Method for the encryption of data transfer
Abstract
The object of the invention is a method for the encryption of information transferred between data transfer devices (MS, SGSN) in a data communication system wherein one or more data frames are created from one or more data packets formed from the information by the application. The data frames comprise at least a header field and a data field. In the method, at least some part of the data packets is ciphered by using a ciphering key (Kc). To the data frames, synchronization data (COUNT) is attached, the value of which is changed at least at the transmission of each data frame.

Term
Term ended
Expired 6 June 2017, 9.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
19 claims: 7 independent, 12 dependent
- 1CONCLUSIES CONCLUSIONS 1. Method of encrypting information 1. Werkwijze voor het versleutelen van informatie 5 to be transferred between data transfer devices (MS, SGSN) in a data transfer system, in which one or more data frames are streamed from one or more data packets generated by the application from the information, and these data frames 5 die moet worden overgedragen tussen gegevensoverdrachtsinrichtingen (MS, SGSN) in een gegevensoverdrachtssysteem, waarin één of meer gegevensrasters worden gevromd uit één of meer gegevenspakketten die door de toepassing uit de informatie worden gevormd, en deze gegevensrasters 10 at least one precursor field and a data field, characterized in that at least part of the data frames, in particular the data fields of the data frames, are encrypted using an encryption key (Kc); 10 tenminste een voorloperveld en een gegevensveld omvatten, met het kenmerk, dat tenminste één deel van de gegevensrasters, in het bijzonder de gegevensvelden van de gegevensrasters worden versleuteld door gebruikmaking van een versleutelingssleutel (Kc); 15 - that synchronization data (COUNT) is added to the data frames, the synchronization data comprising a sequence number of each of the data frames:15 - dat synchronisatiegegevens (COUNT) worden toegevoegd aan de gegevensrasters, waarbij de synchronisatie gegevens een volgordenummer omvatten van elk van de gegevensrasters: - dat een afzonderlijke versleutelingssleutel (Kc) - that a separate encryption key (Kc) 20 is assigned to each connection;and 20 is toegekent aan elke verbinding;en - de gegevens worden toegevoegd aan het gegevensraster, dat aangeeft of het betreffende gegevensraster al of niet versleuteld is. - the data is added to the data grid, which indicates whether or not the data grid in question is encrypted.
- 8A method according to any one of claims 1-7, characterized in that the data transfer connection is a data transfer connection of a packet switching system, such as a GPRS system. 8. Werkwijze volgens een van de conclusies 1-7, met het kenmerk, dat de gegevensoverdrachtsverbinding een gegevensoverdrachtsverbinding van een pakketschakelsysteem, zoals een GPRS-systeem, is.
- 14Method according to one of the preceding claims, characterized in that at least part of the 14. Werkwijze volgens een van de voorafgaande conclusies, met het kenmerk, dat tenminste een deel van de 35 data frames of the adaptive layer are encrypted, in which case data on the encryption of each data frame is preferably transferred in the data frame precursor field. 35 gegevensrasters van de adapterende laag versleuteld zijn, in welk geval gegevens omtrent het versleutelen van elk gegevensraster bij voorkeur wordt overgedragen in het voorloperveld van het gegevensraster.
- 15Data communication system, comprising means for encrypting information transferred between data transfer devices (MS, SGSN), means for forming one or more data packets with the information, means for forming one or more data frames from each data packet at a corresponding data transfer level ( SMDC, LCC), which data grids comprise at least a precursor field and a data field, characterized, that the means of encrypting information include at least:15. Gegevenscommunicatiesysteem, omvattende middelen voor het versleutelen van informatie welke wordt overgedragen tussen gegevensoverdrachtsinrichtingen (MS, SGSN), middelen voor het vormen van één of meer gegevenspakketten met de informatie, middelen voor het vormen van één of meer gegevensrastèrs uit elk gegevenspakket in een desbetreffend gegevensoverdrachtsniveau (SMDC, LCC), welke gegevensrasters tenminste een voorloperveld en een gegevensveld omvatten, met het kenmerk, dat de middelen voor het versleutelen van informatie tenminste omvatten: - means for encrypting at least one part of the data frames, in particular the data fields of the data frames, by a separate encryption key (Kc) assigned to each connection;- middelen voor het versleutelen van tenminste één deel van de gegevensrasters, in het bijzonder de gegevensvelden van de gegevensrasters door een afzonderlijke versleutelingssleutel (Kc) welke toegekent is aan elke verbinding;- means for attaching synchronization data (COUNT) to the data frames, the synchronization data comprising a sequence number of each of the data frames;- middelen voor het hechten van synchronisatiegegevens (COUNT) aan de gegevensrasters, waarbij de synchronisatiegegevens een volgordenummer omvatten van elk van de gegevensrasters;- means for changing the value of the synchronization data (COUNT) upon transmission of each data frame;- middelen voor het veranderen van de waarde van de synchronisatiegegevens (COUNT) bij de overdracht van elk gegevensraster;- means for adding the data to the data frame indicating whether the data frame concerned is encrypted or not;and - middelen voor het toevoegen van de gegevens aan het gegevensraster dat aangeeft of het betreffende gegevensraster al of niet versleuteld is;en - means for interpreting synchronization data in the data frames. - middelen voor het interpreteren van synchronisatiegegevens in de gegevensrasters.
