Method for issuing authorisation tickets in an intelligent transport system

CA3067085CActive Publication Date: 2026-08-11KAPSCH TRAFFICCOM AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CA3067085
Authority / Receiving Office
CA · CA
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-01-25
Filing Date
2020-01-08
Publication Date
2026-08-11
Estimated Expiration
2040-01-08
Patent Text Reader

Abstract

The invention relates to a method for issuing pseudonymous authorisation tickets to nodes of a cooperative ITS, for sign- ing messages, the method comprising: receiving a ticket request from a node in an authorisation server, and sending a valida- tion request to an enrolment server, conducting a validity check in the enrolment server, and, when the validity check is passed, incrementing a counter value of a counter assigned to an account at an account server enrolled with the enrolment server for the requesting node, sending a validation message to the authorisation server, and issuing a pseudonymous authorisa- tion ticket from the authorisation server to the requesting node; repeating the aforementioned steps until a predetermined charging period expires, and, upon expiry, sending, from the enrolment server to the authorisation server, said counter val- ue, and sending a charging request calculated from said counter value from the authorisation server to the account server for charging said account.
Need to check novelty before this filing date? Find Prior Art

Description

in an Intelligent Transport System The present invention relates to a method for issuing pseudonymous authorisation tickets to nodes of a cooperative intelligent transport system, which nodes exchange messages, each of which is signed with one of said authorisation tickets. An intelligent transportation system ("ITS") allows road users and traffic managers to share information exchanged by messages between vehicles and infrastructure (also known as "ITS stations", herein referred to as "nodes") in form of vehi- cle-to-vehicle (V2V) and / or vehicle-to-infrastructure (V2I) communication, and to coordinate their actions. Systems of such kind are known, inter alia, from the European Strategy on Coop- erative Intelligent Transport Systems ("C-ITS"), an initiative discussing and implementing cooperative, connected and automat- ed mobility in an ITS. A significant improvement in road safe- ty, traffic efficiency and comfort of driving is expected from deploying an ITS in consequence of helping the driver - enabled by digital connectivity between vehicles and between vehicles and infrastructure - to take the right decisions and adapt to the traffic situation. For many digital connectivity scenarios, the authenticity and integrity of the messages which typically contain infor- mation such as position, velocity, heading, etc. have to be verified with respect to the trustworthiness of the exchanged information. However, the impact on privacy of each road user should be minimized. For achieving those two objectives, it has been proposed by C-ITS that each message sent from one node shall be signed by a pseudonymous authorisation ticket that has been issued to the node upon its request by a trusted authori- sation server (also known as "authorisation authority") and thereby ensures authenticity without the node identifying it- self in the message. Each authorisation ticket may be used by the node to sign one or more messages; however, for reasons of privacy, used authorisation tickets shall be replaced by new ones frequently. Moreover, the identity of each node is certi- fied by an enrolment server (also known as "enrolment authori- ty"), with which each node has to enrol and which validates each authorisation ticket prior to issuing by the authorisation server. For privacy reasons, the authorisation server and the en- rolment server, though communicating with each other, are sepa- rate from one another such that the authorisation server has no access to the identities of the nodes registered with the en- rolment server and the enrolment server has no access to the authorisation tickets issued by the authorisation server. While the authenticity and integrity of each message ex- changed in the ITS can thereby be proven effectively, the num- ber of pseudonymous authorisation tickets to be issued by the authorisation server is very high in an ITS having lots of nodes. Hence, the load on the authorisation server reaches high levels. Nevertheless, it is desired to serve a large number of CA • . nodes such that all important traffic information is accessible for sharing within the ITS. It is an object of the present invention to provide a method for issuing pseudonymous authorisation tickets which fa- cilitates the implementation of an ITS for a large number of nodes with improved privacy. According to the present invention, this object is achieved by a method of the type mentioned in the outset, com- prising: a) receiving a ticket request from a node in an authori- sation server of the ITS, which ticket request contains enrol- ment credentials