WO0122685A1

Method and arrangement for communications security

Abstract

In a method for establishing a secure communication in a packet based network comprising an access network (13) having access points (10) for two or more mobile terminals (11) belonging to the access network, a first access point is contacted by one mobile terminal in the intention of initiating a session from the mobile terminal. A secret key is generated using a function f stored in the access points acting on the information from the mobile terminal at the first access point by a converter known by two or more access points. The secret key is sent from the first access point to the mobile terminal using encryption, which is decrypted at the mobile terminal. The secret key is then used as a shared security key in communication between the mobile terminal and any access point knowing the converter.

WO0122685A1, drawing sheet 1
Sheet 1 of 3

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 12 independent, 8 dependent

  1. 1
    CLAIMS 1. A method in a communication network (14) for establishing a secure communication between an access point (10) and an entity (11) , the communication network being a packed based network comprising an access network (13) having access points for at least two entities belonging to the access network, the method characterized by the steps of :a) contacting a first access point by an entity in the access network in the intention of initiating a session from the entity in the communication network, b) generating a secret key from the information obtained from the entity at the first access point by a converter known by two or more access points of the network, c) sending the secret key from the first access point to the entity using encryption, d) decrypting the secret key at the entity, and e) using the secret key as a shared security key in communication between the mobile terminal and any access point of the network knowing the converter.
  2. 6
    A method according to any of claims 1 - 5, characterized in that the generation of the key in step b) is carried out by means of a function f .
  3. 7
    A method according to any of claims 1 - 5, characterized in that the generation of the key in step b) is carried out by means of a secret number shared by the access points which use it as a parameter for a pre-defined, well-known function generating the secret key.
  4. 10
    A method according to any of claims 1 - 9, characterized in that after having received the identification information of the entity, the access point takes contact with a server (12) having information on the entities belonging to the access network to download a public cryptographic key of the entity, which is used in the encryption of point c) .
  5. 11
    A method according to any of claims 1 - 9, characterized in that after having received the identification information of the entity, the access point takes contact with a server having or being allowed to get information about the entities belonging to the access network to download a private cryptographic key of the entity, which is used in the encryption of point c) .
  6. 12
    A method according to any of claims 1 - 11, characterized in that the encryption is performed by the access point.
  7. 13
    A method according to any of claims 10 or 11, characterized in that the encryption is performed by the server.
  8. 14
    A method according to any of claims 1 - 13 , characterized in that the decryption of step d) is carried out using a private encryption key of the entity.
  9. 15
    A method according to any of claims 1 - 14, characterized in that in step e) the generated secret key is used by the entity for authentication, data integrity, non-repudiation and/or encryption of its packets.
  10. 17
    A method according to any of claims 1 - 16, characterized in that the generated secret key is used by the access points to send protected messages to the mobile terminal .
  11. 18
    A method according to any of claims 1 - 17, characterized in that the access network is a wireless access network and the entities are mobile terminals.
  12. 19
    A packet based network, comprising an access network (13) having access points (10) for at least two entities (11) belonging to the access network, allowing a secure communication between the access points of the access network and an entity, characterized by a function f stored in the access points for generating a secret key from identification information of the entities in the access network.