Method and apparatus for efficient real-time authentication and encryption in a communication system.
Abstract
Radio frequency cellular switching systems often require both the subscriber device 100 and the communication device 130 of the fixed network communication system to not only provide encryption parameters for encryption processing of messages, but also maintain secret data to be used for user identification processing. Demand. The present invention discloses an efficient real-time user identification method and apparatus using one message 210 that provides user identification and communication link waiting information. In addition, in order to improve the reliability of user identification processing, user identification using instantaneous specific information such as time, carrier frequency of radio frequency, time slot number, radio port number, access manager identifier, radio port control device identifier or base station controller identifier, etc. A method and apparatus are disclosed. Further, a method and apparatus for maintaining the security of packet data communication through encryption processing using the encryption key 502 of a packetized message and a unique packet number 504 as encryption variables are provided.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
10 claims: 6 independent, 4 dependent
- 1A subscriber device for performing user identification in communication with a communication device of a communication system;(a) memory means for maintaining the first subscriber device identifier, the first shared secret data, the second shared secret data, the random trial and moment specific information;(b) processor means operative in combination with said memory means to generate a user confirmation message as a function of said first shared secret data, said random attempt and said instantaneous specific information;(c) a key operative in combination with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said moment specific information. ) means of generating;(d) encryption means operating in combination with said key generating means to form encrypted data by encrypting a second subscriber device identifier and a telephone number uniquely identifying a target communication device using the session key as an encryption variable ;and (e) operating in combination with said memory means, said processor means and said key generating means for transmitting said first subscriber device identifier, said user confirmation message and said encrypted data to said communication device in a single message. A subscriber device comprising transmitter means. 통신 시스템의 통신 장치와의 통신에서 사용자 확인을 수행하는 가입자 장치에 있어서;(a) 제1 가입자 장치 식별자, 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(b) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 프로세서 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키(a session key)를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키(key) 생성 수단;(d) 상기 세션 키를 암호화 변수로 사용하여, 목표 통신 장치를 유일하게 식별해주는 전화 숫자 및 제2 가입자 장치 식별자를 암호화 함으로써 암호화된 데이타를 형성하기 위하여 상기 키 생성 수단과 결합하여 동작하는 암호화 수단;및 (e) 하나의 메시지 내에서 상기 제1 가입자 장치 식별자, 상기 사용자 확인 메시지 및 상기 암호화된 데이타를 상기 통신 장치로 전송하기 위하여 상기 메모리 수단, 상기 프로세서 수단 및 상기 키 생성 수단과 결합하여 동작하는 송신기 수단을 포함하는 것을 특징으로 하는 가입자 장치.
- 3A communication device for performing user identification in communication with a subscriber device of a communication system; (a) receiver means for receiving the first subscriber device identifier, the user acknowledgment message and the encrypted data in one message; (b) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information; (c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information; and (d) processor means operative in combination with said receiver means, said memory means and said key generating means for determining whether the communicated user acknowledgment message is genuine; i) generator means for generating an expected user confirmation message as a function of said first shared secret data, said random attempt and said moment specific information; ii) comparing means for comparing the received user confirmation message with the expected user confirmation message; iii) a telephone that uniquely identifies the target communication device by decrypting the communicated encrypted data using the session key as a decryption variable if the received user confirmation message is essentially similar to the expected user confirmation message means for recovering a number and the second subscriber device identifier and for establishing a communication link on a fraffic channel between the subscriber device and the communication device; and iv) if the received user acknowledgment message is not substantially similar to the expected user acknowledgment message, then processor means comprising means for providing an output indicating that a plurality of users are about to access the communication system. A communication device comprising:통신 시스템의 가입자 장치와의 통신에서 사용자 확인을 수행하는 통신 장치에 있어서;(a) 하나의 메시지 내에서 제1 가입자 장치 식별자, 사용자 확인 메시지 및 암호화된 데이타를 수신하기 위한 수신기 수단;(b) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;및 (d) 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하기 위하여 상기 수신기 수단, 상기 메모리 수단 및 상기 키 생성 수단과 결합하여 동작하는 프로세서 수단으로서;i) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하기 위한 생성기 수단;ii) 상기 수신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교하기 위한 비교수단;iii) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하다면, 상기 세션 키를 해독 변수로 사용하여 상기 교신된 암호화된 데이타를 해독함으로써 상기 목표 통신 장치를 유일하게 식별해주는 전화 숫자 및 상기 제2 가입자 장치 식별자를 복구시키고, 상기 가입자 장치와 상기 통신 장치 사이에 소통 채널(a fraffic channel) 상의 통신 링크(a communication link)를 설정하기 위한 수단;및 iv) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하지 않다면, 다수의 사용자가 상기 통신 시스템에 엑세스하려 함을 지시하는 출력을 제공하기 위한 수단을 포함하는 프로세서 수단을 포함하는 것을 특징으로 하는 통신 장치.