of the requesting node, wherein the enrolment credentials are encrypted with a public key of an enrolment server of the ITS, and sending a validation request containing the requesting node's enrolment credentials to the enrolment server; b) decrypting the enrolment credentials contained in the validation request with a respective private key in the enrol- ment server, conducting a validity check which is only passed when both the requesting node identified by the decrypted en- rolment credentials and, for the requesting node, an account at an account server are enrolled with the enrolment server, and, in case the validity check is passed, incrementing a counter value of a counter assigned to said account and sending a vali- dation message to the authorisation server; CA c) issuing, when the validation message is received in the authorisation server, a pseudonymous authorisation ticket to the requesting node; d) repeating steps a) to c) until a predetermined charg- ing period expires, and, upon expiry, sending, from the enrolment server to the authorisation server, a message containing said counter value and an identi- fier for said account, calculating, from the counter value received in the au- thorisation server, a charging request for the account identi- fied by the received identifier, and sending the charging re- quest to the account server for charging said account. The present method allows for offering the issuing of pseudonymous authorisation tickets by the authorisation server in form of a decentralized charged service. Thereby, new au- thorisation servers may, even one-by-one, be added to the ITS and a sharing of efforts (or load) between the authorisation servers is facilitated such that even a large - and still grow- ing - number of nodes can be served in the ITS. Concurrently, the privacy of each node is not only kept but even improved due to the fact that a relation between an issued ticket and a requesting node cannot be derived from the accumulated counter value. Hence, the authorisation server, de- spite issuing the authorisation tickets to the respective re- questing nodes and sending charging requests to the account server for charging the account of the requesting node, does not have the information necessary to create a link between a . node's identity or account and the authorisation tickets issued to the node. Moreover, the authorisation server cannot decrypt the enrolment credentials of the requesting node in the ticket request. Consequently, neither the authorisation server nor the enrolment server, which has no information on the issued au- thorisation tickets, can retrace which authorisation ticket was issued to which node. It shall be noted in this context that the node when sending a ticket request uses, e.g., a one-time identifier or the like for identification vis-à-vis the author- isation server. It shall be understood that there may be more than one ac- count server. Each account server may keep one or more accounts and each account may be enrolled with the enrolment server for one or more authorisation servers and / or for one or more nodes. In an advantageous embodiment, the account at the account serv- er is enrolled with the enrolment server for more than one node. Hence, when several nodes, e.g., vehicles of a specific manufacturer and / or type, share a common account, the account is charged for all authorisation tickets issued by the authori- sation server to all nodes sharing this account. By such an ac- cumulation of charges privacy is further enhanced. In an alter- native embodiment, however, the account at the account server is enrolled with the enrolment server for a single node such that each node, i.e., its account, is charged separately from other nodes, i.e., accounts. Even in this case, neither the en- rolment server nor the authorisation server has sufficient in- formation to determine which authorisation ticket has been is- sued to which requesting node due to the accumulating counter used in the charging period such that privacy is improved. For plausibility checking and / or dispute resolution, it is particularly favourable when step c) further comprises storing the received validation message in a database of the authorisa- tion server. The authorisation server can then check the coun- ter values received from the enrolment server for all accounts against the total number of authorisation tickets issued to all requesting nodes during the charging period and, if there is a discrepancy, a dispute resolution can be initiated. In an advantageous embodiment, the message containing the counter value and the identifier for the account is digitally signed by the enrolment server prior to sending. Thereby, the authenticity of the message is ensured such that manipulation is avoided and discrepancies or disputes can be settled on a certified basis. It shall be noted, though, that an even more extensive security architecture, e.g., according to the stand- ard ETSI TS 102 940, may be employed with support of a public key infrastructure (PKI) using changing