Verifying check-in authentication by using an access authentication token
Abstract
A simple and efficient ability to verify check-in authentication is made possible by the method and device for verifying check-in authentication before the start of the re-registration process on the basis of a check-in request made by a mobile radio terminal (5) to at least one access device (6) for an intra-domain handover in a mobile communications network. The invention is characterized in that an authentication token, which was sent by an access device (4) to a mobile radio terminal (5) and which was stored in at least one confidence table (7) of at least one access device (1, 4, 6), is received by at least one additional access device (6) during a check-in request made by a mobile radio terminal (5) and is compared to authentication tokens, which are stored in at least one confidence table (7), before the start of the check-in in order to verify check-in authentication, and the check-in is initiated only when an authentication exists.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
24 claims: 23 independent, 1 dependent
- 1Claims 1. 1. A method for checking the log-in authorization prior to the start of the re-registration process due to a log-on request of a mobile radio terminal (5) to at least one access device (6) for an intra-domain handover in a mobile communication network, characterized in that et an authorization mark, which has been sent by an access device (4) to a mobile radio terminal (5) and has been stored in at least one trust table (7) by at least one access device (4), at least one further access device (1, 4, 6) is received in a log-on request of a Mobilfunkendgerates (5) and compared with at least one trust table (7) stored authorization marks before the start of the booking for Einbuchungsberechtigungsprüfung and only if there is an authorization the log-on is started.
- 3Third Method according to one of the preceding claims, characterized in that the verification of the entry authorization is made before the beginning of the re-registration processes.
- 44th Method according to one of the preceding claims, characterized in that the connection update process is used for the re-registration process.
- 55th Method according to one of the preceding claims, characterized in that the authentication and authorization process is used for the re-registration process.
- 66th Method according to one of the preceding claims, characterized in that for the re-registration process the authentication and authorization process and the connection update process are used simultaneously.
- 77th Method according to one of the preceding claims, characterized in that an access device (4) is an access router
- 88th. Method according to one of the preceding claims, characterized in that after successful verification of the authorization of the access device (6) the renewal of the connection process is started.
- 99th Method according to one of the preceding claims, characterized in that after successful verification of the authorization of the access device (6) the renewal of the authorization and authentication process is started.
- 1010th Method according to one of the preceding claims, characterized in that the authorization mark is sent with the message for renewing the connection between access device (6) and mobile radio terminal (5),
- 1111th Method according to one of the preceding claims, characterized in that an access device (4) sends the authorization mark received by a mobile radio terminal (5) to a neighboring access device (1, 6). ± 1
- 1212th Method according to one of the preceding claims, characterized in that an access device (4) sends the authorization mark received by a mobile radio terminal (5) to a neighboring access device (1, 6) which is stored in a trusted list.
- 1313th Method according to one of the preceding claims, characterized in that an access device (4) stores authorization marks received from neighboring access devices (1, 6) in at least one trust table (7).
- 1414th Method according to one of the preceding claims, characterized in that used authorization marks are stored in a dedicated trust table.
- 1515th Method according to one of the preceding claims, characterized in that a Mobilfunkendgerat (5) in an intra-domain handover the entitlement mark to another access device (6) sends.
- 1616th Method according to one of the preceding claims, characterized in that a further access device (6) checks the authorization mark after the validity period of the authorization mark.
- 1717th Method according to one of the preceding claims, characterized in that a further access device (6) checks the authorization mark after the creation of the authorization mark.
- 1818th Method according to one of the preceding claims, characterized in that an addition of the authorization mark representing a key is compared with a calculated key of the access device (6).
- 1919th Method according to one of the preceding claims, characterized geke nzeichnet that an authorization mark contains the identity of the Mobilfunkendgerat (5).
- 2020th Method according to one of the preceding claims, characterized in that an authorization mark contains the identity of the creating access device (4).
- 2121st Method according to one of the preceding claims, characterized in that an authorization mark contains the creation time.
- 2222nd Method according to one of the preceding claims, characterized gekennzeic net, that an authorization mark contains a random number.
- 2323rd Method according to one of the preceding claims, characterized in that an authorization mark contains an addition representing a key.
