Method and system for authentication number protection in a mobile telephone unit
Abstract
The mobile station comprises a memory 54 for storing traffic identification encryption means (TIE) and at least one identification number (A-key). According to the present invention, the protection system comprises a program 61 for encrypting the A-key by means of a TIE during operation and storing the encrypted A-key in A1, and the TIE when it is necessary to use it in uncoded form in the mobile station. and a program 62 for decrypting the A-key by means of a means. Application: security field of mobile wireless phone

Term
Term ended
Projected expiry passed 7 January 2018, 8.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
5 claims: 2 independent, 3 dependent
- 1트래픽 및 식별 암호화 수단과, 적어도 하나 이상의 확인 번호에 대한 보호 시스템과, 상기 확인 번호를 저장하는 기억 수단을 포함하고 있는 이동 무선 전화국에 있어서, 상기 보호 시스템은, 이동국의 동작 개시 시에 비코드화된 형태의 상기 확인 번호를 상기 트래픽 및 식별 암호화 수단으로 암호화하고, 암호화된 형태로만 확인 번호를 상기 기억 수단에 저장하며, 비코드화된 형태의 확인 번호를 이동국에서 이용할 경우에 상기 트래픽 및 식별 암호화 수단으로 상기 확인 번호를 암호해제하는 암호화 수단을 포함하고 있는 것을 특징으로 하는 이동 무선 전화국.
- 2제 1 항에 있어서, 상기 확인 번호는 확인 키 또는 A-key인 것을 특징으로 하는 이동 무선 전화국.
- 3제 2 항에 있어서, 제 2 보호 확인 번호는 SSD(Shared Secret Data)인 것을 특징으로 하는 이동 무선 전화국.
- 4제 1 항 내지 제 3 항중 어느 한 항에 있어서, 암호화 및 암호해제에 이용되는 제조자의 비밀 키를 포함하고 있으며, 이 비밀 키는 상기 이동국이 속한 일련의 유한 이동국들에 대해 예비되어 있는 것을 특징으로 하는 이동 무선 전화국.
- 5제 1 항 내지 제 4 항중 어느 한 항에 있어서, 상기 확인 번호는 상기 이동 무선 전화국에 의해 암호화되고, 저장되며, 상기 이동국에서 비코드화된 형태로 이용할 필요가 있는 경우에는 암호해제되는 것을 특징으로 하는 이동 무선 전화국.
Independent claims5
16 paragraphs, as filed
Mobile radio telephone company equipped with verification number protection system and method for protection of identification number
1 shows a device according to the invention;
Fig. 2 is a diagram showing encryption of a confirmation number;
Fig. 3 is a diagram showing decryption of a confirmation number;
Fig. 4 is a diagram showing updating of the confirmation number SSD by encryption based on A-key;
*Explanation of symbols for main parts of the drawing*
5 : Antenna 10 : Earphone
12 : Microphone 15 : Keyboard
17 : screen 20 : electronic assembly
40 : transmitter 42: receiver
50 : control unit 51: microcomputer
52 : program memory 53 : RAM
54 : Programmable ROM
<background-art><p>The present invention relates to a mobile radiotelephone station comprising traffic and identification encryption means, at least one identification number protection system and storage means for storing said identification number.</p><p>And the present invention relates to a method for protecting an identification number contained in a mobile radiotelephone office of the type described above.</p><p>This protection method is of particular interest for application in the field of AMPS type (or TACS and ETACS) and CDMA type mobile radiotelephone technology. In particular, important numbers in this field are identification numbers (ESN and MIN) of telephone apparatuses connectable to the AMPS network, which correspond to serial numbers of telephone apparatuses and identification numbers of telephone apparatuses, respectively. In order for infringers to charge a communication fee to others other than themselves, the identification number is something that intruders want to find out if they want to use a code that they do not own.</p><p>To protect itself against this type of cheating, the protection system disclosed at the outset of US Pat. No. 5,392,356 is known. According to this known protection system, the identification code is encrypted at the mobile station before being written into the mobile station's EEPROM, and thereafter, the identification code is decrypted and transmitted the moment the communication is transmitted. This technique prevents the identification code from simply being extracted and obtained from the EEPROM by hardware means.</p><p>However, identification codes such as MIN and ESN can always be found out due to communication interference between the mobile station and the base station, so that the above-described illegal acts are possible. </p><p>In order to prevent infringement while maintaining the integrity of the mobile station, more complex verification procedures are gradually inserted as the number of infringing actions against the mobile station increases. In the future, many networks will assign an identification number to each mobile station. This is the confirmation key or A-key, and the second confirmation number, Shared Secret Data (SSD), is calculated by encryption based on the A-key.