pseudonym certificates that may be issued by, e.g., a root certificate authority which approves both the authorisation server and the enrolment serv- er. Moreover, the communication in the ITS may generally be en- crypted and each participant, i.e., each of the nodes, the en- rolment server, the authorisation server and the account serv- er, may be capable of generating cryptographic keys and / or key pairs to share with one another. CA The invention shall now be explained in more detail below on the basis of exemplary embodiments thereof with reference to the accompanying drawings, in which: Fig. 1 shows a cooperative intelligent transportation sys- tem in a schematic block diagram; and Fig. 2 shows the inventive method for issuing pseudonymous authorisation tickets to nodes of the cooperative intelligent transport system of Fig. 1 in a sequence diagram. Fig. 1 shows an example of a cooperative intelligent transportation system ("ITS") 1, e.g., an ITS 1 according to the European Strategy on Cooperative Intelligent Transport Sys- tems ("C-ITS"). Within the ITS 1, the method shown in Fig. 2 is performed. The ITS 1 comprises a plurality of nodes <semantics>N1<annotation encoding="application / x-tex">N_1< / annotation>< / semantics>, <semantics>N2<annotation encoding="application / x-tex">N_2< / annotation>< / semantics>, ..., generally <semantics>Ni<annotation encoding="application / x-tex">N_{i}< / annotation>< / semantics>, that exchange messages <semantics>M1<annotation encoding="application / x-tex">M_{1}< / annotation>< / semantics>, <semantics>M2<annotation encoding="application / x-tex">M_{2}< / annotation>< / semantics>, ..., generally <semantics>Mk<annotation encoding="application / x-tex">M_{k}< / annotation>< / semantics>. Each node Ni is, e.g., a vehicle or an infrastructure device such that the exchange of messages <semantics>Mk<annotation encoding="application / x-tex">M_k< / annotation>< / semantics> allows road users and traffic managers of the ITS 1 to share information, e.g., by vehicle-to-vehicle ("V2V") and / or by vehicle-to-infrastructure ("V2I") communication. As will be explained in greater detail below in the con- text of Fig. 2, the ITS 1 comprises at least one enrolment server (also: "enrolment authority") EA and at least one au- thorisation server (also: "authorisation authority") AA. The ITS 1 optionally further comprises at least one root certifi- cate authority RCA which approves (arrows 2 and 3, respective- ly) both the authorisation server AA and the enrolment server EA, and an optional trust list manager TLM for enabling (arrow 4) the root certificate authority RCA. Moreover, the ITS 1 com- prises at least one of one or more operators / manufacturers OM and one or more account servers AS, wherein each account server AS keeps one or more accounts <semantics>AC1<annotation encoding="application / x-tex">AC_1< / annotation>< / semantics>, <semantics>AC2<annotation encoding="application / x-tex">AC_2< / annotation>< / semantics>, ..., generally <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics>, each for one or more nodes Ni and, when the ITS 1 comprises more than one authorisation server AA, for one or more authorisation servers AA. For communication between the enrolment server EA, the authorisation server AA, the operator / manufacturer OM, the account server AS, and the nodes Ni, the ITS 1 has communica- tion links L, e.g., wire-bound and / or wireless communication links L. Each communication link L may either be direct or via intermediate nodes Ni. Each message <semantics>Mk<annotation encoding="application / x-tex">M_k< / annotation>< / semantics> exchanged in the ITS 1 shall be authenti- cated for controllability and for preventing manipulation. At the same time, privacy of the nodes Ni shall be kept. For achieving both, each message <semantics>Mk<annotation encoding="application / x-tex">M_k< / annotation>< / semantics> is signed with a pseudonymous authorisation ticket <semantics>AT1<annotation encoding="application / x-tex">AT_1< / annotation>< / semantics>, <semantics>AT2<annotation encoding="application / x-tex">AT_2< / annotation>< / semantics>, ..., generally <semantics>ATn<annotation encoding="application / x-tex">AT_n< / annotation>< / semantics> (Fig. 2). The method of issuing these authorisation tickets ATn shall now be explained in detail with reference to Fig. 2. Each node Ni is identified in the enrolment server EA by means of enrolment credentials EC which are suitable to unam- biguously identify the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics>. In the example shown in Fig. 2, in a first step 5 of the method the operator / manufacturer OM registers information on each node Ni - including the enrolment credentials EC thereof - with the enrolment server EA as known from, e.g., C-ITS. In another embodiment, the enrolment creden- tials EC may be generated by the node Ni itself or provided to CA the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics>, e.g., by the operator / manufacturer OM, and are then shared with the enrolment server