- 2424th Device for checking the access authorization when starting authentication and authorization processes due to a log-on request of a mobile radio terminal (5) to at least one access device (4) for an intra-domain handover in a mobile communication network, a receiving unit (10) for receiving an authorization mark and a request for authorization for access of a mobile radio terminal, with a processing unit (11) for creating authorization marks and checking for received authorization marks, with at least one trust table (7) for storing created and at least one access device (6) received authorization marks and with a transmitting unit (12) for sending created authorization marks to a Mobilfunkendgerat (5) and at least one further access device (6) and for forwarding the access authorization to other network units.
Independent claims23
71 paragraphs, as filed
REVIEWING log-AUTHORIZATION BY ACCESS AUTHORITY BRAND
A method for repelling DoS Assault en on optimized and quality of service aspects of supporting handover procedures using regionally valid cryptographic tokens.
The invention relates to a method and apparatus for checking the log-authorization before the start of authentication and authorization processes due to a registration request from a Mobilfunkendgerates at least one access device for an intra-domain handover in a mobile communication network.
QoS mechanisms (QoS = Quality of Service) have to guarantee the purpose of service characteristics, such as the end-to-end runtime etc. in networks that support the mobile Internet communications. In these networks, there is a threat to these mechanisms by so-called denial-of-service - attacks (Denial of Service (DoS)), which aim to reduce the availability of services for legitimate users. A threat is that QoS Signalisierungsmechänismen be used to enable mobile node requests to a network, which is a resource reservation means. If the network is not efficient can check the "credibility" of QoS requests such. For instance by visits to the origin and the authorization of a request from a mobile node, the performance of the network can be reduced with false QoS requests. A mobile radio terminal leaves z. B. its home network and enters a Network with HMIPvβ connection and an AAA architecture.
It is assumed that between the mobility anchor point (MAP) and each access router<sup>'</sup> (AR), between the local AAA server (AAAL) and each access router (AR) between the MAP and the AAAL and between an access router and the other access routers always a security association (security context = SA) consists. Once a mobile radio terminal has successfully registered, its authentication and authorization information are (AA) in a local AAA server (AAAL) saved and his identity is the MAP and the access router (AR), wherein the mobile radio terminal is first registered has known. Thereafter, the mobile radio terminal can move between the catchment areas of the access router (AR) without an interruption in communication. To optimize the intra-domain handover, the waiting time for registration in the individual access routers must be minimized as far as possible. Generally prevent or block DoS attacks normal use or management of communication facilities (or other services). Denial-of-service - attacks (Denial of Service = DoS) usually have a specific goal. So can effect by means of a high number of sent false messages z. B. DoS attacks the collapse or shutdown of the entire network or the reduction of power by overloading the network. All mobile terminals in an access network can send QoS requests to all nodes along the communication path to reserve resources. So even attacker can send QoS requests in the access network. For this reason, an access device, such as an access router has the "credibility" of a QoS request from a Check mobile radio terminal before it processes the request. If an access device. this makes using the local AAA server before the start of the booking process, there is a significant waiting time for the re-registration process. When a mobile radio terminal of the
The catchment area of an access router in the catchment area of another access router in the access network (intranet
Domain handover) changes, should be no interruptions between mobile radio terminal and access network. While the mobile radio terminal maintains the connection with the first access router, it initiates a new
Registration process with another access router by sending Connection Update message (binding update messages). If not checked beforehand whether the mobile radio terminal is a registered user in
is access network attacker to access network can use it for. example, the computing capacity by inquiries concerning the authentication and authorization to waste or resource reservation requests, etc. wrong, strain.
Object of the present invention is, therefore, optimized by an efficient protection against bogus requests the performance of the communication network to ensure.
The object is achieved in each case by the subject matters of the independent claims relating to the method and apparatus. A core of the invention is that in an intra-domain handover before the start of binding update and re-authentication and re-Autorisationsprozessen (AAA processes) an examination of the log-on credential with a token takes place to prevent DoS attacks , The advantages this method is a low latency in re-
Registration processes and the effective protection against DoS
Attacks. Using this method, the filling can (The DoS
Attack attempts to fill the memory of the attacked system and to achieve so that the system can not accept any legitimate inquiries more.) Of the memory of the access router due to a DoS attack, the
Performance degradation of the signaling capacity
Access network are avoided by false requests and unauthorized documents from resources in the local AAA server by false requests. Advantageous embodiments are specified in the claims referring back to this claim subclaims. Reducing the risks with repeat tokens (= token), such. As a cookie may be due to a very limited scope, by the token is accepted, will be achieved.
