Search Images Maps Play YouTube News Gmail Drive More »
Sign in
Screen reader users: click this link for accessible mode. Accessible mode has the same essential features but works better with your reader.

Patents

  1. Advanced Patent Search
Publication numberUSRE40791 E1
Publication typeGrant
Application numberUS 12/004,440
PCT numberPCT/DE2000/001788
Publication date23 Jun 2009
Filing date31 May 2000
Priority date15 Jun 1999
Fee statusPaid
Also published asCN1130099C, CN1314277C, CN1316834C, CN1369183A, CN1516494A, CN1516495A, DE50010928D1, DE50010940D1, DE50013577D1, EP1186193A1, EP1186193B1, EP1326469A2, EP1326469A3, EP1326469B1, EP1326470A2, EP1326470A3, EP1326470B1, US6980796, US7139550, US8565429, US20030229784, US20040006714, WO2000078078A1
Publication number004440, 12004440, PCT/2000/1788, PCT/DE/0/001788, PCT/DE/0/01788, PCT/DE/2000/001788, PCT/DE/2000/01788, PCT/DE0/001788, PCT/DE0/01788, PCT/DE0001788, PCT/DE001788, PCT/DE2000/001788, PCT/DE2000/01788, PCT/DE2000001788, PCT/DE200001788, US RE40791 E1, US RE40791E1, US-E1-RE40791, USRE40791 E1, USRE40791E1
InventorsJorge Cuellar, Guenther Horn
Original AssigneeSiemens Aktiengesellschaft
Export CitationBiBTeX, EndNote, RefMan
External Links: USPTO, USPTO Assignment, Espacenet
Method and system for verifying the authenticity of a first communication participants in a communications network
US RE40791 E1
Abstract
In the method and the arrangement for checking the authenticity of a first communication subscriber in a communications network, a first fault information item is formed in the first communication subscriber using a fault detection data item of the first communication subscriber and an information item relating to a random data item. In a second communication subscriber in the communications network, a second fault information item is formed using a fault detection data item of the second communication subscriber and the information relating to the random data item. The authenticity of the first communication subscriber is checked using the first fault information and the second fault information.
Images(5)
Previous page
Next page
Claims(20)
1. A method for checking the authenticity of a first communication subscriber in a communications network, comprising:
forming a first fault information item in the first communication subscriber using a fault detection data item of the first communication subscriber and an information item relating to a random data item which has been transmitted to the first communication subscriber by a second communication subscriber in the communications network;
transmitting the first fault information to the second communication subscriber by the first communication subscriber,
forming a second fault information item in the second communication subscriber using a fault detection data item of the second communication subscriber and the information item relating to the random data item;
checking the authenticity of the first communication subscriber in the second communication subscriber using the first fault information item and the second fault information item.
2. The method as claimed in claim 1, wherein a difference is determined between the fault detection data item of the first communication subscriber and the fault detection data item of the second communication subscriber.
3. The method as claimed in claim 2, wherein the difference is limited.
4. The method as claimed in claim 1, wherein the first and second communication subscribers are part of a mobile phone system.
5. The method as claimed in claim 2, wherein the first and second communication subscribers are part of a mobile phone system.
6. The method as claimed in claim 3, wherein the first and second communication subscribers are part of a mobile phone system.
7. A system for checking authenticity in a communications network, comprising:
a first communication subscriber to form a first fault information using a fault detection data item of the first communication subscriber and an information item relating to a random data item which has been transmitted to the first communication subscriber, and to transmit the first fault information;
a second communication subscriber to transmit the information relating to the random data item to the first communication subscriber, to receive the first fault information from the first communication subscriber, to form a second fault information using a fault detection data item of the second communication subscriber and the information relating to the random data item, and to check the authenticity of the first communication subscriber using the first fault information and the second fault information.
8. The system as claimed in claim 7, wherein the first communication subscriber is a service provider and the second communication subscriber is a service user in the communications network.
9. The system as claimed in claim 8, wherein the service provider is a mobile phone operator and the service user is a mobile phone.
10. The system as claimed in claim 7, wherein the fault detection data items are sequential numbers.
11. The system as claimed in claim 10, wherein the information relating to the random data item is a random number.
12. The system as claimed in claim 7, wherein the first and second communication subscribers are part of a mobile phone system.
13. The system as claimed in claim 10, wherein the first communication subscriber is a service provider and the second communication subscriber is a service user in the communications network.
14. The system as claimed in claim 13, wherein the service provider is a mobile phone operator and the service user is a mobile phone.
15. The system as claimed in claim 11, wherein the first communication subscriber is a service provider and the second communication subscriber is a service user in the communications network.
16. The system as claimed in claim 15, wherein the service provider is a mobile phone operator and the service user is a mobile phone.
17. The system as claimed in claim 8, wherein the fault detection data items are sequential numbers.
18. The system as claimed in claim 17, wherein the information relating to the random data item is a random number.
19. The system as claimed in claim 18, wherein the service provider is a mobile phone operator and the service user is a mobile phone.
20. A method for a second communication subscriber to confirm the authenticity of a first communication subscriber in a communications network, comprising:
transmitting an information item relating to a random data item to the first communication subscriber;
receiving a first fault information item from the first communication subscriber, the first fault information item being formed using a fault detection data item of the first communication subscriber and the information item relating to the random data item;
forming a second fault information item in the second communication subscriber using a fault detection data item of the second communication subscriber and the information item relating to the random data item; and
checking the authenticity of the first communication subscriber in the second communication subscriber using the first fault information item and the second fault information item.
Description
CROSS REFERENCE TO RELATED APPLICATIONS