- 17Data communication system according to claim 17. Gegevenscommunicatiesysteem volgens conclusie 15, characterized in that the data transfer means comprise at least one base station (BTS). 15, met het kenmerk, dat de gegevensoverdrachtsmiddelen ten minste één basisstation (BTS) omvatten.
- 18Data communication system according to claim 18. Gegevenscommunicatiesysteem volgens conclusie 16, characterized in that the mobile station (MS) is a mobile station of a GSM system. 16, met het kenmerk, dat het mobiele station (MS) een mobiel station van een GSM-systeem is.
- 19Data communication system according to claim 19. Gegevenscommunicatiesysteem volgens conclusie 16, characterized in that the base station (BTS) is a base station of a GSM system. 16, met het kenmerk, dat het basisstation (BTS) een basisstation van een GSM-systeem is. ω ο ω ο ω ω 100625 100625
Independent claims7
120 paragraphs in 7 sections, as filed
<img file="NL1006252C2_D0001.tif" />
Industrial Property Office The Netherlands © 1006252 © C OCTROOI<sup>20</sup> © Patent application: 1006252 © Filed: 06.06.1997 (51) Int.CI.<sup>7</sup>
H04L9 / 18, H04L29 / 06, H04L12 / 56, H04L12 / 66, H04Q7 / 20
<td>© Priority:</td><td>© Patent holder (s):</td>
<td>06.06.1996 Fl 962352</td><td>Nokia Mobile Phones Ltd. in Espoo, Finland (Fl).</td>
<td>© Registered:</td><td rowspan="2">© Inventor (s): Arto Karppanen in Helsinki (Fl)</td>
<td>10.12.1997 IE 1998/02</td>
<td>© Date:</td><td>Hannu Kari in Veikkola (Fl)</td>
<td> 16.01.2002</td><td>Jari Hamalainen in Tampere (Fl) Jari Juopperi in Helsinki (Fl)</td>
<td>© Published:</td><td rowspan="2">© Authorized representative: Ir. P. Eveieens Maarse et al. 2502 EN Den Hedge.</td>
<td>01.03.2002 IE 2002/03</td>
© Method of encrypting data transfer.
The object of the invention is to provide a method of encrypting information transferred between data transfer devices (MS, SGSN) in a data transfer system, in which one or more data frames are formed from one or more data packets used by the application from the information are being formed. The data grids include at least a precursor field and a data field. In the method, at least part of the data packets are encrypted using an encryption key (Kc). Synchronization data (COUNT) is attached to the data frames, the value of which is changed at least when each data frame is transmitted.
NL C 1006252
The content of this patent differs from the original filed description with claim (s) and possible drawing (s). The documents originally submitted can be viewed at the Industrial Property Office.
METHOD FOR ENCRYPTING DATA TRANSFER
The present invention relates to a method of encrypting information transferred between data communication devices in a data communication system, wherein one or more data frames are formed from one or more data packets formed by the information by an application, and this data frame include at least one precursor field and a data field. The invention furthermore relates to a data communication system comprising the means for encrypting the information transferred between data transfer devices, the means for forming one or more data packets from the information and the means for forming data frames from the data packets.
