can use any check function f.<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>() Can be selected. Moreover, as shown in Figure 8, set C<sub>2,1</sub>, C<sub>2,2</sub>, C<sub>2,3</sub>Partially overlap each other. Therefore, set C<sub>2,1</sub>, C<sub>2,2</sub>, C<sub>2,3</sub>Cross set C<sub>2</sub>Is each check function f<sub>2,1</sub>(), f<sub>2,2</sub>(), f<sub>2,3</sub>It consists of roots common to (). Therefore, for the second terminal 130, the value x C<sub>2</sub>By selecting the authentication information that represents, the authentication server 100 can use any check function f.<sub>2,1</sub>(), f<sub>2,2</sub>(), f<sub>2,3</sub>() Can be selected. In addition, as shown in Figure 8, set C<sub>1,2</sub>And C<sub>2,3</sub>Partially overlap each other, but set C<sub>1,2</sub>Is set C<sub>2</sub>It is designed so that it does not overlap with the set C<sub>2,3</sub>Is set C<sub>1</sub>It is designed not to overlap with. Therefore, the value x C<sub>1</sub>By transmitting only the authentication information representing the above to the first terminal 130, the authentication server 100 can change the above authentication information to any of the check functions f.<sub>2,1</sub>(), f<sub>2,2</sub>(), f<sub>2,3</sub>Guarantees that combination with () does not result in successful authentication, value x C<sub>2</sub>By transmitting only the authentication information representing the above to the second terminal 130, the authentication server 100 can change the above authentication information to any of the check functions f.<sub>1,1</sub>(), f<sub>1,2</sub>(), f<sub>1,3</sub>Guarantee that combination with () does not result in successful authentication.
In other words, at least the first terminal 130 and the second terminal 130 can request access to the resource (s) 120, so that the authentication server 100 is at least one of the first terminals. A first set of arbitrary values C that, when input to one of the first check functions and any first check function, returns a given value.<sub>1</sub>And ask. Moreover, when the authentication server 100 is input to at least one second check function of the second terminal and at least one of the second check functions (s), the second check is performed. A second set of arbitrary values for which the function (s) returns a given value C = C<sub>2,1</sub>C<sub>2,2</sub>C<sub>2,3</sub>And ask. Authentication server 100 is the first set C<sub>1</sub>And guarantee that the intersecting set of the second set C is empty.
The check function and the first explanatory example for obtaining each authentication information are based on the polynomial form. Consistent with the above description, C<sub>i, k</sub>Is the check function f<sub>i, k</sub>Think of it as a set of roots in (). In this case, the check function f<sub>i, k</sub>() Can be expressed as follows.<maths num="4"><img id="000005" he="11" wi="55" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>Where q (m) is the check function f<sub>i, k</sub>The order of the root m of (), P<sub>i, k</sub>() Is the relevant P<sub>i, k</sub>() Is a polynomial with no input value that results in the output of a given value α.
In this first example, the set C<sub>i</sub>And C<sub>i, k</sub>Is considered to be already defined. Here, i = 0, ..., T-1 are indexes representing one of each of the T terminals 130. When the authentication server 100 needs to add another terminal 130, the authentication server is a new set C of this other terminal 130.<sub>T</sub>To ask. Here, set C<sub>T</sub>And any already defined set C<sub>i, k</sub>The intersection with and is empty. All already defined sets C<sub>i, k</sub>The union of is shown by A as follows. Here, i = 0, ..., T-1.<maths num="5"><img id="000006" he="11" wi="27" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Therefore, C<sub>T</sub>Is defined as follows.<maths num="6"><img id="000007" he="4" wi="18" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
This results in set C<sub>T</sub>Check function f for which any one of the values of is already defined<sub>i, k</sub>When entered in (), the set C<sub>T</sub>The value of these pre-defined check functions f<sub>i, k</sub>It is possible to guarantee that () does not result in the output of a given value α.
Already defined set C<sub>i</sub>The union of is further shown by B as follows. Here, i = 0, ..., T-1.<maths num="7"><img id="000008" he="11" wi="17" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Authentication server 100 is set C<sub>T, k</sub>Further find the value that forms.
C'set the following<sub>T, k</sub>Will be further shown in.<maths num="8"><img id="000009" he="10" wi="27" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Authentication server 100 is a polynomial P<sub>T, k</sub>The polynomial P having no input value () results in outputting a given value α<sub>T, k</sub>Find (). Next, the authentication server has the following check function f<sub>T, k</sub>Find ().<maths num="9"><img id="000010" he="12" wi="81" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Next, the authentication server 100 is set C.<sub>T</sub>To B and set C<sub>T, k</sub>Is added to A, at which time it is ready to add another new terminal 130.
The check function and the second example for obtaining each authentication information are based on a linear code.
Concentration 2 constructed from M × N generator matrix G<sup>M</sup>Let us consider the linear code L of. Here, M <N. Therefore, any value l belonging to L satisfies l = qG. Where q is a binary word of length M belonging to the set Q. Let H further indicate the N × (NM) parity matrix of G such that the following equation is obtained.<maths num="10"><img id="000011" he="3" wi="13" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The authentication server 100 sets the set Q to a Q such that the intersection set is not empty.<sub>k</sub>Decompose into subsets of pieces.<maths num="11"><img id="000012" he="10" wi="18" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Next, the authentication server 100 can obtain the authentication information (s) as representing the value (s) l'belonging to L such that l'= q'G. Where the q'value (s) is the subset Q<sub>k</sub>It belongs to the intersection set of. Let L'indicate the set of values l'.
Consider a terminal 130 identified by the index i among a plurality of T terminals 130. Here, i = 0, ..., T-1. The authentication server 100 uses the following shifted codeword l for the authentication information (s) of the terminal 130.<sub>i, k</sub>Ask as.<maths num="12"><img id="000013" he="5" wi="20" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>Where l<sub>k</sub>Is a subset Q<sub>k</sub>Represents a binary codeword corresponding to a value belonging to t<sub>i</sub>Is a binary word of length N that does not belong to L, which is any shifted codeword used for any other terminal j.<sub>j, k</sub>Does not correspond to. Summing one codeword with a linear code and one codeword that does not belong to a linear code results in a codeword that does not belong to a linear code, so if the values of the index i are different, the value l<sub>j, k</sub>There is no overlap between them.
Next, the authentication server 100 has a parity matrix H and a value t as shown below.<sub>i</sub>Or value γ<sub>i</sub>To the gateway device 110.<maths num="13"><img id="000014" he="4" wi="14" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Next, when the authentication information is received from the terminal 130 identified by the index i, the gateway device 110 verifies that the following conditions are satisfied.<maths num="14"><img id="000015" he="4" wi="22" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>Where l<sub>i, k</sub>H + γ<sub>i</sub>Is the check function f<sub>i, k</sub>Represents ().
When this condition is met, the terminal 130 is considered to have been authenticated by the gateway device 110.
From the above description, it should be understood that a set of appropriate check functions can be pre-determined by the authentication server 100 for each terminal, in which case the authentication server 100 will be based on this set of check functions and. Select a sufficient pair of credentials. Alternatively, the authentication server 100 can dynamically define a check function and a pair of authentication information. In this case, the authentication server 100 has at least one previous credential that the associated terminal 130 can still use to compensate for the asynchronous application of changes by the gateway device 110 and the associated terminal 130. , Guarantee to work with newly defined check functions. Similarly, the authentication server 100 also ensures that the gateway device 110 works with at least one previous check function that can still be used for the associated terminal 130 with the newly defined credentials. This is set C<sub>i</sub>Further means that may progress over time.
FIG. 6 schematically illustrates the algorithm executed by the authentication server 100 for offloading authentication to the gateway device 110 according to the third embodiment.
In this third embodiment, it is not necessary to associate the temporary identifier with the check function (s) and the authentication information (s). As a result, the check functions of each of the plurality of terminals 130 (hereinafter referred to as unitary check functions) are not sent separately to the gateway device 110, but conversely form a global check function associated with the resource 120. Combined. This global check function, or its coefficient, is then transmitted to the gateway device 110.
In step S601, the authentication server 100 seeks at least one check function for each terminal 130 where authentication is expected to be offloaded towards the gateway device 110.
In step S602, for each terminal 130, the authentication server 100 seeks at least one authentication information associated with the solicited check function (s). For each terminal 130, each authentication information represents a value such that the associated check function returns a predetermined value α when input to any associated check function.
Preferably, such a predetermined value α is zero. That is, each authentication information represents the root of the check function.
In step S603, the authentication server 100 ensures that each authentication of one terminal cannot be associated with a check function of another terminal. This means the following equation, according to the description consistent with the notation already used.<maths num="15"><img id="000016" he="5" wi="40" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Steps S601, S602, and S603 are identical to steps S501, S502, and S503 of the algorithm of FIG. 5A, respectively, to which the same variants apply, including the variants described above with respect to FIGS. 7 and 8. Means to be done. Following the execution of steps S601, S602, and S603, a unitary check function is required for each terminal 130 authorized to gain access to resource 120.
In step S604, the authentication server 100 generates a global check function as a combination of a plurality of unitary check functions. This combination includes at least one unitary check function for each terminal 130 authorized to gain access to resource 120. Considering that this unitary check function outputs a predetermined value α depending on the value input to one of a plurality of unitary check functions, this global check function has a predetermined value depending on the input value described above. It is designed to output β.
Consider the first terminal 130 and the second terminal 130 having the unitary check function and the authentication information defined as shown in FIG. 8 as described above. The global check function is indicated by g (), and the authentication server 100 uses the unitary check function f on the first terminal 130.<sub>1,1</sub>Select () and use the unitary check function f on the second terminal 130.<sub>2,3</sub>We will consider that we will decide to select (). In this case, the global check function g () is the unitary check function f.<sub>1,1</sub>() And f<sub>2,3</sub>Defined as a combination of (), any value x C<sub>1</sub>Or x C<sub>2</sub>For, g (x) = β.
Preferably, the predetermined value β is zero. That is, each authentication information represents the root of the check function.
According to a particular embodiment, the predetermined value β is zero and the global check function g () is the check function f of each terminal 300 authorized to gain access to resource 120.<sub>i, k</sub>Unitary check function f selected by authentication server 100 from ()<sub>i</sub>Defined as the product of ().<maths num="16"><img id="000017" he="10" wi="25" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
According to a particular embodiment, the predetermined value β is zero and the global check function g () is a unitary selected by the authentication server 100 of each terminal 300 authorized to gain access to the resource 120. Check function f<sub>i</sub>It is defined as the product of () multiplied by the rootless auxiliary function h ().<maths num="17"><img id="000018" he="15" wi="35" file="JP6067101B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Further according to a particular embodiment, the authentication server 100 defines a unitary check function f that defines a global check function g ().<sub>i</sub>The authentication server 100 modifies the auxiliary function h () each time it adds, removes, or modifies at least one of (). This feature enhances the untraceability of terminal 130 by the gateway device 110.
In step S605, the authentication server 100 transmits the obtained global check function or its coefficient to at least one gateway device such as the gateway device 110. In addition, the authentication server 100 can transmit a predetermined value β to the gateway device (s).
In step S606, the authentication server 100 transmits at least one requested authentication information to each terminal 130 capable of authentication offload.
Like any unitary check function as described above, the authentication server 100 can change the global check function over time.
After executing the algorithm of FIG. 6, when the terminal 130 subsequently provides the authentication information to the gateway device 110, the gateway device 110 applies the global check function to this authentication information. When the global check function returns the given value β, the terminal 130 is successfully authenticated and access to the resource 120 is granted. Otherwise, the authentication of terminal 130 will fail and access to resource 120 will be denied.
According to certain embodiments, the embodiments described above with respect to FIGS. 5A and 6 or the embodiments described above with respect to FIGS. 5B and 6 can be combined. In this case, when terminal 130 provides the authentication information to the gateway device 110, the gateway device 110 uses the unitary check function f.<sub>i</sub>Check the authentication information using both () and the global check function g (). In this case, the unitary check function f<sub>i</sub>Whether the confirmation performed using () enables authentication of terminal 130 and the confirmation performed using the global check function g () allows terminal 130 to legitimately access resource 120. It becomes possible to judge whether or not.
26 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2011139113A | Cites | Japan |
| Nokia, Nokia Siemens Networks,Additions to H(e)NB security solutions,3GPP TSG-SA WG3#52 S3-080795,2008年 6月27日 | Non-patent | – |
| Qualcomm Incorporated,Network based method of enforcing a USIM restriction using device authentication,3GPP TSG-SA WG3#65 S3-111174,2011年11月11日 | Non-patent | – |
9 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 12193627 | European Patent Office (EPO) | A | |
| 12193627 | European Patent Office (EPO) | A | |
| 121936272 | European Patent Office (EPO) | – | |
| 2013080365 | Japan | W | |
| 2013080365 | Japan | W | |
| 121936272 | – | – | – |
| EP20120193627 | – | – | – |
| JP2013080365 | – | – | – |
| WO2013JP80365 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| EP2736213A1 | European Patent Office (EPO) | A1 | |
| WO2014080780A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN104782099A | China | A | |
| JP2015524627A | Japan | A | |
| US2015249653A1 | United States of America | A1 | |
| EP2736213B1 | European Patent Office (EPO) | B1 | |
| JP6067101B2This record | Japan | B2 | |
| US9756029B2 | United States of America | B2 | |
| CN104782099B | China | B |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 6067101
- Publication, DOCDB
- 6067101
- Publication, EPODOC
- JP6067101B
- Application
- 2015507290
- Application, DOCDB
- 2015507290
- Application, EPODOC
- JP20150507290
Titles2
- Japanese
- 少なくとも1つのリソースへのアクセスを要求する少なくとも1つの端末を認証する方法及びシステム
- English
- Methods and systems to authenticate at least one device requesting access to at least one resource
Classification
- CPC, 6
- H04L63/0884
- H04L63/10
- H04W12/06
- H04W12/062
- H04L63/02
- H04L63/08
- IPC, 1
- H04W12 06