This application is based on and hereby claims priority to German Application No. 19927 271.9 filed on Jun. 15, 1999 in Germany, and PCT Application No. PCT/DE00/01788 filed on May 31, 2000, the contents of which are hereby incorporated by reference. This application is a reissue of 10/009/975, patent 6,980,796.

BACKGROUND OF THE INVENTION

The invention relates to a method and an arrangement for checking the authenticity of a first communication subscriber in a communications network.

In a communications network, data is generally transmitted between communication subscribers, for example a service provider and a service user. In order to protect a communications network against penetration of an unauthorized communication subscriber into the communications network, the authenticity of each communication subscriber is generally checked.

3G TS 33.102 Version 3.0.0 Draft Standard, 3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, 3G Security, Security Architecture, 05/1999 (“the 3G reference”) discloses a method and an arrangement for checking the authenticity of a communication subscriber, in particular of a service provider or of a service user in a communications network.

The method known from the 3G reference and the corresponding arrangement are based on what is referred to as 3G TS 33.102 Version 3.0.0 Draft Standard, which describes a security architecture of a mobile phone system.

In FIG. 4, the procedure during the checking of the authenticity of a communication subscriber, such as is known from the 3G reference is illustrated symbolically and parts thereof will be explained below briefly.

A transmission of data is illustrated in FIG. 4 by an arrow in each case. A direction of an arrow characterizes a transmission direction during a data transmission.

FIG. 4 shows a mobile phone system 400, comprising a user 401 of a communication service, for example a mobile phone, and a provider 402 of a communication service. The provider 402 comprises a dial-in network 403 with a dial-in network operator from which the user 401 locally requests a communication service, and a home network 404 with a home network operator with which the user 401 is signed on and registered.

In addition, the user 401, the dial-in network 403 and the home network 404 each have a central processing unit with a memory, for example a server (central computing unit), with which processing unit the procedure described below is monitored and controlled and on which memory data is stored.

The dial-in network 403 and the home network 404 are connected to one another via a data line over which digital data can be transmitted. The user 401 and the dial-in network 403 are connected to one another via any desired transmission medium for the transmission of digital data.

During a communication, the user 401 dials 410 into the dial-in network 403. At the start of the communication, checking of both the authenticity of the user 401 and the authenticity of the provider 402 is carried out.

To do this, the dial-in network 403 requests 411 what is referred to as authentication data from the home network 404, with which data the authenticity of the user 401 and of the provider 402 can be checked.

The authentication data which is obtained from the home network 404 comprises a random number and a sequential number of the provider 402. The sequential number of the provider 402 is obtained in such a way that a counter of the provider 402 increases the sequential number of the provider 402 by the value 1 at each attempt at communication between the user 401 and the provider 402.