Data transfer between separate data transfer devices may be performed such that the data transfer devices between which data is to be transferred at that time are connected for the time necessary for the data transfer. In such a case, the connection is maintained until the user stops data transfer. In such cases, most of the connection time is spent entering commands provided by the user, and only a small part of this time is used for actual data transfer. This limits, for example, the maximum number of users accessing simultaneously. Another possibility is to use a so-called packet-switched data transfer. In this case, the data is transferred between the data transfer devices in a packet mode, in which case the time between the packets is freely available and can be used by other data transfer devices. In this case, the number of simultaneously accessing users can be increased, particularly with wireless data transmission networks, such as cellular networks, since in this case the mobile stations located in the same cell area can use the same transmission channel. One such cellular system is the GSM system (Group
Special Mobile) for which a data transfer service with a packet mode GPRS (General Packet Radio Service) has been developed. Figure 1 shows a block diagram of the main blocks in the operation of the GPRS system. A packet switching control circuit SGSN (Serving GPRS
Support Node) controls the operation of the packet switching service on the cellular network side. The packet switching control circuit SGSN controls logging in and out of the mobile station MS, updating the location of the mobile station MS and routing the data packets to their correct destinations. The mobile station MS is connected to the subsystem of the base station BSS via a radio insertion circuit Urn (Figure 1). The base station subsystem is connected to the packet switching control circuit SGSN through the BSS-SGSN insertion circuit Gb. In the subsystem of the base station BSS, the base station BTS and the base station control circuit BSC are connected to each other by a BTS-BSC insertion circuit Abis. The location of the packet switching control circuit SGSN in the network of the mobile station may vary, for example, due to which technical implementation is used. Although in Figure 1 the packet switching control circuit SGSN is marked outside the base station BSS subsystem, the packet switching control circuit may
SGSN, for example, may be placed as part of the base station BTS connected to the base station subsystem BSS or as part of the base station control circuit BSC.
10062S2
The GPRS system is described, for example, in draft proposals GSM 01.60, GSM 02.60, GSM 03.60 and GSM 04.60 that are dated prior to the filing date (priority date) of the present invention.
The operation of both the mobile station MS and the packet switching control circuit SGSN can be divided into several layers, each of which performs a different function, as shown in Figure 2. The
International Standardization Organization, ISO has formulated an OSI (Open Systems Interconnection) model for grouping data transfer into different functional layers. This model involves seven layers that are not necessarily all present in all communication systems.
Transferable information such as control signaling and user-transferred data between a mobile station MS and a packet switching control circuit SGSN is preferably exchanged in a data frame mode. The data grid of each layer is made up of a precursor field and a data field.
Figure 2 also shows the structure of the data grids used in the GPRS system in different layers.
The information contained in the data field can be, for example, data entered by the user of the mobile station or signaling data. The data field may contain confidential information that must be secured as reliably as possible before it is transferred to the radio path. In such a case, the encryption must be performed such that a separate encryption key is used in all concurrent connections between the packet switching control circuit SGSN and the associated mobile stations MS. Conversely, it is not preferable to hide the address data from the address grid by the same encryption key used in encrypting the data field, since 1006252 sees mobile stations MS use a common radio path, that is, the information in many different connections within the same channel, for example at different time intervals. In this case, each mobile station must receive all messages transmitted in the respective channel and at least decrypt the address data to identify which mobile station the message is intended for. Nor does the packet switching control circuit SGSN know which encryption key to use.
In the future, the operational functions of the layers of the GPRS system will be presented.
The bottom layer is a MAC (Media Access 15 Control) layer that controls the use of the radio path in the communication between the mobile station MS and the base station subsystem BSS, such as assigning channels for broadcasting and receiving packets .
Data transfer between the base station subsystem and the bottom level packet control circuit SGSN is performed at the L2 layer (link layer) using the link layer protocol, such as the LAPD protocol according to standard Q.921, a raster relay protocol or its equivalent . The L2 layer can also contain quality or route data according to GPRS specifications. The layer L2 has the properties of the physical layer and the connection layer of the OSI model. For example, the physical transmission line between the base station subsystem BSS and the packet control circuit SGSN depends on where the packet controller SGSN is located in the system.
Above the MAC layer is an RLC layer (Radio
Link Control) and its function is to divide the data frames formed by the LLC layer into fixed size packets to be broadcast over the radio track and their broadcast and retransmission when necessary. The length of the packets in the GPRS system corresponds to the length of a GSM time slot (about 0.577 ms).
The LLC (Logical Length Control) layer provides a reliable transmission connection between the mobile station MS and the packet control circuit SGSN. For example, the LLC layer adds error correction data to the broadcast message, thereby attempting to correct the incorrectly received messages and retransmit the message if necessary.
The SNDC (Sub-Network Dependent Convergence) layer includes functions such as protocol conversions of broadcast information, compression, segmentation and segmentation of messages from the top layer. Encryption and decryption are also performed at the SNDC layer. The structure of the SNDC layer is also shown in Figure 2. The SNDC grid includes an SNDC precursor field (SNDC precursor) and an SNDC data field (SNDC data). The SNDC predecessor field is formed by protocol data (Network Layer Service access point
Identity, NLSI) and by SNDC control data, such as compression, segmentation and encryption provisions. The SNDC layer functions as a protocol adapter between protocols used at the top level and the protocol of the LLC layer (link layer). The broadcast information preferably comes as data packets to the SNDC layer from any application, such as messages according to the GPRS system or packets of the Internet protocol (IP). For example, the application may be a mobile station data application, a fax application, a computer program that has a data transfer connection to a mobile station, and so on.