- 5A communication device for performing user verification in communication with a subscriber device operating within a communication system;(a) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information;(b) processor means operative in combination with said memory means to generate a user confirmation message as a function of said first shared secret data, said random attempt and said instantaneous specific information;(c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information;(d) encryption means operative in conjunction with said key generating means to form encrypted data by encrypting a second subscriber device identifier using said session key as an encryption variable;and (e) transmitter means operative in combination with said memory means, said processor means and said key generating means for transmitting said user confirmation message and said encrypted data to said subscriber device in a message. communication device with 통신 시스템 내에서 동작하는 가입자 장치와의 통신에서 사용자 확인을 수행하는 통신 장치에 있어서;(a) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(b) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 프로세서 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;(d) 상기 세션 키를 암호화 변수로 사용하여 제2 가입자 장치 식별자를 암호화함으로써 암호화된 데이타를 형성하기 위하여 상기 키 생성 수단과 결합하여 동작하는 암호화 수단;및 (e) 하나의 메시지 내에서 상기 사용자 확인 메시지 및 상기 암호화된 데이타를 상기 가입자 장치로 전송하기 위하여 상기 메모리 수단, 상기 프로세서 수단 및 상기 키 생성 수단과 결합하여 동작하는 송신기 수단을 포함하는 것을 특징으로 하는 통신 장치.
- 6A subscriber device for performing user identification in communication with a communication device of a communication system; (a) receiver means for receiving a user acknowledgment message and encrypted data in one message; (b) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information; (c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information; and (d) processor means operative in combination with said receiver means, said memory means and said key generating means for determining whether the communicated user acknowledgment message is genuine; i) generator means for generating an expected user confirmation message as a function of said first shared secret data, said random attempt and said moment specific information; ii) comparing means for comparing the received user acknowledgment message with the expected user acknowledgment message; iii) if the received user acknowledgment message is essentially similar to the expected user acknowledgment message, recover the second subscriber device identifier by decrypting the communicated encrypted data using the session key as a decryption variable; means for establishing a communication link on a communication channel between the subscriber device and the communication device; and iv) if the received user acknowledgment message is not substantially similar to the expected user acknowledgment message, then processor means comprising means for providing an output indicating that a plurality of users are about to access the communication system. A subscriber device comprising:통신 시스템의 통신 장치와의 통신에서 사용자 확인을 수행하는 가입자 장치에 있어서;(a) 하나의 메시지 내에서 사용자 확인 메시지와 암호화된 데이타를 수신하기 위한 수신기 수단;(b) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;및 (d) 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하기 위하여 상기 수신기 수단, 상기 메모리 수단 및 상기 키 생성 수단과 결합하여 동작하는 프로세서 수단으로서;i) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하기 위한 생성기 수단;ii) 상기 수신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교하기 위한 비교 수단;iii) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하다면, 상기 세션 키를 해독 변수로 사용하여 상기 교신된 암호화된 데이타를 해독함으로써 상기 제2 가입자 장치 식별자를 복구시키고, 상기 가입자 장치와 상기 통신 장치 사이에 소통 채널 상의 통신 링크를 설정하기 위한 수단;및 iv) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하지 않다면, 다수의 사용자가 상기 통신 시스템에 엑세스하려 함을 지시하는 출력을 제공하기 위한 수단을 포함하는 프로세서 수단을 포함하는 것을 특징으로 하는 가입자 장치.