The invention is illustrated with reference to an embodiment shown in FIG. It shows
Figure 1 as the first token (= token) to
Mobile radio terminal is sent. Figure 2 shows how the previously generated token without limiting the scope and without indication for the use of another
Access device is sent, Figure 3 shows how the previously generated token is transmitted without a usage indicator in a limited scope,
FIG. 4 how the previously generated token is transmitted with an indicator for use in a limited scope, Figure 5 as a token to a
Mobile radio terminal is sent to an intra-domain handover,
Figure 6 is a diagram of a device for sending and checking tokens.
Figure 1 shows how the mobile radio terminal 5 sends a first registration request to an access router 4 when switched on or when you first sign in the access network. After the local AAA server, the positive
Authentication and authorization information received from Heimat- AAA server, it informs the Mobilitats- anchor point (MAP) 2 on the successful authentication and authorization testing. Thereafter, the mobility anchor point sends (MAP) 2 the session key (session key) that generates the home AAA server and the authentication - was forwarded and authorization information to the access router 4, so that the access router is a Security -Assoziation can set up with the mobile radio terminal. 5 The access router 4 creates a token, encrypts it with the session key and sends it to the mobile radio terminal 5. The mobile radio terminal 5 receives the session key safely with the aid of a long-term security association from homeland AAA server.
Tokens are always created here by an access router. The first token is replaced by the mobile radio terminal 5 from the one access router with which the mobile radio terminal 5 logs or intra- domain handover performs, following the successful registration is encrypted with the session key token between the mobile radio terminal 5 and all access routers of established access network and a<sup>'</sup> Access router 4 to the mobile radio terminal 5 with the binding update
Message received. are each access router 4 has at least one trust list 7. In a trust list 7 (trusted list) displays information about the access routers 1, 6 stored whose tokens will be accepted and in another trust list 7 (trusting list)
Information on the access router saved 1.6, which accept the tokens of the generating access router. 4 In a third trust list 7, the token is already in use are stored. Here are all tokens are stored, which have already been used successfully by a mobile radio terminal. In this way it is achieved that a. Token after a single use
"Devalued" and can not be used repeatedly. The other two trust lists serve the purpose that not every used token in each access router 1, 4, 6 of the entire access network needs to be saved, but only in the access routers 1, 4, 6, lying in the by the two trust lists (trusted list and trusting list) realized scopes. Without the limitation of scope, the process would not scale for large access networks. It accepts only tokens that have been created by the access routers 4 which are in its trust list. in a further trust list 7, the access router are included which accept the tokens created by this access router 4. in order to increase security of an access router 4, the token of his
Neighboring access router stored in a trust list. For a limited scope for the acceptance of a token is generated as an access Router 4 only its self-generated tokens and those that were created by a neighbor access router 6, accepted.
When a mobile radio terminal 5 wants to perform an intra-domain handover, it adds (5) the token of
Re-registration request and sends it (5) as a text to the new access router 6. The new access router 6 executes three actions to check the token by:
Checking the validity of the expiry time of the token;
Checking the identity of the access router which generated the token, in a trust list 7;
After checking the above points a Zufallszahl- Supplement (key-hashed digest) with the Berechtigungsmarken- information using the Berechtigungsmarken- key is calculated and compared with the random number addition, already exists in the token.
If the verification of the token is successful, the binding update and re-authorization process is started. The new access router 6 will authenticate the re-registration request when the session key (BU ACK - message) in the re-registration request, the mobility anchor point (MAP) obtained contained. 2 If the verification fails the access router 6 is not further process the re-registration query. Has the
Mobile radio t 5 yet received a reply on the re-registration from the access router 6 after some time, must the mobile radio terminal 5 a and Autorisations-
Authentication process via the local AAA server 3 and the home AAA server to start, as in an intra domain handover or when the device 5. This can, however, 5 the optimized handover process does not use.
From access router 6 a new token is generated by the session key and the mobile radio terminal 5 sent for the next intra-domain handover, if the re-authentication process did not fail. The old token can not be used. After verification of the token of the access router 6 informs the access router 4 which generated the token, about the use of the token. The access router 4 which generated the token informs all the access routers 1, 6 in its trust lists 7, except for the access router 6 which used the token to prevent a second use of the token.
