KR100181566B1

Method and apparatus for efficient real-time authentication and encryption in a communication system.

Abstract

Radio frequency cellular switching systems often require both the subscriber device 100 and the communication device 130 of the fixed network communication system to not only provide encryption parameters for encryption processing of messages, but also maintain secret data to be used for user identification processing. Demand. The present invention discloses an efficient real-time user identification method and apparatus using one message 210 that provides user identification and communication link waiting information. In addition, in order to improve the reliability of user identification processing, user identification using instantaneous specific information such as time, carrier frequency of radio frequency, time slot number, radio port number, access manager identifier, radio port control device identifier or base station controller identifier, etc. A method and apparatus are disclosed. Further, a method and apparatus for maintaining the security of packet data communication through encryption processing using the encryption key 502 of a packetized message and a unique packet number 504 as encryption variables are provided.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

10 claims: 6 independent, 4 dependent

  1. 1
    A subscriber device for performing user identification in communication with a communication device of a communication system;(a) memory means for maintaining the first subscriber device identifier, the first shared secret data, the second shared secret data, the random trial and moment specific information;(b) processor means operative in combination with said memory means to generate a user confirmation message as a function of said first shared secret data, said random attempt and said instantaneous specific information;(c) a key operative in combination with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said moment specific information. ) means of generating;(d) encryption means operating in combination with said key generating means to form encrypted data by encrypting a second subscriber device identifier and a telephone number uniquely identifying a target communication device using the session key as an encryption variable ;and (e) operating in combination with said memory means, said processor means and said key generating means for transmitting said first subscriber device identifier, said user confirmation message and said encrypted data to said communication device in a single message. A subscriber device comprising transmitter means. 통신 시스템의 통신 장치와의 통신에서 사용자 확인을 수행하는 가입자 장치에 있어서;(a) 제1 가입자 장치 식별자, 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(b) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 프로세서 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키(a session key)를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키(key) 생성 수단;(d) 상기 세션 키를 암호화 변수로 사용하여, 목표 통신 장치를 유일하게 식별해주는 전화 숫자 및 제2 가입자 장치 식별자를 암호화 함으로써 암호화된 데이타를 형성하기 위하여 상기 키 생성 수단과 결합하여 동작하는 암호화 수단;및 (e) 하나의 메시지 내에서 상기 제1 가입자 장치 식별자, 상기 사용자 확인 메시지 및 상기 암호화된 데이타를 상기 통신 장치로 전송하기 위하여 상기 메모리 수단, 상기 프로세서 수단 및 상기 키 생성 수단과 결합하여 동작하는 송신기 수단을 포함하는 것을 특징으로 하는 가입자 장치.
  2. 3
    A communication device for performing user identification in communication with a subscriber device of a communication system; (a) receiver means for receiving the first subscriber device identifier, the user acknowledgment message and the encrypted data in one message; (b) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information; (c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information; and (d) processor means operative in combination with said receiver means, said memory means and said key generating means for determining whether the communicated user acknowledgment message is genuine; i) generator means for generating an expected user confirmation message as a function of said first shared secret data, said random attempt and said moment specific information; ii) comparing means for comparing the received user confirmation message with the expected user confirmation message; iii) a telephone that uniquely identifies the target communication device by decrypting the communicated encrypted data using the session key as a decryption variable if the received user confirmation message is essentially similar to the expected user confirmation message means for recovering a number and the second subscriber device identifier and for establishing a communication link on a fraffic channel between the subscriber device and the communication device; and iv) if the received user acknowledgment message is not substantially similar to the expected user acknowledgment message, then processor means comprising means for providing an output indicating that a plurality of users are about to access the communication system. A communication device comprising:통신 시스템의 가입자 장치와의 통신에서 사용자 확인을 수행하는 통신 장치에 있어서;(a) 하나의 메시지 내에서 제1 가입자 장치 식별자, 사용자 확인 메시지 및 암호화된 데이타를 수신하기 위한 수신기 수단;(b) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;및 (d) 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하기 위하여 상기 수신기 수단, 상기 메모리 수단 및 상기 키 생성 수단과 결합하여 동작하는 프로세서 수단으로서;i) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하기 위한 생성기 수단;ii) 상기 수신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교하기 위한 비교수단;iii) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하다면, 상기 세션 키를 해독 변수로 사용하여 상기 교신된 암호화된 데이타를 해독함으로써 상기 목표 통신 장치를 유일하게 식별해주는 전화 숫자 및 상기 제2 가입자 장치 식별자를 복구시키고, 상기 가입자 장치와 상기 통신 장치 사이에 소통 채널(a fraffic channel) 상의 통신 링크(a communication link)를 설정하기 위한 수단;및 iv) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하지 않다면, 다수의 사용자가 상기 통신 시스템에 엑세스하려 함을 지시하는 출력을 제공하기 위한 수단을 포함하는 프로세서 수단을 포함하는 것을 특징으로 하는 통신 장치.
  3. 5
    A communication device for performing user verification in communication with a subscriber device operating within a communication system;(a) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information;(b) processor means operative in combination with said memory means to generate a user confirmation message as a function of said first shared secret data, said random attempt and said instantaneous specific information;(c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information;(d) encryption means operative in conjunction with said key generating means to form encrypted data by encrypting a second subscriber device identifier using said session key as an encryption variable;and (e) transmitter means operative in combination with said memory means, said processor means and said key generating means for transmitting said user confirmation message and said encrypted data to said subscriber device in a message. communication device with 통신 시스템 내에서 동작하는 가입자 장치와의 통신에서 사용자 확인을 수행하는 통신 장치에 있어서;(a) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(b) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 프로세서 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;(d) 상기 세션 키를 암호화 변수로 사용하여 제2 가입자 장치 식별자를 암호화함으로써 암호화된 데이타를 형성하기 위하여 상기 키 생성 수단과 결합하여 동작하는 암호화 수단;및 (e) 하나의 메시지 내에서 상기 사용자 확인 메시지 및 상기 암호화된 데이타를 상기 가입자 장치로 전송하기 위하여 상기 메모리 수단, 상기 프로세서 수단 및 상기 키 생성 수단과 결합하여 동작하는 송신기 수단을 포함하는 것을 특징으로 하는 통신 장치.
  4. 6
    A subscriber device for performing user identification in communication with a communication device of a communication system; (a) receiver means for receiving a user acknowledgment message and encrypted data in one message; (b) memory means for maintaining the first shared secret data, the second shared secret data, random trial and instantaneous information; (c) key generating means operative in conjunction with said memory means to generate a session key as a function of said first shared secret data, said second shared secret data, said random attempt and said instant specific information; and (d) processor means operative in combination with said receiver means, said memory means and said key generating means for determining whether the communicated user acknowledgment message is genuine; i) generator means for generating an expected user confirmation message as a function of said first shared secret data, said random attempt and said moment specific information; ii) comparing means for comparing the received user acknowledgment message with the expected user acknowledgment