EA. In step 6, the account server AS registers the respective account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> for each node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> and, in case of more than one au- thorisation server AA, for at least one authorisation server AA with the enrolment server EA. In an optional embodiment when the account server AS is run by the operator / manufacturer OM such that it is integrated therein, steps 5 and 6 may be merged. Again, the account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> for a node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> may alternatively be shared with the enrolment server EA by the node Ni itself, e.g., after having been provided therewith by the account serv- er AS. In an alternative embodiment, the account server AS is run by the enrolment server EA such that it is integrated therein; in this case, step 6 may not be required, e.g., when the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> itself registers its respective account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> with the enrolment server EA, for example, during enrolment as de- scribed below. In step 7, the account server AS registers with the au- thorisation server AA. This registration may be notified to the enrolment server EA in step 8 either upon registration or upon a later request by the enrolment server EA. In another embodi- ment this registration with the authorisation server AA and / or the notification thereof to the enrolment server EA may be a precondition for approving the account server AS in the ITS 1 such that steps 7 and / or 8 are unnecessary. After registration, the node <semantics>N1<annotation encoding="application / x-tex">N_1< / annotation>< / semantics> sends an enrolment request (step 9) to the enrolment server EA. When the node <semantics>N1<annotation encoding="application / x-tex">N_1< / annotation>< / semantics> is iden- CA tified based on said registered information the enrolment serv- er EA sends back the enrolment credentials EC, and the respec- tive account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> at the account server <semantics>AS<annotation encoding="application / x-tex">AS< / annotation>< / semantics> is enrolled for the node <semantics>Ni<annotation encoding="application / x-tex">N_{i}< / annotation>< / semantics> (step 10). The enrolment credentials EC of each node <semantics>Ni<annotation encoding="application / x-tex">N_{i}< / annotation>< / semantics> may be changed occasionally or regularly. For having an authorisation ticket ATn issued after enrol- ment, the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> sends a ticket request TR to the authorisa- tion server AA in step 11. The ticket request TR contains the enrolment credentials EC of the requesting node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics>, i.e., of the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> which sends the ticket request TR. The enrolment credentials EC of the requesting node Ni are encrypted by the requesting node Ni with a public key Kpu of the enrolment server EA. The public key Kpu is part of an asymmetric encryption scheme as known in the art; therein, data encrypted with said public key Kpu can only be decrypted with a respective private key <semantics>Kpr<annotation encoding="application / x-tex">K_{pr}< / annotation>< / semantics> of the enrolment server EA, which private key <semantics>Kpr<annotation encoding="application / x-tex">K_{pr}< / annotation>< / semantics> - being "private" - is only known to the enrolment server EA. Hence, the authorisation server AA has no access to the en- crypted enrolment credentials EC and, particularly, cannot de- rive any information on the identity of the requesting node Ni therefrom. After receiving a ticket request TR, the authorisation server AA generates, in step 12, a validation request VR which contains the encoded enrolment credentials EC of the requesting node Ni. In some embodiments, the validation request VR con- tains further parts of the ticket request TR or even the com- plete ticket request TR of the requesting node Ni. In step 12, CA the authorisation server AA also sends the generated validation request VR to the enrolment server EA for validation. Upon re- ception of said validation request VR, the enrolment server EA conducts a validity check 13. The validity check 13 comprises at least the following criteria of validity that are checked independently from each other, i.e., in any sequence and / or in parallel. A first crite- rion is checked in step 14 and concerns the enrolment of the requesting node <semantics>Ni<annotation encoding="application / x-tex">N_{i}< / annotation>< / semantics> such that the first criterion is only satis- fied when the requesting node Ni identified by the decrypted enrolment credentials EC is enrolled with the enrolment server EA; otherwise, the validity check 13 is not passed. A second criterion is checked in step 15. The second criterion is only satisfied when the