Achieved the token its expiration time for the validity of the token, the token from the trust lists 7 of the access routers 1, 4, 6 is deleted. A token contains the token information and the random number addition
(Hash code). The token information include:
- The identity of Mobilfunkendgerates 5: the unique identification of Mobilfunkendgerates 5 in the access network; which may be a unique identification which receives a mobile radio terminal 5 after its first registration; The identity of the access router, which
Token has created: The one-time (= only once used, unique) access router
ID may be its IP address or other unique identification possibility in the access network.
The production time for creating the
Token is used to limit the validity of the token. - A random number: This is used to two
Tokens, which were created at the same time to differentiate.
A-hashed message is an excerpt from the token information and the Berechtigungsmarke- key. The calculation of the random number-Extension can be done by the function HMAC-MD5 or HMAC-SHA1 either. The token key is the mobility anchor point (MAP) 2 distributed to each access router and periodically updated.
A token therefore looks like this:
Token: = token information, token-random number addition
Token information: = (identity of the
Mobile radio terminal, identity of the generating access router,
Generation time, random number)
Token-random number suffix: = HMAC (token key, Berechtigungsmarke-
Informations) Figure 2 shows the case that the scope for a created token is the entire access network.
If a token sent to an access router 6 to the first use, is only he (6) safe from DoS attacks because it (6) is the only one who knows that the
Token was used and only he (6) can thus prevent a second use of the token.
Other access routers 1, 4, which does not have information that
have use of the token, could be in danger of not noticing a DoS attack because the access router 6 will not be passed the information on the use of the token in the access network. However, the information about the use of the token to the entire access network caused much signaling traffic in the access network.
Figures 3 and 4 show how each access router its two adjacent access router and itself enters into at least one trust list to reduce the scope of the token, such .. as access router 4 transmits the access router 1 and 6 and themselves in at least one trust list. Thus, the token created by the access router is accepted only by the access routers 1, 4 and 6. FIG. The access router 4 possesses security associations with the access routers 1, 6, and each access router 4, 1 and 6 has at least one trust list 7 with information indicating which tokens it (4) of which access routers 1 , 4 and 6 accepted.
The mobile radio terminal 5 receives a token created by the access router 4, and sends it to an intradomain handover to an access router 6. After successful verification of the token, the
Binding update and the AAA process begin.
The access router that is not of the trust list 7
included access router 4 are (z. B. All other access routers except 1, 4 and 6) are not in danger of a repeated token which has already been used to obtain. The access router 6 which used the token, knows well about the use of communication, ie only the access routers 1 and 4 are in danger of a possible DoS attack, since they would accept this token still.
Figure 5 shows how the access router 6 after having played 6 accepts the token, sends an information immediately to the access router 4, which has generated the token. Thereafter, the access router 4 informs the access router 1 in its trust list 7 and the access router 6, so that it 6 will not accept additional copies of the token. If the verification of the token fails, the re-registration process will not be started, otherwise is started simultaneously with the connection updating process and the re-authorization process. If a re-registration query - arrives (BU ACK message) with the session key in the access router 6, verified this (6) a digital signature to a mobile node over the entire term of the QoS request with the session key in terms the re-authentication was created. After successful verification of the token of the access router 6 adds a message encrypted with the session key new token of the re-registration request - and sends it to the mobile radio terminal 5 (BU ACK message). Figure 6 shows how an access router 4 a
Token created with a processing unit 11 and sends it to a transmitting unit 12 to a mobile radio terminal. Tokens that were created by other access routers 6 are forwarded via a .Empfangseinheit 10 to a processing unit 11, which sends it to another trust list 7 11th Each access router (4, 6) has at least one trust list. In a trust list 7 (trusted list) information on the access router (1, 6) are stored whose tokens will be accepted and in another trust list 7 (trusting list), information on the access router (1.6) is stored, which accept the tokens of the generating access router (4). In a third trust list 7, the token is already in use are stored. Here are all tokens are stored, which have already been used successfully by a mobile radio terminal. When a mobile radio terminal 5 wants to perform an intra-domain handover, it adds (5) the
Token of the re-registration request and sends it (5) as a text to the new access router 6. The new access router 6 receives the token via a receiver unit 10 and forwards it for checking to a processing unit 11th The processing unit 11 performs three actions to check the token by:
- Checking the validity of the expiry time of the token; Verifying the identity of the access router, which
has created token, in a trust list 7;
After checking the above points a Zufallszahl- Supplement (key-hashed digest) with the Berechtigungsmarken- information using the Berechtigungsmarken- key is calculated and compared with the random number addition, already exists in the token.