The MAC layer, the RLC layer, the LLC layer and the L2 layer have properties described at layer 2 in the OSI model. However, the above layers and the layers described in the OSI model are not necessarily coherent.
The SNDC grid is transferred to the LLC layer when an LLC precursor field is added to the grid. The LLC precursor field is formed by a Temporary Logical Link Identity (TLLI) and an LLC5 controller. The packet control circuit GPRS determines a TLL identity for each data transfer connection between a mobile station MS and a packet control circuit GPRS. This data is used in data transfer to determine which data transfer connection each message belongs to. At the same time, the same TLL identity can only be used in one data transfer connection. After termination of the connection, the TLL identity applied in the connection can be assigned to a new connection to be subsequently formed. The LLC control section defines the frame number and command type (information, confirmation, retransmission requests, etc.) to ensure error-free data transfer.
Encryption at the GSM system is performed at the physical layer as an encryption that occurs bit by bit, that is, the bit stream transmitted to the radio track is formed by adding to the broadcast data encryption bits generated using the algorithm A5 known per se, the use of an encryption key Kc. The algorithm A5 encrypts transmitted data and signaling information at the physical layer at the channels assigned to data transmission (Traffic Channel, TCH or Dedicated Control
Channel, DCCH).
The synchronization of the broadcast messages is ensured such that the algorithm 5 is driven by means of special synchronization data (COUNT). The synchronization data COUNT is formed based on the TDMA grating number. Then, the content of each 114-bit block formed by algorithm A5 depends only on the number of the frame and the encryption key Kc.
f006252
The setting of the encryption key Kc is most preferably performed at the stage on which the communication traffic of the respective channel is not yet encrypted, and the mobile station network to be used has identified the mobile station MS. Identification in the GSM system uses an International Mobile Subscriber Identity, IMSI that identifies the mobile station and is stored in the mobile station or where a Temporary
Mobile Subscriber Identity, TMSI is used which is formed based on the subscriber's identity. A subscriber identification key Ki is also stored in a mobile station. The subscriber identification key Ki is also known to the mobile station network15.
To ensure that the encryption key Kc is known only to the mobile station MS and the mobile station network, the transfer of the encryption key from the BSS subsystem from the base station to the mobile station is indirect. Then, a Random Access Number, RAND is generated in the base station subsystem BSS which is broadcast to the mobile station MS. The encryption key Kc is generated from the random access number RAND and from the subscriber identification key Ki using algorithm A8, as shown in Figure 3. The calculation and storage of the encryption key Kc are performed in both the mobile station MS and the mobile station network.
The data transfer between the mobile station MS and the base station subsystem BSS is not encrypted at the start of the connection. The transition to the encrypted state preferably takes place such that the BSS subsystem from the base station to the mobile station transmits a certain command (unencrypted) which in this context is referred to as a start key. After the mobile station MS has received the command start key, this starts with the encryption of the broadcast messages and the decryption of the received messages. Accordingly, the base station subsystem BSS starts encrypting the messages sent to the mobile station after the base station subsystem has received the encrypted message sent by the mobile station and decrypted the encryption correctly. .
For example, with the encryption described above, the synchronization was based on the number of TDMA grids of the physical layer. It is not possible to use it in all applications, especially when information associated with different connections is broadcast on the same channel, such as in packet-controlled data transfer method.
European patent application EP-0 689 316 describes a method of encryption of data transmission, in which, for example, encryption data comprising an encryption key are attached to the transmitted data frames.
U.S. Patent No. 5,319,712 describes a method and equipment for encrypting data transfer such that a sequence number is assigned to the data layer of the link layer and the data frame is encrypted. A drawback of these prior art encryption methods is, for example, that without the decryption, the receiver does not know to whom the received data frame is intended, in which case the redundant reception of data frames and the decryption thereof worsens the effectiveness of the system.
US-A-5 455 863 discloses a method for encrypting information to be transferred between data transfer devices (MS, SGSN) in a data transfer system, in which one or more data frames are extracted from one or more data packets that the application uses from the information is generated, and these data grids comprise at least a precursor field and a data field,
The object of the present invention is to provide a method and an apparatus for encrypting the data transfer in a data transfer system, wherein the transferred data is in a data frame mode and which data transfer system is divided into functional layers, in which case the data frame structure is different can be in the different layers.