account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> at the account server AS is en- rolled with the enrolment server EA for the identified request- ing node Ni. Further criteria may be checked in the validity check 13, e.g., that the account server AS is registered with the authorisation server AA when this is not a precondition in the ITS 1. Only when all criteria are satisfied, the validity check 13 is passed; otherwise, the validity check 13 is not passed. To each account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> enrolled with the enrolment server <semantics>EA<annotation encoding="application / x-tex">EA< / annotation>< / semantics> a separate counter <semantics>CT1<annotation encoding="application / x-tex">CT_1< / annotation>< / semantics>, <semantics>CT2<annotation encoding="application / x-tex">CT_2< / annotation>< / semantics>, ..., generally <semantics>CTm<annotation encoding="application / x-tex">CT_m< / annotation>< / semantics>, is assigned. When the validity check 13 is passed, the enrolment server EA, in step 16', increments a counter value CV of that counter CTm in the enrolment server EA which is assigned to the account ACm enrolled with the enrolment server EA for the requesting node ( Ni. Moreover, the enrolment server EA validates the validation request VR, e.g., by sending a validation message VM to the au- thorisation server AA in step 16" in reply to the validation request VR, when the validity check 13 has been passed. When, on the other hand, the validity check 13 has not been passed, the enrolment server EA does not increment the counter <semantics>CTm<annotation encoding="application / x-tex">CT_m< / annotation>< / semantics> and does not validate the validation request VR, e.g., by not send- ing a message to the authorisation server AA in reply to the validation request VR (implicitly), or by sending a message that is different from the validation message VM to the author- isation server AA in reply to the validation request VR (ex- plicitly). When the authorisation server AA receives the validation message VM in reply to the validation request VR, i.e., when the validation request VR was validated by the enrolment server EA, the authorisation server AA generates and issues a pseudon- ymous authorisation ticket <semantics>ATn<annotation encoding="application / x-tex">AT_n< / annotation>< / semantics> to the requesting node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> in step 17. In an optional step 18, the authorisation server AA stores the received validation message VM in a database 19 thereof for later plausibility check and / or dispute resolution. It shall be noted that the requesting node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> identifies itself vis-à-vis the authorisation server AA for addressabil- ity, e.g., by means of a one-time identifier or the like as known in the art, such that the true identity of the node <semantics>Ni<annotation encoding="application / x-tex">N_{i}< / annotation>< / semantics> remains undisclosed to the authorisation server AA. After having received the issued authorisation ticket ATn from the authorisation server AA, the requesting node Ni can CA use the authorisation ticket ATn once or several times to sign and thereby pseudo-anonymise messages <semantics>M1<annotation encoding="application / x-tex">M_1< / annotation>< / semantics>, <semantics>M2<annotation encoding="application / x-tex">M_2< / annotation>< / semantics>, ..., <semantics>Mk<annotation encoding="application / x-tex">M_k< / annotation>< / semantics> that the node <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics> sends to other nodes <semantics>Ni+1<annotation encoding="application / x-tex">N_{i+1}< / annotation>< / semantics>, <semantics>Ni+2<annotation encoding="application / x-tex">N_{i+2}< / annotation>< / semantics>, ..., see steps 20 to 22. Until a predetermined charging period CP expires, said sending and receiving ticket requests TR, validation requests VR and validation messages VM and said issuing authorisation tickets <semantics>ATn<annotation encoding="application / x-tex">AT_n< / annotation>< / semantics> is repeated (arrow 23). Upon expiry of the charging period CP, the enrolment server EA sends a message ME to the authorisation server AA (step 24), which message ME contains the counter value CV of the counter <semantics>CTm<annotation encoding="application / x-tex">CT_m< / annotation>< / semantics> assigned to said ac- count ACm and an identifier IAC of the account ACm at the ac- count server AS. It is understood that, when the ITS 1 has more that one account server AS, the account server AS which keeps said account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> is also indicated by the identifier <semantics>IAC<annotation encoding="application / x-tex">I_{AC}< / annotation>< / semantics>. As the ITS 1 comprises a multiplicity of nodes <semantics>Ni<annotation encoding="application / x-tex">N_i< / annotation>< / semantics>, said message ME contains, in one embodiment, the counter values CV of some or all counters <semantics>CTm<annotation