It is to be noted that the random number and the sequential number of the provider 402 only constitute part of the authentication data and are not to be understood as comprehensive. Further authentication data is known from the 3G reference.

The home network 404 transmits 412 the requested authentication data to the dial-in network 403. The dial-in network 403 processes the received authentication data in a suitable way 413, and transmits the processed authentication data to the user 401.

The user 401 checks 415 the authenticity of the provider 402 using a dedicated sequential number, which is handled in a way corresponding to the sequential number of the provider 402, and using the sequential number of the provider 402.

The procedure during the checking of the authenticity of the provider 402 is described in the 3G reference.

A result of the checking of the authenticity of provider 402, “authenticity of provider satisfactory” 416, “authenticity of provider satisfactory but sequential fault has occurred” 417 or “authenticity of provider not satisfactory” 418, is transmitted 419 from the user 401 to the provider 402.

In the case of the result “authenticity of provider satisfactory” 416, the dial-in network 403 checks 420 the authenticity of the user 401 as described in the 3G reference.

In the case of the result “authenticity of provider not satisfactory” 418, the communication is interrupted and/or restarted 421.

In the case of the result “authenticity of provider satisfactory but a sequential fault has occurred” 417, resynchronization takes place in such a way that the home network 404 transmits 422 a resynchronization request to the user 401. The user responds with a resynchronization response in which resynchronization data is transmitted 423 to the home network 404. The sequential number of the provider 402 is changed 424 as a function of the resynchronization response. The authenticity of the user 401 is then checked, as is known from the 3G reference.

The procedure described has the disadvantage that during checking of the authenticity of a communication subscriber, in particular during the checking of the authenticity of a service provider, a large amount of data has to be transmitted between the communication subscribers.

SUMMARY OF THE INVENTION

One aspect of the invention is thus based on simplifying and improving the known method and the known arrangement, to yield a simplified and improved arrangement for checking the authenticity of a communication subscriber in a communications network.

In the method for checking the authenticity of a first communication subscriber in a communications network, a first fault information item is formed in the first communication subscriber using a fault detection data item of the first communication subscriber and an information item relating to a random data item. In a second communication subscriber in the communications network, a second fault information item is formed using a fault detection data item of the first communications subscriber and the information relating to the random data item.

The authenticity of the first communication subscriber is checked using the first fault information item and the second fault information item.

In the arrangement for checking the authenticity of a first communication subscriber in a communications network, the first communication subscriber is set up in such a way that a first fault information item can be formed using a fault detection data item of the first communication subscriber and an information item relating to a random data item. In addition, the arrangement has a second communication subscriber in the communications network which is set up in such a way that a second fault information item can be formed using a fault detection data item of the second communication subscriber and the information relating to the random data item. The authenticity of the first communication subscriber can be checked using the first fault information item and the second fault information item.

The checking of the authenticity of a communication subscriber in a communications network is to be understood as meaning method steps which are carried out in the wider sense with checking of the authorization of a communication subscriber for access to a communications network or participation in communication in a communication network.

This thus encompasses both method steps which are carried out within the scope of the checking of the authorization of a communication subscriber for access to a communications network and such method steps which are carried out within the scope of the processing or the administration of data which is used in the checking.

The developments described below relate to the method and to the arrangement.

The development described below can be implemented either using software or hardware, for example using a specific electrical circuit.

In one refinement, the first communication subscriber is a service provider and/or the second communication subscriber is a service user in the communications network.

A sequential number is preferably used as the fault detection data item.

In one refinement, the information relating to the random data item is a random number.

In one development, the checking of the authenticity is simplified by determining a difference between the fault detection data item of the first communication subscriber and the fault detection data item of the second communication subscriber.

In one refinement, the checking of the authenticity is further improved with respect to the security of the communications network by limiting the difference.

One development is preferably used within the scope of a mobile phone system. In the mobile phone system, the service user is implemented as a mobile phone and/or the service provider is implemented as a mobile phone network operator.

BRIEF DESCRIPTION OF THE DRAWINGS

These and other objects and advantages of the present invention will become more apparent and more readily appreciated from the following description of the preferred embodiments, taken in conjunction with the accompanying drawings of which:

FIG. 1 shows a mobile phone system;

FIG. 2 shows an outline in which checking of the authenticity of a communication subscriber is illustrated symbolically;

FIG. 3 shows a flowchart in which individual method steps are illustrated during checking of the authenticity of a service provider in a communications network; and

FIG. 4 shows an outline in which checking of the authenticity of a communication subscriber in accordance with the 3G TS 33.102 Version 3.0.0 Standard is illustrated symbolically.

DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT

Reference will now be made in detail to the preferred embodiments of the present invention, examples of which are illustrated in the accompanying drawings, wherein like reference numerals refer to like elements throughout.

Exemplary Embodiment: Mobile Phone System

A mobile phone system 100 is illustrated in FIG. 1. The mobile phone system 100 comprises a mobile phone 101, a local dial-in network 102 with a dial-in network operator 103 and a home network 104 with a home network operator 105.

The mobile phone 101 is signed on and registered in the home network 104.

In addition, the mobile phone 101, the dial-in network 102 and the home network 104 each have a central processing unit 106, 107, 108 with a memory 109, 110, 111, with which processing units 106, 107, 108 the procedure described below is monitored and controlled, and on which memories 109, 110, 111 data is stored.

The dial-in network 102 and the home network 104 are connected to one another via a data line 112 via which digital data can be transmitted. The mobile phone 101 and the dial-in network 102 are connected to one another via any desired transmission medium 113 for transmitting digital data.

The procedure during the checking of the authenticity of the mobile phone 101 and the procedure during the checking of the authenticity of the home network 104 and/or of the home network operator 105 are illustrated symbolically in FIG. 2, and parts thereof will be explained below briefly.

The transmission of data in FIG. 2 is illustrated in each case by an arrow. A direction of an arrow characterizes a transmission direction during a data transmission.

The procedure which is described below and illustrated symbolically in FIG. 2 is based on what is referred to as a 3G TS 33.102 Version 3.0.0 Standard, which describes a security architecture of a mobile phone system and is described in the 3G reference.

During a communication, the mobile phone 201 dials 210 into the dial-in network 203. At the start of the communication, checking both of the authenticity of the mobile phone 201 and of the authenticity of the home network 204 and/or of the home network operator takes place.

To do this, the dial-in network 203 requests 211 authentication data from the home network 204, with which authentication data the authenticity of the user 201 and of the home network 204 and/or of the home network operator can be checked.

The authentication data which is determined by the home network 204 comprises a random number and a sequential number of the home network 204 (cf. FIG. 3 step 310). The sequential number of the home network 204 is determined in such a way that a counter of the home network 204 increases the sequential number of the home network 204 by the value 1 at each attempt at communication between the mobile phone 201 and the home network 204.

It is to be noted that the random number and the sequential number of the home network 204 only constitute part of the authentication data and are not to be understood as comprehensive. Further authentication data is specified in the 3G reference.

The home network 204 transmits 212 the requested authentication data to the dial-in network 203. The dial-in network 203 processes the received authentication data in a suitable way 213 and transmits the processed authentication data to the mobile phone 201.

The mobile phone 201 checks 215 the authenticity of the home network 204 using a dedicated sequential number which is handled in a way corresponding to the sequential number of the home network 204, and using the sequential number of the home network 204. In a way corresponding to the home network 204, the mobile phone 201 also has a counter.

The procedure during the checking of the authenticity of the home network 204 is described in the 3G reference. Method steps which differ therefrom are described below.

What is referred to as overflow checking of the counter of the mobile phone 201 is carried out within the scope of the checking of the authenticity of the home network 203. This overflow checking prevents overflowing of an acceptable numerical range of the counter of the mobile phone 201.

In the overflow checking, the following conditions are tested:

    • 1) sequential number of the home network 204>sequential number of the mobile phone 201;
    • 2) sequential number of the home network 204−sequential number of the mobile phone 201<−predefinable deviation (1,000,000);
    • the following applying for the predefined deviation:
      • predefinable deviation is sufficiently large in order to ensure, during normal or fault-free communications operation:
      • that the sequential number of the home network 204—sequential number of the mobile phone 201 is not>predefinable deviation;
        • the maximum permissible sequential number of the mobile phone 201/predefinable deviation is sufficiently large in order to ensure that the maximum permissible sequential number of the mobile phone 201 is not reached during operation.