- 7A method for identifying a user between a subscriber device and a communication device in a communication system, the method comprising;(a) providing instantaneous specific information to the subscriber device and the communication device;(b) generating a user confirmation message as a function of the instantaneous specific information;(c) communicating the user acknowledgment message between the subscriber device and the communication device;(d) generating an expected user confirmation message as a function of the instantaneous specific information;and (e) determining whether the communicated user acknowledgment message is genuine by comparing the communicated user acknowledgment message with the expected user acknowledgment message. 통신 시스템의 가입자 장치와 통신 장치 사이의 사용자 확인 방법에 있어서;(a) 상기 가입자 장치와 상기 통신 장치에 순간 특정 정보를 제공하는 단계;(b) 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하는 단계;(c) 상기 가입자 장치와 상기 통신 장치 사이에서 상기 사용자 확인 메시지를 교신하는 단계;(d) 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하는 단계;및 (e) 상기 교신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교함으로써 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하는 단계를 포함하는 것을 특징으로 하는 사용자 확인 방법.
- 10A method for maintaining security of packet data communication through encryption processing between a subscriber device and a wireless communication device of a communication system in operation;(a) generating a packetized message encryption key within the subscriber device and the operating communication system;(b) assigning unique packet numbers to packets of a message such that the order of the packets within the packetized message is maintained;(c) encrypting the packet of the message using an encryption key and a unique packet number of the packetized message as an encryption variable;(d) communicating said unique packet number and an encrypted packet of said message between said subscriber device and a wireless communication device of said operating communication system;and (e) decrypting the transmitted encrypted packet of the message using the generated packetized message encryption key and the transmitted unique packet number. 동작 중인 통신 시스템의 가입자 장치와 무선 통신 장치 사이에서 암호화 처리를 통해 패킷 데이타 통신의 보안을 유지하는 방법에 있어서;(a) 상기 가입자 장치 및 상기 동작 중인 통신 시스템 내에 패킷화된 메시지의 암호화 키(a packetized message encryption key)를 생성하는 단계;(b) 상기 패킷화된 메시지 내에서의 패킷의 순서가 유지되도록 메시지의 패킷에 고유 패킷 번호를 부여하는 단계;(c) 상기 패킷화된 메시지의 암호화 키 및 고유 패킷 번호를 암호화 변수로 이용하여 상기 메시지의 패킷을 암보호화하는 단계;(d) 상기 가입자 장치와 상기 동작 중인 통신 시스템의 무선 통신 장치 간에 상기 고유 패킷 번호와 상기 메시지의 암호화된 패킷을 교신하는 단계;및 (e) 상기 생성된 패킷화된 메시지의 암호화 키 및 상기 교신된 고유 패킷 번호를 이용하여 상기 메시지의 교신된 암호화된 패킷을 해독하는 단계를 포함하는 것을 특징으로 하는 패킷 데이타 통신 보완 유지 방법.
Independent claims6
38 paragraphs, as filed
[Name of invention]
Efficient real-time user identification and encryption method of communication system and its device
[Field of invention]
The present invention relates to communication systems, and in particular to user identification and encryption of communication systems.
[Background of the invention]
Many communication systems currently use user verification and encryption to improve the security of the system. Such communication systems include not only wired and wireless data networks, but also cellular radio telephone communication systems, personal communication systems, and paging systems. Hereinafter, a cellular communication system will be described as an example, but if you are an expert in the technical field of the present invention, it will be appreciated that the described user identification and encryption technology can be easily extended to other communication systems without departing from the scope and concept of the present invention. will be. Now returning to the cellular communication system, typically in this system, a subscriber unit that communicates with a fixed network communication unit via a radio frequency (hereinafter referred to as RF) communication link ( It includes a subscriber unit (such as a mobile or portable device) that communicates with a mobile or portable communication unit. A typical cellular communication system includes at least one base station (ie, communication device) and a switching center. The switching center accessed by the subscriber device may not be its home switching center. In this case, the subscriber device is referred to as a roaming subscriber unit. The switching center accessed by the subscriber device (referred to as a visited switching center) is to obtain information about the subscriber device and return service charge information to its subscription switching center (i.e., a subscription communication system). In addition, communication with the subscribing switching center must be made through a public switched telephone network (PSTN) or another type of connection such as a satellite link.