message; iii) if the received user acknowledgment message is essentially similar to the expected user acknowledgment message, recover the second subscriber device identifier by decrypting the communicated encrypted data using the session key as a decryption variable; means for establishing a communication link on a communication channel between the subscriber device and the communication device; and iv) if the received user acknowledgment message is not substantially similar to the expected user acknowledgment message, then processor means comprising means for providing an output indicating that a plurality of users are about to access the communication system. A subscriber device comprising:통신 시스템의 통신 장치와의 통신에서 사용자 확인을 수행하는 가입자 장치에 있어서;(a) 하나의 메시지 내에서 사용자 확인 메시지와 암호화된 데이타를 수신하기 위한 수신기 수단;(b) 제1 공유 비밀 데이타, 제2 공유 비밀 데이타, 임의적 시도 및 순간 특정 정보를 유지하기 위한 메모리 수단;(c) 상기 제1 공유 비밀 데이타, 상기 제2 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 세션 키를 생성하기 위하여 상기 메모리 수단과 결합하여 동작하는 키 생성 수단;및 (d) 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하기 위하여 상기 수신기 수단, 상기 메모리 수단 및 상기 키 생성 수단과 결합하여 동작하는 프로세서 수단으로서;i) 상기 제1 공유 비밀 데이타, 상기 임의적 시도 및 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하기 위한 생성기 수단;ii) 상기 수신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교하기 위한 비교 수단;iii) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하다면, 상기 세션 키를 해독 변수로 사용하여 상기 교신된 암호화된 데이타를 해독함으로써 상기 제2 가입자 장치 식별자를 복구시키고, 상기 가입자 장치와 상기 통신 장치 사이에 소통 채널 상의 통신 링크를 설정하기 위한 수단;및 iv) 만약, 상기 수신된 사용자 확인 메시지가 상기 예상 사용자 확인 메시지와 본질적으로 유사하지 않다면, 다수의 사용자가 상기 통신 시스템에 엑세스하려 함을 지시하는 출력을 제공하기 위한 수단을 포함하는 프로세서 수단을 포함하는 것을 특징으로 하는 가입자 장치.
  5. 7
    A method for identifying a user between a subscriber device and a communication device in a communication system, the method comprising;(a) providing instantaneous specific information to the subscriber device and the communication device;(b) generating a user confirmation message as a function of the instantaneous specific information;(c) communicating the user acknowledgment message between the subscriber device and the communication device;(d) generating an expected user confirmation message as a function of the instantaneous specific information;and (e) determining whether the communicated user acknowledgment message is genuine by comparing the communicated user acknowledgment message with the expected user acknowledgment message. 통신 시스템의 가입자 장치와 통신 장치 사이의 사용자 확인 방법에 있어서;(a) 상기 가입자 장치와 상기 통신 장치에 순간 특정 정보를 제공하는 단계;(b) 상기 순간 특정 정보의 함수로서의 사용자 확인 메시지를 생성하는 단계;(c) 상기 가입자 장치와 상기 통신 장치 사이에서 상기 사용자 확인 메시지를 교신하는 단계;(d) 상기 순간 특정 정보의 함수로서의 예상 사용자 확인 메시지를 생성하는 단계;및 (e) 상기 교신된 사용자 확인 메시지와 상기 예상 사용자 확인 메시지를 비교함으로써 상기 교신된 사용자 확인 메시지가 진정한 것인지를 결정하는 단계를 포함하는 것을 특징으로 하는 사용자 확인 방법.
  6. 10
    A method for maintaining security of packet data communication through encryption processing between a subscriber device and a wireless communication device of a communication system in operation;(a) generating a packetized message encryption key within the subscriber device and the operating communication system;(b) assigning unique packet numbers to packets of a message such that the order of the packets within the packetized message is maintained;(c) encrypting the packet of the message using an encryption key and a unique packet number of the packetized message as an encryption variable;(d) communicating said unique packet number and an encrypted packet of said message between said subscriber device and a wireless communication device of said operating communication system;and (e) decrypting the transmitted encrypted packet of the message using the generated packetized message encryption key and the transmitted unique packet number. 동작 중인 통신 시스템의 가입자 장치와 무선 통신 장치 사이에서 암호화 처리를 통해 패킷 데이타 통신의 보안을 유지하는 방법에 있어서;(a) 상기 가입자 장치 및 상기 동작 중인 통신 시스템 내에 패킷화된 메시지의 암호화 키(a packetized message encryption key)를 생성하는 단계;(b) 상기 패킷화된 메시지 내에서의 패킷의 순서가 유지되도록 메시지의 패킷에 고유 패킷 번호를 부여하는 단계;(c) 상기 패킷화된 메시지의 암호화 키 및 고유 패킷 번호를 암호화 변수로 이용하여 상기 메시지의 패킷을 암보호화하는 단계;(d) 상기 가입자 장치와 상기 동작 중인 통신 시스템의 무선 통신 장치 간에 상기 고유 패킷 번호와 상기 메시지의 암호화된 패킷을 교신하는 단계;및 (e) 상기 생성된 패킷화된 메시지의 암호화 키 및 상기 교신된 고유 패킷 번호를 이용하여 상기 메시지의 교신된 암호화된 패킷을 해독하는 단계를 포함하는 것을 특징으로 하는 패킷 데이타 통신 보완 유지 방법.