The result of the checking of the authenticity of the home network 204, “authenticity satisfactory” 216, “authenticity satisfactory but a sequential fault has occurred” 217 or “authenticity not satisfactory” 218 is transmitted 219 to the home network 204 from the mobile phone 201.

In the case of the result “authenticity satisfactory” 216, the dial-in network 203 checks 220 the authenticity of the mobile phone 201, as described in 3G reference.

In the case of the result “authenticity not satisfactory” 218, the communication is interrupted or restarted 221.

In the case of the result “authenticity satisfactory but a sequential fault has occurred” 217, resynchronization 222 takes place. Resynchronization is to be understood as a change of the sequential number of the home network 204.

For this purpose, the mobile phone 201 transmits 222 resynchronization data to the dial-in network 203.

The resynchronization data comprises the same random number which was transmitted within the scope of the authentication data, and the sequential number of the mobile phone 201 (cf. FIG. 3 step 320).

The dial-in network 203 processes the resynchronization data in a suitable way and transmits the processed resynchronization data to the home network 204.

The home network 204 checks the sequential number of the mobile phone 201 and the sequential number of the home network 204 using the processed resynchronization data, and if appropriate changes 223 the sequential number of the home network 204 (cf. FIG. 3 step 330).

The home network 204 sequentially transmits new authentication data, which if appropriate comprises the changed sequential number of the home network 204, to the dial-in network 203.

In order to illustrate the described procedure, important steps 300 of the procedure are illustrated in FIG. 3.

FIG. 3 shows a first step 310 within the scope of which the authentication data (first fault information) is determined.

The resynchronization data (second fault information) is determined within the scope of a second step 320.

The sequential number of the mobile phone and the sequential number of the home network are checked within the scope of a third step 330, using the resynchronization data.

An alternative of the first exemplary embodiment is described below.

In the alternative exemplary embodiment, a method is implemented in which the home network is made more reliable with respect to a data in the event of a system crash.

For this purpose, the current sequential number of the home network is stored in the memory of the home network, in each case at a predefinable time interval. A sequential number of the home network which has been lost during a system crash of the home network is restored in such a way that a predefinable additional value is added to the value of the stored sequential number. The predefinable additional value is dimensional in such a way that exceeding of the sum of the sequential number of the mobile phone and the predefinable deviation is not exceeded.

In the alternative exemplary embodiment, the predefinable additional value is determined in such a way that an average number of authentication attempts on one day by the home network, which number is determined during operation of the communications network, is multiplied by a factor with the value 10.

The invention has been described in detail with particular reference to preferred embodiments thereof and examples, but it will be understood that variations and modifications can be effected within the spirit and scope of the invention.