</p></background-art><tech><p>It is an object of the present invention to prevent a verification key contained in a mobile radio telephone company from being read by electronic means.</p><p>Another object of the present invention is to provide a mobile radio telephone station in which illegal use is prevented.</p><p>By the following fact, the above object is achieved and the disadvantages of the prior art are alleviated. That is, in the mobile radio telephone office defined in the introduction, when the protection system starts operation of the mobile station, the uncoded form of the confirmation number is encrypted by the traffic and identification encryption means, and only the encrypted form of the confirmation number is stored in the storage means. and an encryption means for decrypting the identification number with the traffic and identification encryption means when the uncoded confirmation number is used in the mobile station.</p><p>As described above, a person with an unjust intention who may read the contents of the EEPROM of the mobile unit protected as described above and separate the confirmation key such as the coded A-key and SSD by decoding the confirmation key It cannot be illegally inserted in uncoded form in In addition, the verification key is used only for encryption and cannot be transmitted over the air, completely preventing access by a third party other than the manufacturer, or operator, or subscriber.</p><p>In addition, encryption and decryption of the verification means by the encryption means already present in the transmission system (mobile station and base station) is easy to operate and can have a protective function with little cost. In some cases, the encryption system CAS is given as a standard to control the ETACS network, and the CAVE system itself is used as an AMPS and CDMA network.</p><p>These and other aspects of the present invention will become apparent from the examples set forth below, which are illustrated by way of example.</p></tech>
<p>The apparatus shown in Fig. 1 is a mobile radio telephone station adapted to connect with an ETACS-type or AMPS-type network. It consists of the components typical for this type of device: antenna 5 , microphone 12 , earphone 10 , keyboard 15 , screen 17 , electronic assembly 20 . This electronic assembly includes a transmitter 40 that accepts wireless traffic using an antenna 5 and converts it into words using an earphone 10 and a microphone 12, including the signal exchange involved by using the keyboard 15. ) and a receiver 42 . This entire electronic assembly is controlled by a control unit 50, which, in a conventional manner, includes at least one microcomputer 51, a flash memory type program memory 52, a random access memory, which are connected to each other in a conventional manner. (53), a programmable ROM 54 of the EEPROM type. In this memory 54, various confirmation numbers can be stored. In this detailed description, in particular, the identification number designated by the A-key, which is a key that enables the mobile station to identify itself as different from other mobile stations, will be described. This key is confidential and should not be known to anyone other than the operator or manufacturer, possibly the subscriber who is the user of the mobile station. For example, as disclosed in U.S. Patent No. 5,392,356, it is appropriate to take measures to preserve the identification number in order to prevent fraudulent activity.</p><p>According to the present invention, in order to preserve the A-key, this A-key number is given in uncoded form at the mobile station if the qualified person, ie preferably the operator, uses the same in the same way as inserted in uncoded form at the base station. is inserted into The program memory 52 contains a program 61 that encrypts at least the A-key and writes the encrypted key to the location A1 of the memory EEPROM 54. The algorithm used for encryption is an algorithm already used for encryption for identification or traffic, and may be a CAVE or CAS algorithm depending on the type of each telephone network. This is because it is given by standards that control the operation of mobile radio networks AMP and ETACS. The CAVE algorithm is EIA/TIA (Electronics Industry Association/Telecommunications Industry Association) Interim Standard IS-54, Appendix A of Revision B, more specifically TR45.0.A, Common Cryptographic Algorithms, Revision B (June 21, 1995) ) is disclosed.