The method according to the present invention is characterized in that at least part of the data frames, in particular the data fields of the data frames, are encrypted using an encryption key (Kc);
- that synchronization data (COUNT) is added to the data frames, the synchronization data comprising a sequence number of each of the data frames:
- that a separate encryption key (Kc) is assigned to each connection; and
- the data is added to the data grid, which indicates whether or not the data grid in question is encrypted.
The invention provides important advantages over the prior art encryption methods.
In the method of the invention, the precursor field of the data layer of the physical layer can be broadcast in an unencrypted mode or currently known methods of encryption can be used. Both methods according to a preferred embodiment of the invention, the encryption key is changed for each transmission layer of the physical layer, in which case decryption without knowledge of the encryption key is virtually impossible. Moreover, by using the method according to the invention it is possible to use partial encryption, in which case only a part of the transmitted data frames is encrypted. In this way, for example, advertisements can be delivered unencrypted, and other information can only be decrypted by those who have the right to receive and decrypt encrypted data frames.
Next, the present invention will be described in more detail with reference to the accompanying drawing, in which:
Figure 1 shows the logical structure of the GPRS system as a block diagram, Figure 2 shows the layer structure of the GPRS system 15, as well as the data grid structure of the layers, Figure 3 shows a definition of the prior art encryption key in mobile stations and mobile station network as a block diagram, Figure 4a shows an encryption according to a preferred embodiment of the present invention, Figure 4b shows an encryption according to another preferred embodiment of the present invention, Figures 5a-5d show the data grid structure of a connection layer according to an embodiment, Figure 6a shows the data grid structure of the adaptive layer according to an embodiment with a Point-to-Point connection, and Figure 6b shows the data grid structure of the adaptive layer according to an embodiment with multipoint connections.
In the following, the invention has been visualized by means of a packet switching service GPRS implemented in the GSM system, but the invention is not limited to only this system.
The invention has attempted to achieve an implementation that uses as much of the existing encryption technique as possible, such as the encryption of the GSM system which has been adapted in such a way that it can be used in the transmission of data frames in, for example, the GPRS -system. An advantage of the invention is that it can be used in many modes, such as a Point-to-Pont (PTP) connection, a multi-point connection (Pointto-Multipoint-Multicast, PTM-M; Point-to-MultipointGroup , PTM-G) and so on. The encryption methods are mainly classified based on the TLLI identity. A separate TLLI identity has been assigned for each connection type between the mobile station MS and the packet switching control circuit SGSN. The following different types are available for use with the GPRS system according to these standards:
Point-to-Point (PTP) uses a single TLL identity in the communication between the mobile station MS and the packet switching control circuit SGSN.
- Point-to-Multipoint-Multicast (PTM-M) uses TLLI, assigned to the communication between the mobile station MS and the service provider broadcasting to different stations.
Point-to-Multipoint Group (PTM-G) uses TLLI assigned to two-way communication between a multi-station broadcasting station of mobile stations MS within the group of mobile stations.
Point-to-Point connections usually use the acknowledgment position at the link layer level, that is, the broadcast receiver transmits the data as an acknowledgment of correct reception. In Point-to-Multipoint connections, data grids are usually broadcast using the mode in which acknowledgments are not broadcast.
As mentioned earlier in this description, in systems where data from different connections are transferred in the same channel, it is not preferable to use the precursor field of data frames
06252 encrypt through a unique encryption key for each connection. In this case, the data grids are at least partially encrypted at a layer other than the physical layer. In the GPRS system, encryption is performed at the LLC layer. The transmitted data is encrypted such that a corresponding bit of the data bit sequence is added to each bit of the data frame. The data bit string is preferably formed by an encryption algorithm using a separate and unique encryption key Kc. The encryption algorithm is preferably the A5 algorithm known from the GSM system.
In addition to the fact that the data must be sent to the correct address, it must be ensured that the data grids can be placed in the correct sequence at the receiver. This can be done in a manner known per se, so that synchronization data COUNT is entered into the encryption algorithm, in which case the receiver can determine the order of the data frames after decryption. For example, in Time Division Multiple Access (TDMA) systems, such as GSM, the TDMA frame number can be used to number the physical layer data frames. However, the packet switching control circuit SGSN of the GPRS25 system does not know the TDMA frame number, so that in this invention a method for synchronizing data frames has been developed and according to this method, the sequence number of data frames (the data frame number) is used as the synchronizing data. Thus, the content of each broadcast block is determined, for example, by the frame number and the encryption key Kc.