Patent Citations
Cited PatentFiling datePublication dateApplicantTitle
US451906811 Jul 198321 May 1985Motorola, Inc.Method and apparatus for communicating variable length messages between a primary station and remote stations of a data communications system
US5239294 *7 Dec 199024 Aug 1993Motorola, Inc.Method and apparatus for authenication and protection of subscribers in telecommunication systems
US5241598 *22 May 199131 Aug 1993Ericsson Ge Mobile Communications, Inc.Rolling key resynchronization in cellular verification and validation system
US5282250 *27 May 199325 Jan 1994Telefonaktiebolaget L M EricssonMethod of carrying out an authentication check between a base station and a mobile station in a mobile radio system
US5557654 *23 Feb 199317 Sep 1996Nokia Telecommunications OySystem and method for authenticating subscribers of a transmission network and subscription, having differing authentication procedures, using a common authentication center
US5572193 *22 Aug 19945 Nov 1996Motorola, Inc.Method for authentication and protection of subscribers in telecommunications systems
US5642401 *28 Jun 199424 Jun 1997Nec CorporationSystem and method of authenticating a service request in a mobile communication system
US5689563 *1 Jun 199518 Nov 1997Motorola, Inc.Method and apparatus for efficient real-time authentication and encryption in a communication system
US5794139 *10 Oct 199511 Aug 1998Sony CorporationFor use in a cellular mobile telephone system
US5799084 *6 May 199625 Aug 1998Synacom Technology, Inc.System and method for authenticating cellular telephonic communication
US5953652 *24 Jan 199714 Sep 1999At&T Wireless Services Inc.Detection of fraudulently registered mobile phones
US599162327 Dec 199623 Nov 1999Fujitsu LtdMethod and system for preventing unjust use of personal communication terminal
US6016349 *18 Dec 199618 Jan 2000Musa; LorenzoCellular phone provided with legal identification means of the owner of the cellular phone
US6035039 *17 Feb 19987 Mar 2000Tisdale; William R.Fraud detection and user validation system for mobile earth terminal communication device
US6078807 *26 Aug 199720 Jun 2000International Business Machines CorporationTelephony fraud detection using voice recognition techniques
US6091945 *26 Mar 199718 Jul 2000Sony CorporationAuthentication method for radio communication system, radio communication system, radio communication terminal and communication managing apparatus
US6108424 *5 Jan 199822 Aug 2000U.S. Philips CorporationMobile radio telephone station comprising a protection system for at least one authentication number and method of protecting an authentication number
US6118993 *5 Jan 199812 Sep 2000Lucent Technologies, Inc.Effective use of dialed digits in call origination
US64667803 Sep 199715 Oct 2002Interlok Technologies, LlcMethod and apparatus for securing digital communications
US6618584 *30 Aug 20009 Sep 2003Telefonaktiebolaget Lm Ericsson (Publ)Terminal authentication procedure timing for data calls
US6665530 *27 Jan 199916 Dec 2003Qualcomm IncorporatedSystem and method for preventing replay attacks in wireless communication
US6741852 *5 May 199825 May 2004Detemobil Deutsche Telekom Mobilnet GmbhMethod and device to authenticate subscribers in a mobile radiotelephone systems
US6839553 *22 Mar 20024 Jan 2005Lg Information & Communications, Ltd.Method of managing mobile station operational parameters
US698079631 May 200027 Dec 2005Siemens AktiengesellschaftMethod and system for verifying the authenticity of a first communication participants in a communications network
DE19524021A1 *30 Jun 19952 Jan 1997Siemens AgVerfahren zum Verschlüsseln von Informationen in ATM-Systemen
JPH0984124A Title not available
JPH05508274A Title not available
JPH08242488A Title not available
WO1991001067A214 Jun 199013 Jan 1991Motorola IncMethod for authentication and protection of subscribers in telecommunication systems
WO1992002103A115 Jul 199117 Jan 1992Motorola IncMethod for authentication and protection of subscribers in telecommunication systems
Non-Patent Citations
Reference
1 *3G TS 33.102 version 3.0.0-Draft Standard, 3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, 3G Security Architecture (May 1999).
2 *3G TS 33.102 version 3.4.2-Draft Standard 3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, 3G Security Architecture (Sep. 2001) (Release 4).
3 *3G TS 33.102 version 3.9.0-Draft Standard, 3rdGeneration Partnership Project, Technical Specification Group Services and System Aspects, 3G Security Architecture (Jun. 2001) (Release 1999).
43rd Generation Partnership Project, Technical Specification Group Services and System Aspects, 3G Security, Security Architecture, Release 4, 3GPP TS 33.102 V4.4.0 (Jun. 2002).
5 *Patent Abstract of Germany-DE 197 18 827 A1-Mohrs, Nov. 19, 1998.
6Patent Abstract of Japanese Publication No. JP-4-24954 published Sep. 4, 1992.
7Patent Abstract of Japanese Publication No. JP-5-503816 published Jun. 17, 1993.
8 *The GSM System, Mobility and Security Management, pp. 433-498 XP-000860007.
Classifications
U.S. Classification455/410, 380/270, 713/182, 380/271, 380/247, 455/411
International ClassificationH04L9/00, G06F11/30, H04W12/10, H04L9/32, H04W12/06, H04L12/28, H04M1/66, G09C1/00, G06F21/20
Cooperative ClassificationH04W12/06, H04W12/10, H04L63/126
European ClassificationH04L63/12B, H04W12/06, H04W12/10
Legal Events
DateCodeEventDescription
7 Mar 2013FPAYFee payment
Year of fee payment: 8
6 Oct 2009CCCertificate of correction