WO9501684A1

Method and apparatus for efficient real-time authentication and encryption in a communication system

Abstract

Radio frequency based cellular telecommunication systems often require both subscriber units (100) and communication units (130) of a fixed network communication system to maintain secret data which may be used to verify authenticity as well as provide encrypting variables for message encryption processes. An efficient real-time authentication method and apparatus are provided which use a single message (210) to provide authentication and communication link setup information. Further, an authentication method and apparatus are provided which uses instant-specific information such as a time of day, radio frequency carrier frequency, a time slot number, a radio port number, access manager identifier, a radio port control unit identifier, or a base site controller identifier to enhance the reliability of the authentication process. Furthermore, a method and apparatus are provided for maintaining secure packet data communications through an encryption process by utilizing a packetized message encryption key (502) and a unique packet number (504) as encryption variables.

WO9501684A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

10 claims: 6 independent, 4 dependent

  1. 1
    Claims What is claimed is:1. A subscriber unit which authenticates communications with a communication unit of a communication system, comprising: (a) memory means for maintaining first subscriber unit identifier, first shared-secret data, second shared-secret data, a random challenge, and instant-specific information;(b) processor means, operatively coupled to the memory means, for generating an authentication message as a function of the first shared-secret data, the random challenge, and the instant-specific information;(c) key generation means, operatively coupled to the memory means, for generating, a session key as a function of the first shared-secret data, the second shared-secret data, the random challenge, and the instant-specific information;(d) encrypting means, operatively coupled to the key generation means, for forming encrypted data by encrypting dialed digits which uniquely identify a target communication unit and a second subscriber unit identifier by using the session key as an encryption variable;and (e) transmitter means, operatively coupled to the memory means, processor means, and key generation means, for transmitting, in a single message, the first subscriber unit identifier, the authentication message and the encrypted data to the communication unit.
  2. 3
    A communication unit which authenticates communications with a subscriber unit of a communication system, comprising:(a) receiver means for receiving, in a single message, a first subscriber unit identifier, an authentication message and encrypted data;(b) memory means for maintaining first shared-secret data, 5 second shared-secret data, a random challenge, and instant-specific information;(c) key generation means, operatively coupled to the memory means, for generating, a session key as a function of the first shared-secret data, the second shared-secret data, the 10 random challenge, and the instant-specific information;and (d) processor means, operatively coupled to the receiver means, the memory means, and the key generation means, for determining whether the communicated 15 authentication message is authentic, comprising: (i) generator means for generating an expected authentication message as a function of the first shared-secret data, the random challenge, and the instant-specific information;20 (ii) comparison means for comparing the received authentication message and the expected authentication message;(iii) means for recovering the dialed digits which uniquely identifies the target communication unit 25 and the second subscriber unit identifier by decrypting the communicated encrypted data by using the session key as an decryption variable and for establishing a communication link on a traffic channel with between the subscriber unit and the 30 communication unit, if the received authentication message is substantially similar to the expected authentication message;and (iv) means for providing output indicating that a multiple user is attempting to access the communication 35 system, if the received authentication message is not substantially similar to the expected authentication message.
  3. 5
    A communication unit which authenticates communications with subscriber unit operating within a communication system, comprising:(a) memory means for maintaining first shared-secret data, second shared-secret data, a random challenge, and instant-specific information;(b) processor means, operatively coupled to the memory means, for generating an authentication message as a function of the first shared-secret data, the random challenge, and the instant-specific information;(c) key generation means, operatively coupled to the memory means, for generating, a session key as a function of the first shared-secret data, the second shared-secret data, the random challenge, and the instant-specific information;(d) encrypting means, operatively coupled to the key generation means, for forming encrypted data by encrypting a second subscriber unit identifier by using the session key as an encryption variable;and (e) transmitter means, operatively coupled to the memory means, processor means, and key generation means, for transmitting, in a single message, the authentication message and the encrypted data to the subscriber unit.
  4. 6
    A subscriber unit which authenticates communications with a communication unit of a communication system, comprising:(a) receiver means for receiving, in a single message, an authentication message and encrypted data;(b) memory means for maintaining first shared-secret data, second shared-secret data, a random challenge, and instant-specific information;(c) key generation means, operatively coupled to the memory means, for generating, a session key as a function of the first shared-secret data, the second shared-secret data, the random challenge, and the instant-specific information;and (d) processor means, operatively coupled to the receiver means, the memory means, and the key generation means, for determining whether the communicated authentication message is authentic, comprising: (i) generator means for generating an expected authentication message as a function of the first shared-secret data, the random challenge, and the instant-specific information;(ii) comparison means for comparing the received authentication message and the expected authentication message;(iii) means for recovering the second subscriber unit identifier by decrypting the communicated encrypted data by using the session key as an decryption variable and for establishing a communication link on a traffic channel with between the subscriber unit and the communication unit, if the received authentication message is substantially similar to the expected authentication message;and (iv) means for providing output indicating that a multiple user is attempting to access the communication system, if the received authentication message is not substantially similar to the expected authentication message.
  5. 7
    A method of authentication between a subscriber unit and a communication unit of a communication system, comprising:(a) providing instant-specific information to the subscriber unit and the communication unit;(b) generating an authentication message as a function of the instant-specific information;(c) communicating the authentication message between the subscriber unit and the communication unit;(d) generating an expected authentication message as a function of the instant-specific information;and (e) determining whether the communicated authentication message is authentic by comparing the communicated authentication message and the expected authentication message.
  6. 10
    A method for maintaining secure packet data communications through an encryption process between a subscriber unit and radio communication units of a serving communication system, comprising:(a) generating a packetized message encryption key within the subscriber unit and the serving communication system;(b) numbering a packet of a message with a unique packet number such that a sequential order of the packet in the packetized message can be maintained;(c) encrypting the packet of the message by using the packetized message encryption key and the unique packet number as encryption variables;(d) communicating the unique pack number and the encrypted packet of the message between the subscriber unit and a radio communication unit of the serving communication system;and (e) decrypting the communicated encrypted packet of the message by using the generated packetized message encryption key and the communicated unique packet number.