US2021135878A1PendingUtilityA1

Authentication Mechanism for 5G Technologies

Assignee: FUTUREWEI TECHNOLOGIES INCPriority: Mar 10, 2016Filed: Jan 11, 2021Published: May 6, 2021
Est. expiryMar 10, 2036(~9.6 yrs left)· nominal 20-yr term from priority
H04W 12/10H04W 12/72H04W 12/106H04W 12/03H04W 12/02H04L 2209/80H04L 63/045H04L 63/0428H04L 9/3273H04L 9/3247H04L 9/3242H04L 9/30H04L 9/14H04L 9/0861H04W 12/06
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIAR ENC ) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIAS ENC ) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIAR INT ) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIAS INT ) to verify the integrity of information in an IAS message. The KIAR ENC , KIAR INT , KIAS ENC , and/or KIAS INT may be independently computed by the UE and a home subscriber server (HSS).

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for secure authentication, the method comprising:
 receiving, by a home subscriber server (HSS) in a home network, an authentication and data request message from a mobility management entity (MME) in a serving network, the authentication and data request message including an encrypted portion, a first random number, and a first International Mobile Subscriber Identity (IMSI) associated with a user equipment (UE);   obtaining, by the HSS, a first encryption key based on the first IMSI and the first random number;   decrypting, by the HSS, the encrypted portion using the first encryption key to obtain a second random number;   obtaining, by the HSS, a second encryption key based on the first IMSI and the second random number; and   sending, by the HSS, an authentication and data response message to the MME, the authentication and data response message including the second encryption key.   
     
     
         2 . The method of  claim 1 , further comprising generating, by the HSS, at least one authentication vector, wherein the authentication and data response message further includes the at least one authentication vector. 
     
     
         3 . The method of  claim 1 , further comprising verifying an integrity of the authentication and data request message. 
     
     
         4 . The method of  claim 3 , wherein decrypting the encrypted portion further obtains at least one of a second IMSI or a third random number. 
     
     
         5 . The method of  claim 4 , wherein verifying the integrity of the authentication and data request message comprises at least one of comparing the second IMSI to the first IMSI or comparing the third random number to the first random number. 
     
     
         6 . The method of  claim 1 , wherein the encrypted portion is an encrypted inner portion. 
     
     
         7 . The method of  claim 1 , wherein the second random number is generated by the UE. 
     
     
         8 . The method of  claim 1 , wherein the second random number is generated by the HSS. 
     
     
         9 . The method of  claim 1 , wherein the second encryption key is generated by the HSS. 
     
     
         10 . The method of  claim 1 , further comprising receiving at least one of the first encryption key or the second encryption key from an authentication server. 
     
     
         11 . A home subscriber server (HSS) in a home network, the HSS comprising:
 a processor; and   a non-transitory computer readable storage medium storing programming for execution by the processor, the programming including instructions to:
 receive an authentication and data request message from a mobility management entity (MME) in a serving network, the authentication and data request message including an encrypted portion, a first random number, and a first International Mobile Subscriber Identity (IMSI) associated with a user equipment (UE); 
 obtain a first encryption key based on the first IMSI and the first random number; 
 decrypt the encrypted portion using the first encryption key to obtain a second random number; 
 obtain a second encryption key based on the first IMSI and the second random number; and 
 send an authentication and data response message to the MME, the authentication and data response message including the second encryption key. 
   
     
     
         12 . The HSS of  claim 11 , the instructions further to generate at least one authentication vector, wherein the authentication and data response message further includes the at least one authentication vector. 
     
     
         13 . The HSS of  claim 11 , the instructions further to verify an integrity of the authentication and data request message. 
     
     
         14 . The HSS of  claim 13 , wherein decrypting the encrypted portion further obtains at least one of a second IMSI or a third random number. 
     
     
         15 . The HSS of  claim 14 , wherein the instructions to verify the integrity of the authentication and data request message comprises instructions to at least one of compare the second IMSI to the first IMSI or compare the third random number to the first random number. 
     
     
         16 . The HSS of  claim 11 , wherein the encrypted portion is an encrypted inner portion. 
     
     
         17 . The HSS of  claim 11 , wherein the second random number is generated by the UE. 
     
     
         18 . The HSS of  claim 11 , wherein the second random number is generated by the UE. 
     
     
         19 . The HSS of  claim 11 , wherein the second encryption key is generated by the HSS. 
     
     
         20 . The HSS of  claim 11 , the instructions further to receive at least one of the first encryption key or the second encryption key from an authentication server.

Join the waitlist — get patent alerts

Track US2021135878A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.