If the verification of the token is successful, the binding update and re-authorization process is started. The new access router 6 will authenticate the re-registration request when the session key (BU ACK - message) in the re-registration request, the mobility anchor point (MAP) 2 is replaced is a receiving unit 10th If the verification fails 6 is not further process the re-registration query the access router. If the mobile radio terminal 5 yet received a reply on the re-registration from the access router 6 via a transmission unit 12, after some time, the mobile radio terminal 5 must begin a Autorisations- and authentication process via the local AAA server 3 and the home AAA server as in an intra domain handover or when the device. 5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2005107166A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO0122685A1 | Cites | World Intellectual Property Organization (WIPO) | A | International search | 1-24 |
| WO0122685A1 | Cites | World Intellectual Property Organization (WIPO) | A | International search | 1-24 |
| SUBRAMANYAM V ET AL: "Security in mobile systems", RELIABLE DISTRIBUTED SYSTEMS, 1998. PROCEEDINGS. SEVENTEENTH IEEE SYMPOSIUM ON WEST LAFAYETTE, IN, USA 20-23 OCT. 1998, LOS ALAMITOS, CA, USA,IEEE COMPUT. SOC, US, 20 October 1998 (1998-10-20), pages 407 - 412, XP010319125, ISBN: 0-8186-9218-9 | Non-patent | – | – | International search | – |
| HUNG-YU LIN ET AL: "Authentication in wireless communications", GLOBAL TELECOMMUNICATIONS CONFERENCE, 1993, INCLUDING A COMMUNICATIONS THEORY MINI-CONFERENCE. TECHNICAL PROGRAM CONFERENCE RECORD, IEEE IN HOUSTON. GLOBECOM '93., IEEE HOUSTON, TX, USA 29 NOV.-2 DEC. 1993, NEW YORK, NY, USA,IEEE, 29 November 1993 (1993-11-29), pages 550 - 554, XP010109722, ISBN: 0-7803-0917-0 | Non-patent | – | – | International search | – |
| MOLVA R ET AL: "AUTHENTICATION OF MOBILE USERS", IEEE NETWORK, IEEE INC. NEW YORK, US, vol. 8, no. 2, 1 March 1994 (1994-03-01), pages 26 - 34, XP000515077, ISSN: 0890-8044 | Non-patent | – | – | International search | – |
12 members in 8 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0210962 | European Patent Office (EPO) | W | |
| WO2002EP10962 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO2004034717A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002342779A1 | Australia | A1 | |
| US2005079866A1 | United States of America | A1 | |
| EP1547418A1 | European Patent Office (EPO) | A1 | |
| JP2006501780A | Japan | A | |
| US7171202B2 | United States of America | B2 | |
| EP1547418B1 | European Patent Office (EPO) | B1 | |
| AT387825T | Austria | T | |
| ATE387825T1 | Austria | T1 | |
| DE50211804D1 | Germany | D1 | |
| ES2300484T3 | Spain | T3 | |
| JP4278614B2 | Japan | B2 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Wipo information: grant in national officeWWG | WWG | |
| Wipo information: published in national officeWWP | WWP | |
| Wipo information: entry into national phaseWWE | WWE | |
| Wipo information: entry into national phaseWWE | WWE | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | |
| Wipo information: entry into national phaseWWE | WWE | |
| Designated statesAK | AK | |
| Designated countries for regional patentsAL | AL | |
| Wipo information: entry into national phaseWWE | WWE |
Numbers
- Publication
- 2004/034717
- Publication, DOCDB
- 2004034717
- Publication, EPODOC
- WO2004034717
- Application
- 10962
- Application, DOCDB
- 0210962
- Application, EPODOC
- WO2002EP10962
Titles3
- German
- ÜBERPRÜFEN DER EINBUCHUNGSBERECHTIGUNG DURCH EINE ZUGANGS-BERECHTIGUNGSMARKE
- English
- VERIFYING CHECK-IN AUTHENTICATION BY USING AN ACCESS AUTHENTICATION TOKEN
- French
- VERIFICATION D'UNE HABILITATION D'ENREGISTREMENT PAR JETON D'HABILITATION D'ACCES
Classification
- CPC, 7
- H04L63/0807
- H04L63/12
- H04L63/1458
- H04W8/06
- H04W12/062
- H04W12/108
- H04W12/122
- IPC, 6
- H04L29 06
- H04W12 00
- H04W12 06
- H04W12 08
- H04W36 00
- H04W60 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo