Nova Patents
WO9927678A2

Security of data connections

Abstract

The invention concerns the security of the data connections of a telephone user. The basic idea of the invention is to forward the authentication of a telephone system to the leg between two private data networks connected via an arbitrating network. When establishing the connection, the private network connected to the telephone system forwards the authenticated subscriber identity to the other private network. To provide the identity forwarded with authenticity, the message containing the identity is signed. To provide encryption of the subscriber identity, the message is encrypted using a public key method. In response the second private network generates a session key to be used in the connection. This key is signed and encrypted using a public key method and sent to the first private network. During the connection, a symmetrical encryption method with the session key is used.

WO9927678A2, drawing sheet 1
Sheet 1 of 11

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

27 claims: 5 independent, 22 dependent

  1. 1
    Claims 1. Method of providing security of data connections in an arrangement comprising a telecommunication network comprising subscribers, a first private data network connected to the telecommunication network, a second private data network comprising a server providing data services, in which method the subscriber is authenticated for the first private data network using the authentication method of the telecommunication network, ch a racterized in that in addition to the identification of the subscriber is added an authenticity code in the first private data network and a message comprising the subscriber identity and the authenticity code is sent to the second private data network, and in response to having received the message in the second private data network:the authenticity code is verified, the identified user's right to the requested service is checked, and if the user is entitled to the requested service, a reply is generated and sent to the first private data network.
  2. 4
    A method according to claim ^ characterized in that the authenticity code is a message authentication code MAC.
  3. 16
    A method according to claim ^ cha racterized in that the reply comprises a session key to be used to encrypt the data traffic on the leg between the first and the second private data networks in a connec- tion to be established between the subscriber and the server.
  4. 21
    An authentication server for a data network connected to a telecommunication network cha racterized in that the authentication server has receiving means for receiving a subscriber identity from the tele- communication network, determining means responsive to the receiving means for determining the identity of a second authentication server on the basis of the identity of the subscriber, signing means responsive to the receiving means for generating a digital signature, sending means responsive to the receiving means, the determining means, and the signing means, which has the functionality of sending the identity and the signature to the second authentication server.
  5. 25
    An authentication server for a data network characterized in that the authentication server has receiving means for receiving a subscriber identity and a digital signature calculated from the subscriber identity and the identification of a service requested by the subscriber, verification means responsive to the receiving means for verifying the digital signature, checking means responsive to the receiving means for checking the subscriber's right to the requested service, generation means responsive to the checking means for generating a session key, encryption means responsive to the generation means for encrypting the session key, and sending means responsive to the encryption means for sending the encrypted message to another authentication server.