One of the duties of a fixed network communication device is to allow the subscriber device to use the communication system after requesting that the subscriber device meets the user identification requirements of the system. In a typical cellular telephone system, a telephone number (mobile identification number, MIN) (hereinafter referred to as a first subscriber device identifier) that allows each subscriber device to identify the subscriber device from any fixed network communication device. ) And an identification number (or serial number) (hereinafter referred to as SN) (hereinafter referred to as a second subscriber device identifier) are assigned. Each subscriber device has a unique identification number that distinguishes it from other subscriber devices. Fixed network communication devices access this identification number through a database. Often, fixed network communication devices use this number to bill the subscriber for the time the system has been used. In the case of a floating subscriber device, the visiting switching center must communicate with the subscriber's subscription system's database to identify and bill the subscriber's users. If such communication is required for each call of the subscriber device, it will cause a serious call waiting delay. When the presser calls another device, he enters the phone number (i.e., the phone number number) to call. The phone number becomes data to be transmitted to the fixed network communication device. The data may also include other information about a third-party communication device, such as the location of the device.
The legitimate subscriber's identification number is exposed by RF eavesdropping, or by intentionally or inadvertently leaking the MIN/SN combination by a wireless telephone installer. Once the subscriber's phone number and identification number are known (if stolen), the thief reprograms another subscriber device with the stolen identification number, so that two or more subscriber devices have the same MIN/SN combination. Cellular wireless telephone systems have a user authentication process that prevents subscribers who do not have valid identification numbers from accessing them, but can effectively attenuate the effect of detecting a large number of users or leaking the subscriber's identification number. I do not have the ability to have. Thus, the legitimate user is charged for both his own usage and the thief's usage.
Several user identification techniques are known. Sections 2 and 3 of EIA-553 describe how each user has a mobile identification number (MIN) and designates a serial number (SN) in the factory. The phone number to which the subscriber attempts a call is data transmitted by the subscriber to the fixed network communication device. If MIN and the corresponding SN are found in the database of the fixed network communication device, the user verification of this system is completed. Unfortunately, EIA-553 does not require the MIN or SN to be password-changed prior to transmission to the fixed network communication device, so any MIN or SN is directly exposed to RF eavesdropping. Also, this technique cannot prevent thieves who obtained MIN/SN from the installer.
Other user identification techniques are described in the European Cellular Communication System Recommendations established by Group Special Mobile (GSM) (see the following sections, ie 02.09, 02.17, 03.20 and 12.03). This method additionally requires the subscriber to publicly transmit a temporary mobile subscriber ID (hereinafter referred to as IMSI) to the fixed network communication device. The fixed network communication device generates and transmits a random number (RAND) to a subscriber. The enciphering technique allows a subscriber device to automatically obtain at least three encryption components from its memory, i.e. a predetermined enciphering key, SN (serial number) (user identification code of an individual subscriber; individual subscriber authentication key). ) And MIN (mobile identification number) (international mobile subscriber identification number; hereinafter referred to as IMSI). Then, the subscriber (device) encrypts his SN and MIN using a cipher to construct a RAND (random number) into a signed response. The subscriber device returns this approved response to the fixed network communication device, where the fixed network communication device checks the SN, MIN and encryption code against its database using the subscriber's temporary ID (TMSI).
The fixed network communication device generates its own response to the same random number by using information obtained from the database, and compares the approved response of the subscriber with the response generated by the fixed network communication device. If the response is essentially the same, the user verification is complete. The entered phone number can only be transmitted after approval of the user confirmation. This system can, to some extent, prevent thieves who obtained MIN/SN from installers by reassigning temporary TMSI and encrypting SN each time a subscriber enters another unit area.
Another user identification technique is described in the US Digital Cellular (USDC) standard (known as IS-54 and IS-55) published by the Electronics Industry Association (EIA) at 20006 Eye Street 2001, Washington, DC, New York. Like each of the above descriptions, USDC's user identification technology uses a series of specialized messages that must pass through both the subscriber device and the communication device of the communication system before system access is allowed. However, USDC's technology introduced a global challenge on the common signaling channel (e.g., a random access channel or a pliot channel). For user identification and voice privacy function, shared secret data (hereinafter referred to as SSD) (ie, an encryption code known to a subscriber device and a communication device constituting a communication link) is used. The first subscriber message sent includes a user acknowledgment, but no other data is encrypted. After the subscriber is assigned a communication channel, a command is sent from the service provider to the subscriber to start the encryption process.
The problem with this user identification technology is that it cannot provide a traffic channel, and message encryption cannot be performed based on one message transmission from a subscriber device to a communication device. In addition, the global attempt system used in USDC gives an illegal user an opportunity to imitate the call set-up messages of a legitimate user if the global attempt does not change frequently. For example, call waiting may be stopped as soon as the user responds to a global challenge. If the global attempt has not changed, since the phone number (i.e. phone number) is included in the user acknowledgment, a fraudulent user can imitate a user acknowledgment in order to be assigned a traffic channel to some unwanted target phone number have. If encryption is not possible and the fraudulent user can change the called party (i.e., who will answer the phone), the user makes a free call. Even if this assumption is not plausible, it can be a more serious problem in personal communication systems with a large number of users. Therefore, there is a need for a user identification technology that can alleviate this problem.
In addition to user identification technology, many communication systems are designed to enable secure/encrypted communication. In such communication systems, packetized data also needs to be encrypted. Packetized data adds another problem to the typical encryption process. This is because packets of data arrive at different times at different times at the subscriber device of the communication device (ie, the packet message is not connected). These packets must be rearranged and decrypted in the same order they were encrypted. Also, encryption codes can be processed only when a subscriber registers. Accordingly, there is a need for an encryption technique to alleviate these problems related to packetized data.
[Summary of the invention]
This need is met by providing a method and apparatus for user identification between a communication device and a subscriber device of a communication system. User verification is performed by providing the subscriber device and the communication device with a first subscriber device identifier, a first shared secret data, a second shared secret data, a random challenge and instant-specific information. It also generates a user confirmation message as a function of the first shared secret data, random attempts and moment specific information. In addition, a session key is generated as a function of the first shared secret data, the second shared secret data, the random attempt and moment specific information. Further, by using the session key as an encryption variable, a phone number that uniquely identifies the target communication device and a second subscriber device identifier are encrypted to form encrypted data. Subsequently, a first subscriber device identifier, a user confirmation message, and encrypted data are communicated between the subscriber device and the communication device in one message. It also generates an expected user confirmation message as a function of the first shared secret data, random attempt and moment specific information. In this way, it is determined whether the communicated user confirmation message is true based on the comparison between the communicated user confirmation message and the expected user confirmation message. If the transmitted user confirmation message is determined to be true, the session key is used as a decryption variable, and the telephone number and the second subscriber device identifier that uniquely identify the target communication device are decrypted from the encrypted data and the subscriber Establish a communication link on a communication channel between the device and the communication device. On the other hand, if it is determined that the communicated user confirmation message is not genuine, it provides an output indicating that multiple users are attempting to access the communication system.
Another user identification process that improves user identification is provided by providing instantaneous specific information to subscriber devices and communication devices. This moment-specific information is used to generate a user confirmation message as a function of this moment-specific information. The user confirmation message is communicated between the subscriber device and the communication device. It also generates an expected user confirmation message as a function of moment-specific information. Finally, by comparing the communicated user confirmation message and the expected user confirmation message, a decision as to whether the communicated user confirmation message is true is made.
In addition, there is provided a method of maintaining the secret of packet data communication between a subscriber device of a communication system and a wireless communication device through an encryption process. The encryption process includes generating an encryption key for a packetized message in a communication system with a subscriber device. In addition, a unique packet number is assigned to at least one packet of a message to be communicated so that the order of packets in the packetized message can be maintained. Packets of these messages are encrypted using the unique packet number and the encryption key of the packetized message to the encryption variable. The unique packet number and the encrypted packet of the message are communicated between the wireless communication device and the subscriber device of the communication system. Finally, the encrypted packet of the communicated message is decrypted using the encryption key of the packetized message and the communicated unique packet number.
[Brief description of drawings]
Fig. 1 is a block diagram showing a preferred embodiment with a subscriber device and a fixed network communication device of the present invention.
