Method and apparatus for connecting a communication device to a deployable network without compromising authentication keys
Abstract
A method and apparatus is provided for connecting a communication device to a deployable system. The deployable system obtains at least one deployable key derived on a fixed system for the deployable system based on an existing key stored on a database of the fixed system, wherein the existing key is used to authenticate a communication device. The deployable system stores the derived key. Subsequent to the storing, the deployable system is activated to provide communication resources to communication devices disconnected from the fixed system. The activated deployable system is not connected to the fixed system. The activated deployable system receives an authentication request from the communication device requesting connection to the deployable system; generates authentication vectors using the at least one derived deployable key; and authenticates an authentication response received from the communication device using the authentication vectors.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method, comprising:
storing, on a communication device, subscription information for the communication device and a list of identifiers including a first identifier for a deployable system; obtaining, by the communication device, a second identifier and determining that the second identifier is the same as the first identifier; identifying, by the communication device, that a communication link with a fixed system is unavailable; in response to identifying an unavailable communication link and determining that the second identifier is the same as the first identifier, sending, by the communication device, an attachment request to the deployable system; receiving, by the communication device, an authentication request from the deployable system; deriving, by the communication device, a deployable key for the deployable system based on the subscription information; and computing, by the communication device, an authentication response to the authentication request using the deployable key and authenticating the deployable system using the authentication response.
2 . The method of claim 1 , wherein the storing comprises storing subscription information for the communication device on a smart card stored in the communication device.
3 . The method of claim 1 , wherein the deriving comprises deriving a deployable authentication key and a communication device specific operator key with a key derivation function known to a fixed system and the communication device,
wherein the deployable authentication key is derived by executing the key derivation function on an authentication key stored on the communication device and the second identifier; and the communication device specific operator key is derived by executing the key derivation function on a concatenation of an operator key of the fixed system and the second identifier.
4 . The method of claim 1 , wherein the second identifier is one of a unique identifier associated with the deployable system and a global identifier associated with a group of deployable systems.
5 . The method of claim 1 , further comprising determining that the second identifier is included in a revoked list, wherein an identifier in the revoked list is removed from the list of identifiers.
6 . A communication device, comprising:
a memory configured to store subscription information for the communication device and a list of identifiers including a first identifier for a deployable system; a transceiver configured to receive a second identifier; a processor configured to perform a set of functions comprising:
determining that the first identifier is the same as the second identifier;
identifying that a communication link with a fixed system is unavailable;
in response to identifying an unavailable communication link and determining that the first identifier is the same as the second identifier, sending, via the transceiver, an attachment request to the deployable system;
in response to the sending, receiving, via the transceiver, an authentication request from the deployable system;
deriving a deployable key for the deployable system based on the subscription information and the second identifier; and
computing an authentication response to the authentication request using the at least one deployable key and authenticating the deployable system using the authentication response.
7 . The communication device of claim 6 , wherein the communication device is configured to store subscription information for the communication device on a smart card stored in the communication device.
8 . The communication device of claim 7 , wherein processor is configured to derive the deployable key by deriving a deployable authentication key and a communication device specific operator key with a key derivation function known to a fixed system and the communication device,
wherein the deployable authentication key is derived by executing the key derivation function on an authentication key stored on the communication device and the second identifier; and the communication device specific operator key is derived by executing the key derivation function on a concatenation of an operator key of the fixed system and the second identifier.
9 . The communication device of claim 7 , wherein processor is configured to determine that the second identifier is included in a revoked list, wherein an identifier included in the revoked list is removed from the list of identifiers.Join the waitlist — get patent alerts
Track US2018070230A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.