US2018070230A1PendingUtilityA1

Method and apparatus for connecting a communication device to a deployable network without compromising authentication keys

Assignee: MOTOROLA SOLUTIONS INCPriority: Oct 30, 2014Filed: Nov 8, 2017Published: Mar 8, 2018
Est. expiryOct 30, 2034(~8.3 yrs left)· nominal 20-yr term from priority
H04W 4/90H04L 63/08H04L 9/08H04L 9/0819H04L 9/0838G06F 16/951G06F 17/30864H04W 12/06H04W 12/04H04W 12/041H04W 12/082H04W 12/069
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus is provided for connecting a communication device to a deployable system. The deployable system obtains at least one deployable key derived on a fixed system for the deployable system based on an existing key stored on a database of the fixed system, wherein the existing key is used to authenticate a communication device. The deployable system stores the derived key. Subsequent to the storing, the deployable system is activated to provide communication resources to communication devices disconnected from the fixed system. The activated deployable system is not connected to the fixed system. The activated deployable system receives an authentication request from the communication device requesting connection to the deployable system; generates authentication vectors using the at least one derived deployable key; and authenticates an authentication response received from the communication device using the authentication vectors.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method, comprising:
 storing, on a communication device, subscription information for the communication device and a list of identifiers including a first identifier for a deployable system;   obtaining, by the communication device, a second identifier and determining that the second identifier is the same as the first identifier;   identifying, by the communication device, that a communication link with a fixed system is unavailable;   in response to identifying an unavailable communication link and determining that the second identifier is the same as the first identifier, sending, by the communication device, an attachment request to the deployable system;   receiving, by the communication device, an authentication request from the deployable system;   deriving, by the communication device, a deployable key for the deployable system based on the subscription information; and   computing, by the communication device, an authentication response to the authentication request using the deployable key and authenticating the deployable system using the authentication response.   
     
     
         2 . The method of  claim 1 , wherein the storing comprises storing subscription information for the communication device on a smart card stored in the communication device. 
     
     
         3 . The method of  claim 1 , wherein the deriving comprises deriving a deployable authentication key and a communication device specific operator key with a key derivation function known to a fixed system and the communication device,
 wherein the deployable authentication key is derived by executing the key derivation function on an authentication key stored on the communication device and the second identifier; and   the communication device specific operator key is derived by executing the key derivation function on a concatenation of an operator key of the fixed system and the second identifier.   
     
     
         4 . The method of  claim 1 , wherein the second identifier is one of a unique identifier associated with the deployable system and a global identifier associated with a group of deployable systems. 
     
     
         5 . The method of  claim 1 , further comprising determining that the second identifier is included in a revoked list, wherein an identifier in the revoked list is removed from the list of identifiers. 
     
     
         6 . A communication device, comprising:
 a memory configured to store subscription information for the communication device and a list of identifiers including a first identifier for a deployable system;   a transceiver configured to receive a second identifier;   a processor configured to perform a set of functions comprising:
 determining that the first identifier is the same as the second identifier; 
 identifying that a communication link with a fixed system is unavailable; 
 in response to identifying an unavailable communication link and determining that the first identifier is the same as the second identifier, sending, via the transceiver, an attachment request to the deployable system; 
 in response to the sending, receiving, via the transceiver, an authentication request from the deployable system; 
 deriving a deployable key for the deployable system based on the subscription information and the second identifier; and 
 computing an authentication response to the authentication request using the at least one deployable key and authenticating the deployable system using the authentication response. 
   
     
     
         7 . The communication device of  claim 6 , wherein the communication device is configured to store subscription information for the communication device on a smart card stored in the communication device. 
     
     
         8 . The communication device of  claim 7 , wherein processor is configured to derive the deployable key by deriving a deployable authentication key and a communication device specific operator key with a key derivation function known to a fixed system and the communication device,
 wherein the deployable authentication key is derived by executing the key derivation function on an authentication key stored on the communication device and the second identifier; and   the communication device specific operator key is derived by executing the key derivation function on a concatenation of an operator key of the fixed system and the second identifier.   
     
     
         9 . The communication device of  claim 7 , wherein processor is configured to determine that the second identifier is included in a revoked list, wherein an identifier included in the revoked list is removed from the list of identifiers.

Join the waitlist — get patent alerts

Track US2018070230A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.