Fig. 2 is a flow chart of a preferred embodiment of a user identification method used by a subscriber device or a fixed network communication device of the present invention.
FIG. 3 is a flow chart of a preferred embodiment of a method for providing shared secret data to a communication device operating according to the user identification method of the invention shown in FIG.
Figure 4 is a flow diagram of a preferred embodiment of a method for providing a random challenge according to the user identification method of the present invention shown in Figure 2;
Fig. 5 is a flow chart of a preferred embodiment of an encryption and decryption method used by a subscriber device or a fixed network communication device according to the present invention.
[Detailed description of the invention]
FIG. 1 is a general diagram of a subscriber communication device 100, such as a subscriber telephone, and a fixed network communication device 130, such as a cellular telephone base station and switching center. The subscriber communication device 100 includes a microprocessing stage 118 that performs user verification and encryption, which are various preferred embodiments, by accessing a nonvolatile memory device 106 and a radio frequency (hereinafter, RF) stage 122. do. Other components accessed by the microprocessing stage 118 include a key input pad of the phone (for entering phone number-data). A data input stage 102 for inputting voices or other data to be transmitted, a random number generator (to generate random attempts) 104 and an encryption/decryption device 120 are included.
The nonvolatile memory device 106 has the characteristics of a serial number 110 (corresponding to a subscriber device) and a subscriber phone number 108 (for example, a mobile identification number MIN), as a first subscriber device identifier. Can be used) is stored. The serial number 110 is used as a second subscriber device identifier known only to the subscriber device and the fixed network device. For example, this number should not be known to the installer of the subscriber device, but only to the legitimate user of the subscriber device and the database of the fixed network communication device. These identifiers do not have to be numeric, but only have properties that can be identified by a fixed network communication device. For example, in another embodiment in a cellular system, a stored lookup table including a set of a plurality of serial numbers and a set of each identifier is a specific cellular area or a fixed network communication device. Include the corresponding phone number. The memory device 106 is also used as a storage of keys generated by the encryption/decryption device 120. These keys contain the first shared secret data (SSD<sub>A</sub>)(112), the second shared secret data (SSD<sub>B</sub>) 114 and third shared secret data (i.e., packetized data key).
In the fixed network communication device 130, like the subscriber device 100, a microcomputer that operates in connection with a link to the database 136 and the base station radio frequency stage 152 to perform user verification and encryption processing. An exchange center including a processing stage 148 is included. Other components accessed by the microprocessing stage 148 include a random number generator 134 and an encryption/decryption device 150. In addition, the switching center includes an interface to the public telephone network (PSTN). The public telephone network link can be used for communication between the visiting switching center and the subscription switching center necessary for user identification and billing of the floating subscriber device.
The database contains keys associated with the phone number 138 generated from the encryption/decryption device or received from the subscription switching center, as well as the subscriber device such as the serial number 140 and the associated subscriber phone number 138. Information is included. These keys contain the first shared secret data ((SSD<sub>A</sub>) (142), the second shared secret data (SSD<sub>B</sub>) 144 and third shared secret data 146 (i.e., packetized data key). Communication between the subscriber communication device 100 and the fixed network communication device 130 is performed by RF transmission between the antennas 124 and 154 of the two devices, respectively, according to a known technology of a cellular system.
As shown in FIG. 2, the subscriber device 100 and the fixed network communication device 130 perform user verification in an essentially similar manner. The method 200 of user identification between a subscriber device of a communication system and a communication device includes a first subscriber device identifier, a first shared secret data (SSD) in the subscriber device 100 and the communication device 130.<sub>A</sub>), the second shared secret data (SSD<sub>B</sub>), random attempt (RAND), and instantaneous specific information (IS INFO). In addition, the method includes a user confirmation message (AUTH) as a function of the first shared secret data, random attempt and moment specific information.<sub>RESP</sub>) To generate (202). Such user confirmation messages are generated by one-way encryption, which the unauthorized user cannot decrypt (eg, real-time decryption) sufficiently quickly. Such a one-way encryption technology is known as the Digital Signature Algorithm developed by The National Institute for Science and Technology and described in US Patent Application No. 07/736.451.