The amount of data to be encrypted varies in different connections, but this is not important in the practice of the invention, since the encryption can be performed by preferably dividing the transmitted data into subblocks of a standard length. Then, the first bit of each subblock is encrypted by the first bit of the encryption algorithm, the second bit of the subblock by the second bit of the encryption algorithm, and so on. In the GPRS system, the length of a subblock can be, for example, 114 bits, as in the current GSM system. The length of the subblock may preferably be divisible by the length of a byte. In many applications, the length of a byte is 8, in which case a suitable length for a subblock could be 64 bits.
In the GSM system, a mobile station MS can only use one encryption key Kc at a time. In the GPRS system, one encryption key per mobile station MS is not necessarily sufficient in every situation, since the mobile station can simultaneously participate in many different types of active connections (PTP, PTM), each connection preferably having a separate encryption key Kc which is preferably formed by various means. The encrypted data frame thus includes the encryption key Kc used, the synchronization data COUNT, and possibly also the COUNTb values of a block counter BLCNT assigned to the TLLI. Figure 4 shows a preferred encryption method according to the invention as in a block diagram in a situation where an unencrypted subblock (plain text) is encrypted (encrypted text) transferred from the network to the mobile station. In this embodiment, the COUNTb value of the block counter is also used in determining the encryption block BLOCK 1. The block counter can be set to its initial value by a setting line free, preferably at the start of the data grid of each adaptive layer . On both the network side and at the mobile station MS, the value of the synchronization data COUNT is calculated for each broadcast block, the value of the synchronization data COUNT and the encryption key
Kc are entered in the encryption algorithm A5.
At the transmit side, the output bit sequence (BLOCK 1) becomes at the subblock (plain text in). The coded subblock is transferred to the mobile station MS in the channel. The mobile station MS encrypts this in accordance with adding the output bit sequence (BLOCK 1) of the encryption algorithm A5 to the received encrypted subblock, and as a result of the addition, an unencrypted subblock (outgoing plain text) in accordance with the transmitted subblock obtained. Figure 4b shows another preferred encryption method according to the invention as a block diagram. This embodiment differs from the embodiment of Figure 4a mainly in that the block counter BLCNT is not used.
A typical raster sequence number length is between 6 and 8 bits. From the point of view of encryption security, this value as a COUNT variable is not sufficient in itself, so that other variables can also be used in determining the COUNT value of the synchronization data outside, for example, the grid sequence number and the identification of the base station. The base station identification is known to both the network and the mobile station, since the mobile station being used informs the packet switching control circuit SGSN of the change of the base station. Thus, the change of the base station changes the COUNT value of the synchronization data in this embodiment.
In Point-to-Point connection mode, the following variables are available when determining the COUNT value of the synchronization data:
a) The raster number of the Logical Link Control35 layer (LLC raster number, LLC #) applied to the adaptive layer (SNDC).
b) The data frame number of the adaptive layer (SNDC data block number, SDU #) that can be assigned to the broadcast data frame or that can be initialized at the start of the connection, if it is maintained at both ends of the connection.
c) The identity of a routing area (routing area #) known at both ends of the connection, so that the identity need not be attached to the broadcast data frame.
d) Identity of the area of a packet control circuit (SGSN #) known at both ends of the connection, so that the identity need not be attached to the broadcast data frame.
e) Identity of a base station (cell #) known at both ends of the link, so that the identity need not be attached to the broadcast data frame.
With the Point-to-Multipoint data mode, the following variables are available when determining the COUNT value of the synchronization data:
a) The data frame number of the adaptive layer 20 (SNDC data block number, SDU #) transmitted within the SNDC data frame.
b) Identity of a routing area (routing area #) known at both ends of the connection, so that the identity need not be attached to the broadcast data frame.
c) Identity of the area of a packet switching control circuit (SGSN #) known at both ends of the connection, so that the identity need not be attached to the broadcast data frame.
d) Identity of a base station (cell #) known at both ends of the link, so that the identity need not be attached to the broadcast data frame.
In addition, the value of the block counter BLCNT can be used in both connection modes, which will make cracking an encrypted data field even more difficult for an intruder, since not the same encryption bit sequence is used in the encryption of
The variables that define COUNT synchronization data proposed above can be used alone or in combination. Some of these variables thus have to be supplied to the receiver within data frames and some of them can be controlled locally. The use of locally controlled variables increases the level of security and to some extent reduces the amount of data transferred. The following tables give an example of the contents of the synchronization data COUNT. Table 11 shows some synchronization data according to the most preferred embodiment of the invention, and uses a block counter DLCNT, and Table 1.2 shows another preferred embodiment of the invention, in which the identity of the base station is used instead of the value of the block counter COUNTb.