</p><p>A-key is encrypted as shown in FIG. 2 . </p><p>The A-key is encrypted via the program 61 by the manufacturer's key Kc through the CAVE algorithm. And the encrypted A-key' is stored in the position A1 of the EEPROM 54 (Fig. 1). Since the manufacturer's key Kc is secret, it is not contained in the EEPROM 54 but is contained in the inviolable program memory 52, and the manufacturer's key Kc is not transmitted over the air.</p><p>When the uncoded A-key is needed to perform a verification procedure in the mobile station, the program memory 52 according to the present invention contains a program 62 for extracting the encrypted A-key' from the EEPROM 54, , as shown in FIG. 3, decrypts the extracted A-key' by the manufacturer's key Kc and the CAVE algorithm, and applies the decrypted A-key to the mobile station for the purpose of identifying it in an inviolable manner. do.</p><p>Note that most of the verification number SSDs are used for verification procedures. As shown in Fig. 4, the SSD itself is obtained by encryption based on A-key and in particular ESN in order to update the SSD through a random number used even during specific encryption.</p><p>The base station (right side of Fig. 4) wirelessly supplies the random number RANDSSD to the mobile station (left side of Fig. 4). For either station, the same encryption operation as follows is performed.</p><p> Encrypt with the CAVE algorithm of the assembly. That is, A-key-RANDSSD, this result becomes the confirmation key SSD.</p><p> It is supplied by radio channel of random number RANDBS from mobile station to base station.</p><p> Encrypt with the CAVE algorithm of the assembly to prove that the two calculated numbers of the two stations are the same. That is, ESN-MIN-SSD-RANDBS, the result is the number AUTHBS.</p><p> Numbers AUTHBS are exchanged and compared between the mobile station and the base station, and their identity also means the identity of the number SSD.</p><p>And the number SSD thus obtained is encrypted by the program 62 (FIG. 1) and stored in the location A2 of the memory 54.</p><p>Preferably, the program 61 of the program memory 52 encrypts all data it should contain so that it is supplied to the memory EEPROM 54 . In contrast, a program 62 is provided to decrypt each of these data prior to supply to the mobile station on demand.</p><p>In addition, the manufacturer may periodically change the manufacturer's secret key Kc to enable data to be encrypted at the mobile station and the base station.</p>
<p>The present invention prevents the verification key contained in the mobile radiotelephone office from being read by electronic means. It will also provide a mobile wireless telephone company that is protected from illegal use.</p>
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2022103354A1 | Cited by | United States of America | Search report |
| US12120225B2 | Cited by | United States of America | Search report |
| US5392356A | Cites | United States of America | Search report |
| US5467398A | Cites | United States of America | Search report |
| US5799084A | Cites | United States of America | Search report |
| KR970019180A | Cites | Republic of Korea | Search report |
| KR970032221A | Cites | Republic of Korea | Search report |
4 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 9700153 | France | – | |
| 9700153 | France | A |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| EP0853438A1 | European Patent Office (EPO) | A1 | |
| JPH10210535A | Japan | A | |
| KR19980070367AThis record | Republic of Korea | A | |
| US6108424A | United States of America | A |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-3-3-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Decision to refuse applicationE601 | E601 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 1998-070367
- Application
- 162
Titles4
- Korean
- 확인 번호 보호 시스템을 구비한 이동 무선 전화국 및 확인 번호 보호 방법
- English
- Mobile radio telephone company equipped with verification number protection system and method for protection of identification number
- Unlabeled
- 확인 번호 보호 시스템을 구비한 이동 무선 전화국 및 확인 번호 보호 방법
- Unlabeled
- Mobile radio telephone company equipped with verification number protection system and method for protection of identification number
Classification
- CPC, 5
- H04W12/04
- H04W88/02
- H04W12/069
- H04L9/0861
- H04W12/06
- IPC, 3
- H04L9 32
- H04W12 04
- H04W88 02