Those skilled in the art of the present invention will understand that no matter what one-way encryption algorithm is used in this user verification process, it does not depart from the scope of the spirit of the present invention. In addition, a session key is generated 206 as a function of the first shared secret data, the second shared secret data, the random attempt, and moment specific information. In addition, encrypted data is formed by encrypting a second subscriber device identifier and a phone number uniquely identifying the target communication device using the session key as an encryption variable (208). Subsequently, between the subscriber device 100 and the communication device 130, a first subscriber device identifier, a user confirmation message, and encrypted data are communicated 210 within one message. The device under user verification (i.e., the receiving subscriber device 100 or communication device 130) is essentially the same way as in step 204, the first shared secret data, the random attempt and the expected user confirmation message which is a function of the moment-specific information Further, the device under user confirmation compares the communicated user confirmation message with the expected user confirmation message and determines whether the communicated user confirmation message is true (214). If the user confirmation message was true, by decrypting the encrypted data communicated with the session key as a decryption variable, the telephone number and the second subscriber device identifier uniquely identifying the target communication device are recovered (218), and the subscriber device By establishing 220 a link on a communication channel between 100 and the communication device 130, continuous communication between the subscriber device and the communication device is permitted. On the other hand, if the communicated user confirmation message was not true, it provides an output indicating that multiple users are attempting to access the communication system.
As shown in FIG. 3, in the process 300 of providing the first shared secret data and the second shared secret data, if the communicated first subscriber identifier is known to the communication system 130 (i.e., data If described in the base 136), by searching 304 the first shared secret data 142 and the second shared secret data 144 associated with the first subscriber device identifier, the communicated first subscriber identifier 108 , 138) (i.e., a subscriber's telephone number) to obtain the first shared secret data 142 and the second shared secret data 144 (302). Alternatively, if the communicated first subscriber device identifier is not known to the communication system 130, the first shared secret data 142 and the second shared secret data 144 are different from other communication systems (for example, a public telephone network ( 132), and then the first shared secret data 142 and the second shared secret data 144 associated with the communicated first subscriber device identifier 108 are extracted (308), Then, the first shared secret data and the second shared secret data are obtained by storing 310 in a database of the communication device. As a result (312), even if there is no priority information on the subscriber device 130 requesting a service from the communication equipment, a process of providing the first shared secret data and the second shared secret data can be performed.
As shown in FIG. 4, the process of providing a random attempt to the subscriber device 100 and the communication device 130 (i.e., steps 400 to 406) generates a random attempt at the communication device 130 (402). ), and periodically transmitting an arbitrary attempt to be received by the subscriber device 100 on a common system signal channel 126. Or (that is, when the subscriber device 100 is performing user verification), the processing is performed by the subscriber device 100 to generate a random attempt, and a signal channel 126 to receive a random attempt to be received by the communication device 130. ) Is defined as including the step of transmitting.
The specific information at the moment used in the user identification process is constantly changing, but includes some types of information available in the subscriber device 100 and the communication device 130 at any given time. The specific information at this moment includes one or more of the following types of information: The specific information at this moment includes one or more of the following types of information: That is, time (a time of day), radio frequency carrier frequency (radio frequency carrier frequency), time slot number (a time slot number), radio port number (a radio port number), access manager identifier (access manager identifier) , A radio port control unit identifier and a base site manager identifier.
An expert in the technical field of the present invention will be able to recognize a user identification method in which several changes have been made to the preferred embodiment described above within the scope of the spirit of the present invention. For example, the user confirmation message and the encrypted data may be transferred to the subscriber device 100 and the communication device 130, such as a rolling key, a call counter, or a hand-off counter. It can also be formed as a function of other types of information available to everyone. It is also possible to encrypt and communicate more data as encrypted data.