encoding="application / x-tex">CT_m< / annotation>< / semantics> respectively assigned to the ac- counts ACm of some or all requesting nodes Ni, and the respec- tive identifier <semantics>IAC<annotation encoding="application / x-tex">I_{AC}< / annotation>< / semantics>; in an alternative embodiment, the enrol- ment server EA sends a separate message ME for each counter value CV and account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> which the respective counter <semantics>CTm<annotation encoding="application / x-tex">CT_m< / annotation>< / semantics> is assigned to. Optionally, the message ME is digitally signed by the enrolment server EA prior to sending. After sending said message ME, the counter value CV of each counter CTm in the en- rolment server EA is optionally reset for a subsequent charging period CP. CA In step 25, the authorisation server AA calculates, from each received counter value CV, e.g., by means of an agreed multiplier, a respective charging request CR for the account <semantics>ACm<annotation encoding="application / x-tex">AC_m< / annotation>< / semantics> identified by the received identifier <semantics>IAC<annotation encoding="application / x-tex">I_{AC}< / annotation>< / semantics>. Then, the author- isation server AA sends the charging request CR to the account server AS for charging each of said accounts ACm. Thereby, the issuing of authorisation tickets ATn is charged. It shall be noted that the communication between nodes Ni, the authorisation server AA, the enrolment server EA, the oper- ator / manufacturer OM and / or the account server AS is optionally encrypted by further keys of a symmetric or an asymmetric en- cryption scheme as known in the art. Thus, the disclosed sub- ject-matter is not restricted to the specific embodiments de- scribed in detail herein, but encompasses all variants, combi- nations and modifications thereof that fall within the frame- work of the appended claims. . CA

Claims

<pat:ClaimStatement>Claims:< / pat:ClaimStatement> <pat:Claims com:id="claims"> <pat:Claim com:id="CLM-00001"> <pat:ClaimNumber>1< / pat:ClaimNumber> <pat:ClaimText>1. A method for issuing pseudonymous authorisation tickets to nodes of a cooperative intelligent transport system, ITS, the nodes exchange messages, each of which is signed with one of said pseudonymous authorisation tickets, the method comprising: a) receiving a ticket request from a node in an authoriza- tion server of the ITS, the ticket request contains enrolment credentials of the requesting node, wherein the enrolment cre- dentials are encrypted with a public key of an enrolment server of the ITS, and sending a validation request containing the requesting node's enrolment credentials to the enrolment server; b) decrypting the enrolment credentials contained in the validation request with a respective private key in the enrolment server, conducting a validity check which is only passed when both the requesting node identified by the decrypted enrolment credentials and, for the requesting node, an account at an ac- count server are enrolled with the enrolment server, and, in case the validity check is passed, incrementing a counter value of a counter assigned to said account and sending a validation message to the authorisation server; c) issuing, when the validation message is received in the authorisation server, one of the pseudonymous authorisation tickets to the requesting node; d) repeating steps a) to c) until a predetermined charging period expires, and, upon expiry, sending, from the enrolment server to the authorization server, a message containing said counter value and an identifier for said account, calculating, from the counter value received in the author- isation server, a charging request for the account identified by the received identifier, and sending the charging request to the account server for charging said account. < / pat:ClaimText> < / pat:Claim> <pat:Claim com:id="CLM-00002"> <pat:ClaimNumber>2< / pat:ClaimNumber> <pat:ClaimText>2. The method according to claim 1, wherein the account at the account server is enrolled with the enrolment server for more than one node. < / pat:ClaimText> < / pat:Claim> <pat:Claim com:id="CLM-00003"> <pat:ClaimNumber>3< / pat:ClaimNumber> <pat:ClaimText>3. The method according to claim 1, wherein the account at the account server is enrolled with the enrolment server for a single node. < / pat:ClaimText> < / pat:Claim> <pat:Claim com:id="CLM-00004"> <pat:ClaimNumber>4< / pat:ClaimNumber> <pat:ClaimText>4. The method according to any one of the claims 1 to 3, wherein step c) further comprises storing the received valida- tion message in a database of the authorisation server. < / pat:ClaimText> < / pat:Claim> <pat:Claim com:id="CLM-00005"> <pat:ClaimNumber>5< / pat:ClaimNumber> <pat:ClaimText>5. The method according to any one of the claims 1 to 4, wherein the message containing the counter value and the iden- tifier for the account is digitally signed by the enrolment server prior to sending. < / pat:ClaimText> < / pat:Claim> < / pat:Claims>