IP Library Granted Patent US 9,184,913
Granted Patent B2
US 9,184,913 · App. 14/239,560 · Granted Nov 10, 2015

Authenticating a telecommunication terminal in a telecommunication network

Inventors: Martin Froels (Bonn, DE); Martin Tessmer (Bonn, DE)
Assignee: DEUTSCHE TELEKOM AG
H04L9/14H04W12/06H04L9/3247H04L9/3263H04L63/062H04L63/0823H04L63/0853H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,184,913
App. No.
14/239,560
Granted
Nov 10, 2015
Kind
B2
Abstract

A method for authenticating a telecommunications terminal having an identity module includes: storing a first private key, a first public key and a first signature, the first signature being based on signing the first public key using a second private key; generating identity information and a second signature, the second signature being based on signing the identity information using the first private key; transmitting the first public key, the identity information, and the first and second signatures to a server device; verifying, by the server device, the authenticity of the first public key using a second public key; and verifying, by the server device, the authenticity of the identity information using the verified first public key. The identity information includes International Mobile Subscriber Identity (IMSI) information.

Claims (65)

1. A method for authenticating, on a server device in a telecommunications network, a telecommunications terminal comprising an identity module, wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the method comprising;

storing, at the identity module, the first private key, the first public key and a first signature, the first signature being based on signing the first public key using the second private key;

generating the identity information and a second signature, the second signature being based on signing the identity information using the first private key;

transmitting the first public key, the identity information, and the first and second signatures to the server device;

verifying, by the server device, the authenticity of the first public key using the second public key; and

verifying, by the server device, the authenticity of the identity information using the verified first public key;

wherein the identity information comprises International Mobile Subscriber Identity (IMSI) information corresponding to the identity module.

2. The method according to claim 1 , wherein the telecommunications terminal has a user interface, and the method further comprises, before or during the generating step:

providing user input of confidential information via the user interface.

3. The method according to claim 1 , wherein the transmitting utilizes an encryption protocol.

4. The method according to claim 1 , wherein the transmitting further comprises:

transmitting counter information, wherein the transmission of the counter information allows the server device to distinguish between first and second messages transmitted to the server device during the transmitting using a database corresponding to the server device.

5. The method according to claim 1 , wherein a third key pair comprising a third public key and a third private key is allocated to the server device or to a further server device;

wherein the storing further comprises storing a third signature at the identity module, the third signature being based on signing the first public key with the third private key;

wherein the transmitting further comprises transmitting the third signature to the server device: and

wherein the method further comprises:

verifying, by the server device, the third signature using the third public key; and

verifying, by the server device, the first signature using the first public key.

6. The method according to claim 1 , wherein the identity module is a Subscriber Identity Module (SIM) card or a Universal Subscriber Identity Module (USIM) card.

7. A method for authenticating, on a server device in a telecommunications network, a telecommunications terminal comprising an identity module, wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the method comprising:

storing, at the identity module, the first private key and the first public key, wherein the first public key is stored in an encrypted form, the encrypted form being based on signing the first public key using the second private key;

generating, by the identity module, the identity information in an encrypted form using the first private key;

transmitting the encrypted first public key and the encrypted identity information to the server device;

decrypting, by the server device, the encrypted first public key using the second public key; and

decrypting, by the server device, the encrypted identity information using the decrypted first public key.

8. The method according to claim 7 , wherein the telecommunications terminal has a user interface, and the method further comprises, before or during the generating step:

providing user input of confidential information via the user interface.

9. The method according to claim 7 , wherein the transmitting utilizes an encryption protocol.

10. The method according to claim 7 , wherein the transmitting further comprises:

transmitting counter information, wherein the transmission of the counter information allows the server device to distinguish between first and second messages transmitted to the server device during the transmitting using a database corresponding to the server device.

11. The method according to claim 7 , wherein a third key pair comprising a third public key and a third private key is allocated to the server device or to a further server device;

wherein the storing further comprises storing the first public key in a further encrypted form based on signing the first public key using the third private key;

wherein the transmitting further comprises transmitting the first public key in the further encrypted form to the server device; and

wherein the method further comprises:

decrypting, by the server device, the first public key in the further encrypted form using the third public key.

12. The method according to claim 11 , wherein the identity information is international Mobile Subscriber Identity (IMSI) information of the identity module.

13. The method according to claim 7 , wherein the identity module is a Subscriber Identity Module (SIM) card or a Universal Subscriber Identity Module (USIM) card.

14. A system for authenticating, by a server device of a telecommunications network, a telecommunications terminal comprising an identity module, Wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the system comprising:

the identity module, wherein the identity module is configured to:

store the first private key, the first public key and a first signature, the first signature being based on signing the first public key using the second private key;

generate a second signature, the second signature being based on signing the identity information using the first private key; and

the server device, wherein the server device is configured to:

check the first signature using the second public key; and

check the second signature using the first public key;

wherein the identity information comprises International Mobile Subscriber identity (IMSI) information corresponding to the identity module.

15. A system for authenticating, by a server device of a telecommunications network, a telecommunications terminal comprising an identity module, wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the system comprising:

the identity module, wherein the identity module is configured to:

store the first private key and the first public key, wherein the first public key is stored in an encrypted form, wherein the encrypted form is based on signing the first public key using the second private key;

generate the identity information in an encrypted form using the first private key; and

the server device, wherein the server device is configured to:

decrypt the first public key using the second public key; and

decrypt the identity information using the decrypted first public key.

16. A non-transitory, processor-readable medium having processor-executable instructions stored thereon for authenticating, on a server device in a telecommunications network, a telecommunications terminal comprising an identity module, wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the processor-executable instructions, when executed by a processor, causing the following steps to be performed:

storing, at the identity module, the first private key, the first public key and a first signature, the first signature being based on signing the first public key using the second private key;

generating the identity information and a second signature, the second signature being based on signing the identity information using the first private key;

transmitting the first public key, the identity information, and the first and second signatures to the server device;

verifying, by the server device, the authenticity of the first public, key using the second public key; and

verifying, by the server device, the authenticity of the identity information using the verified first public key;

wherein the identity information comprises International Mobile Subscriber Identity (IMSI) information corresponding to the identity module.

17. A non-transitory, processor-readable medium having processor-executable instructions stored thereon for authenticating, on a server device in a telecommunications network, a telecommunications terminal comprising an identity module, wherein identity information uniquely allocated to the identity module is used for the authentication using asymmetric cryptography, wherein a first key pair comprising a first public key and a first private key is allocated to the identity module, and wherein a second key pair comprising a second public key and a second private key is allocated to the server device, the processor-executable instructions, when executed by a processor, causing the following steps to be performed:

storing, at the identity module, the first private key and the first public key, wherein the first public key is stored in an encrypted form, the encrypted form being based on signing the first public key using the second private key;

generating, by the identity module, the identity information in an encrypted form using the first private key;

transmitting the encrypted first public key and the encrypted identity information to the server device;

decrypting, by the server device, the encrypted first public key using the second public key; and

decrypting, by the server device, the encrypted identity information using the decrypted first public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2014
From: FROELS, MARTIN; TESSMER, MARTIN
To: DEUTSCHE TELEKOM AG
Reel/Frame 032250/0940 →
Priority Claims (2)
DE 10 2011 110 958 · Aug 24, 2011 · national
DE 10 2011 118 367 · Nov 14, 2011 · national
Continuity (1)
Related Publication 20140219448A1 · Aug 7, 2014