The subscriber device 100 and the fixed network communication device perform an encryption/decryption function in a manner essentially similar to that shown in FIG. 5. A method of maintaining 500 security of packet data communication through an encryption process between the subscriber device 100 and the wireless communication device 130 of the communication system is the subscriber device 100 and the communication system 130 in operation. Generating (502) an encryption key for the message packetized within. In addition, in order to maintain the order of packets in the packetized message, a unique packet number is assigned to the packet of the message (504). For example, if the entire message consists of three packets, each packet is assigned a unique number that allows them to be combined to form the entire message. It is preferable that this unique packet number includes an offset that distinguishes each message so that any two messages can be distinguished from each other. Subsequently, the packet of the message is encrypted 506 using the encryption key and the unique packet number of the packetized message as encryption variables. Subsequently, the unique number and the encrypted packet of the message are communicated 508 between the subscriber device 100 and the wireless communication device 130 of the operating communication system. Finally, in order to complete (512) the security maintenance communication process of the packet data, the encrypted packet of the communicated message is decrypted using the encryption key of the generated packetized message and the communicated unique packet number (510). do. Those skilled in the art will recognize that each remaining packet of the message to be transmitted can be encrypted and decrypted according to the same procedure as the single packet processing described above. In addition, the packet of the message to be communicated includes not only the combination of both the voice information and the data information format, but also voice information or data information.
This method of maintaining the security of packet data communication can also be used for communication transmitted from the subscriber device 100 to the communication device 130. For example, the packet numbering step 504 and the packet encryption step 506 are performed by the subscriber device. Subsequently, the unique packet number and the encrypted packet of the message are transmitted from the subscriber device 100 to the wireless communication device 130 of the operating communication system. Finally, packet decryption is performed in the wireless communication device 130 of the operating communication system. Similarly, the packet numbering step 504 and the packet encryption step 506 are performed in the communication device. Subsequently, the unique packet number and the encrypted packet of the message are transmitted from the wireless communication device 130 to the subscriber device 100. Finally, the subscriber device 100 performs packet decryption.
Although the present invention has been described to some extent, it should be understood that the technology of the present embodiment is disclosed by way of example only, and various changes and combinations, etc., which do not depart from the scope of the spirit of the present invention claimed in the claims If you are an expert in the field of technology, you will recognize it. For example, the communication channel may be any type of communication channel, such as an electronic data bus, wire, optical fiber link, or satellite link.
14 members in 8 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 8084664 | United States of America | – | |
| 8466493 | United States of America | A | |
| 8466493 | United States of America | A | |
| 9405726 | United States of America | W | |
| 9405726 | United States of America | W | |
| 8084664 | – | – | – |
| PCTUS9405726 | – | – | – |
| US19930084664 | – | – | – |
| WO1994US05726 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| CA2141318A1 | Canada | A1 | |
| WO9501684A1 | World Intellectual Property Organization (WIPO) | A1 | |
| MX9404953A | Mexico | A | |
| FI950714A | Finland | A | |
| FI950714A0 | Finland | A0 | |
| EP0663124A1 | European Patent Office (EPO) | A1 | |
| KR950703236A | Republic of Korea | A | |
| US5455863A | United States of America | A | |
| JPH08500950A | Japan | A | |
| US5689563A | United States of America | A | |
| CA2141318C | Canada | C | |
| KR0181566B1 | Republic of Korea | B1 | |
| KR100181566B1This record | Republic of Korea | B1 | |
| EP0663124A4 | European Patent Office (EPO) | A4 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapse due to unpaid annual feeLapsedLAPS | LAPS | |
| Annual fee paymentFPAY | FPAY | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 1001815660000
- Publication, DOCDB
- 0181566
- Publication, EPODOC
- KR0181566B
- Application
- 100700812
- Application, DOCDB
- 19950700812
- Application, EPODOC
- KR19950700812
Titles3
- English
- Efficient real-time user identification and encryption method and device for communication system
- Korean
- 통신 시스템의 효율적인 실시간 사용자 확인 및 암호화 방법 및 그 장치
- English
- Efficient real-time user identification and encryption method of communication system and its device
Classification
- CPC, 4
- H04L9/3297
- H04L9/32
- H04L2209/56
- H04L2209/80
- IPC, 2
- H04Q7 38
- H04L9 32
Designated states22
- Regional, 18
- EP 유럽특허
- 오스트리아
- 벨기에
- 스위스
- 리히텐슈타인
- 독일
- 덴마크
- 스페인
- 프랑스
- 영국
- 그리스
- 아일랜드
- 이탈리아
- 룩셈부르크
- 모나코
- 네덜란드
- 포르투갈
- 스웨덴
- National, 4
- 캐나다
- 핀란드
- 일본
- 대한민국