<td>Bit/ stand,</td><td> 22</td><td> 21 20</td><td> 19</td><td> 18</td><td> 17</td><td> 16</td><td> 15</td><td> 14</td><td> 13</td><td> 12</td><td> 11</td><td> 10</td><td> 9</td><td> 8</td><td> 7</td><td> 6</td><td> 5</td><td> 4</td><td> 3</td><td> 2</td><td> 1</td>
<td>FIT</td><td colspan="2">SDU #; (locally or</td><td>Fg</td><td colspan="3">supplied)</td><td></td><td colspan="3">LLC # (delivered</td><td><Q</td><td></td><td></td><td colspan="3">COUNTb</td><td></td><td></td><td></td><td></td><td></td>
<td>PTM</td><td colspan="3">SDU #. (Delivered)</td><td></td><td></td><td></td><td></td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td colspan="3">COUNTb</td><td></td><td></td><td></td><td></td><td></td>
Table 1.1
<td>Bit/ stand</td><td> 22</td><td> 21</td><td> 20</td><td> 19</td><td> 18</td><td> 17</td><td> 16</td><td> 15</td><td> 14</td><td> 13</td><td> 12</td><td> 11</td><td> 10</td><td> 9</td><td> 8</td><td> 7</td><td> 6</td><td> 5</td><td> 4</td><td> 3</td><td> 2</td><td> 1</td>
<td>PTP</td><td colspan="8">SDU # (locally or delivered)</td><td colspan="6">LLC # (Delivered)</td><td>Cell bf</td><td colspan="7">. #, routing area H SGSM (local)</td>
<td>PTM</td><td colspan="8">SDU # (Delivered)</td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td> 1</td><td colspan="8">Cell #, router lttgo area # or SGSM (local)</td>
Table 1.2
The following describes how to set the encryption key Kc. The setting of the encryption key Kc is initiated by the network as many times as the user of the network deems necessary. In addition, a unique encryption key must be generated for each TLLI connection. A table of the encryption key Kc-TLLI identity pairs. most preferably maintained in both the package 1006252
The following describes how to set the encryption key Kc. The setting of the encryption key Kc is initiated by the network as many times as the user of the network deems necessary. In addition, a unique encryption key must be generated for each TLLI connection. A table of the encryption key Kc-TLLI identity pairs is most preferably maintained in both the packet switching control circuit GPRS and in the mobile station on MS. Setting the encryption key is different for different connection types.
In a Point-to-Point connection, the encryption key Kc is sent out indirectly using any access number RAND. In the GPRS system, the encryption key Kc is preferably formed from the freely accessible access number RAND and from the subscriber identification key Ki of the mobile station using the algorithm A8, as well as in the GSM system. The identification key of a mobile station is stored on the SIM card (Subscriber Identity Module) of the mobile station, and in the Authentication Center AuC of the network.
In a multipoint connection, all mobile stations connected to the same service use the same encryption key Kc. The encryption key Kc is activated when the connection to the service is established. The encryption key Kc can be supplied to the mobile station MS using various methods. A multi-point service delivery setting may preferably enter the encryption key in an encrypted position, in which case the mobile station MS must be connected to the packet switching control circuit GPRS via a Point-to-Point connection, prior to accessing the multi-point connection . During the establishment of the Point-to-Point connection, an encryption key Kc is defined for the connection and is used in encrypting the encryption key of the multi-point connection when it is broadcast to the mobile station MS.
The encryption key of the multi-point connection can also be supplied, for example, by using the keyboard of the mobile station MS, such as in PIN code or some kind of SIM card that can be used, in which, among other things, the encryption key Kc is stored.
The encryption key Kc need not be regenerated when the mobile station MS changes its location to the area of another packet switching control circuit GPRS, because the encryption key can be distributed from the previous packet switching controller to the new one.
The transition from the pure text mode to the encrypted mode preferably takes place such that the packet switching control circuit GPRS sends a special start cipher command in unencrypted text. In the mobile station MS, encryption of the transmission and decryption of reception begins after the start cipher command has been properly received by the mobile station. On the side of the packet switching control circuit GPRS, encryption starts accordingly, after the packet switching control circuit has received and decrypted the message broadcast by the mobile station MS. The operation described above corresponds, with regard to its main parts, to the start of encryption of the GSM system.
In some packet switching applications, encryption can also be applied such that only one-way messages are encrypted, i.e. the messages from the mobile station MS to the packet switching control circuit GPRS or from the packet switching control circuit GPRS to the mobile station MS. Applications such as these include, for example, the delivery of advertisements that are usually broadcast unencrypted.
Moreover, the encryption according to the invention can also be applied in such a way that only part of the transmitted data frames of the adaptive layer SNDC are encrypted. In this case, preferably one encryption bit is added to the data frame of the adaptive layer and this will indicate whether the data frame in question is encrypted or not encrypted.
For example, when the encryption bit has the value zero, the data grid is not encrypted, and when the encryption bit has the value one, the data grid is encrypted. This can be used, for example, in a situation where the access rights to a service require the registration or the like, in which case the registered users can decrypt the encrypted data frames. For other users, the service provider may deliver information related to services and advertisements in non-encrypted data grids.
Figure 5a shows an example of a data layer structure of a link layer according to a preferred embodiment. The data frame (frame precursor) precursor field includes a three byte TLLI identity and a two byte control section (Control). As is known, a byte includes 8 binary information units (bits). The data field information field includes the broadcast information. The length of the information may vary. The data frame also includes a two-byte check field (check string) that includes, for example, error correction information.
Figure 5b shows the structure of the control part of the data frame of Figure 5a, when the data frame is an information delivery and system management35 data frame (information + control), wherein:
C / R indicates whether there is a command or a response (Command / Response),
SI and S2 describe the type of control command,
N (S) indicates the number of the transmission sequence (transmission sequence number),
P / F indicates whether there is a confirmation request message (P) or a confirmation message (F) (Poll / Final), and
N (R) is the number of receive sequences.
Figure 5c shows the structure of the control part of the data frame of Figure 5a, when the data frame is a system control data frame (control). The meaning of the bits has been described above.
Figure 5d shows a structure of the control portion of the data frame of Figure 5a, when the data frame is an unnumbered data frame (numbered 15), wherein:
ML-5 are numbered commands and responses,
G / D indicates whether there is a control or data grid (Control / Data), and the x-bits are not significant.
Figure 6a shows an example of a data grid structure with a Point-to-Point connection of an adaptive layer according to a preferred embodiment. The first byte includes control data, in which:
- M indicates whether there is the last segment 25 of the information generated by the application,
- E indicates whether the encryption is in use,
- Pri indicates the priority rating,
- NLSI is a protocol data that can be, for example,
- TCP / IP,
- CLNP,
- X.25,
- GPRS, and so on.
Figure 6b shows an example of a data race 35 structure with a multipoint connection of an adaptive layer according to a preferred embodiment. The significance of the bits is described above.
Although the invention has been described above in a data transfer system in which a mobile stations MS, subsystems of a base station BSS and packet switching control circuits SGSN of a GPRS5 system are used, the invention can also be applied to other data transfer systems, such as TDMA and CDMA data transfer systems, in preferred in packet switching data transmission systems.
The present invention is not limited to the above described embodiments, but is defined by the scope of the appended claims.
Contents7
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP0689316A2 | Cites | European Patent Office (EPO) | DX | Search report | 1,16 |
| US4866772A | Cites | United States of America | Y | Search report | 4-8,15 |
| US5319712A | Cites | United States of America | DX | Search report | 1,16 |
| US5455863A | Cites | United States of America | XY | Search report | 1,3,9,10,16-20 |
| US5519780A | Cites | United States of America | X | Search report | 1,2,11-14,16 |
| WO9733403A1 | Cites | World Intellectual Property Organization (WIPO) | E | Search report | 1-3,9,10,16-20 |
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 962352 | Finland | A | |
| 962352 | Finland | A | |
| 962352 | – | – | – |
| FI19960002352 | – | – | – |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | |
| Change of ownershipPD | PD | |
| Modifications of names of proprietors of patentsTD | TD | |
| A search report has been drawn upPD2B | PD2B | |
| Patents in respect of which a decision has been taken or a report has been made (novelty report)RD2N | RD2N | |
| A request for search or an international type search has been filedAD1A | AD1A |
Numbers
- Publication, DOCDB
- 1006252
- Publication, EPODOC
- NL1006252C
- Application
- 1006252
- Application, DOCDB
- 1006252
- Application, EPODOC
- NL19971006252
Titles2
- Dutch
- Werkwijze voor het versleutelen van gegevensoverdracht.
- English
- Method of encrypting data transfer.
Classification
- CPC, 7
- H04L9/065
- H04L63/0428
- H04L63/0853
- H04W92/00
- H04L9/12
- H04L2209/80
- H04W12/033
- IPC, 5
- H04L9 18
- H04L29 06
- H04W12 02
- H04W92 00
- H04L9 08