Authentication Mechanism for 5G Technologies
Abstract
Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIAR ENC ) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIAS ENC ) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIAR INT ) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIAS INT ) to verify the integrity of information in an IAS message. The KIAR ENC , KIAR INT , KIAS ENC , and/or KIAS INT may be independently computed by the UE and a home subscriber server (HSS).
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for secure authentication, the method comprising:
receiving, by a home subscriber server (HSS) in a home network, an authentication and data request message from a mobility management entity (MME) in a serving network, the authentication and data request message including an encrypted portion, a first random number, and a first International Mobile Subscriber Identity (IMSI) associated with a user equipment (UE); obtaining, by the HSS, a first encryption key based on the first IMSI and the first random number; decrypting, by the HSS, the encrypted portion using the first encryption key to obtain a second random number; obtaining, by the HSS, a second encryption key based on the first IMSI and the second random number; and sending, by the HSS, an authentication and data response message to the MME, the authentication and data response message including the second encryption key.
2 . The method of claim 1 , further comprising generating, by the HSS, at least one authentication vector, wherein the authentication and data response message further includes the at least one authentication vector.
3 . The method of claim 1 , further comprising verifying an integrity of the authentication and data request message.
4 . The method of claim 3 , wherein decrypting the encrypted portion further obtains at least one of a second IMSI or a third random number.
5 . The method of claim 4 , wherein verifying the integrity of the authentication and data request message comprises at least one of comparing the second IMSI to the first IMSI or comparing the third random number to the first random number.
6 . The method of claim 1 , wherein the encrypted portion is an encrypted inner portion.
7 . The method of claim 1 , wherein the second random number is generated by the UE.
8 . The method of claim 1 , wherein the second random number is generated by the HSS.
9 . The method of claim 1 , wherein the second encryption key is generated by the HSS.
10 . The method of claim 1 , further comprising receiving at least one of the first encryption key or the second encryption key from an authentication server.
11 . A home subscriber server (HSS) in a home network, the HSS comprising:
a processor; and a non-transitory computer readable storage medium storing programming for execution by the processor, the programming including instructions to:
receive an authentication and data request message from a mobility management entity (MME) in a serving network, the authentication and data request message including an encrypted portion, a first random number, and a first International Mobile Subscriber Identity (IMSI) associated with a user equipment (UE);
obtain a first encryption key based on the first IMSI and the first random number;
decrypt the encrypted portion using the first encryption key to obtain a second random number;
obtain a second encryption key based on the first IMSI and the second random number; and
send an authentication and data response message to the MME, the authentication and data response message including the second encryption key.
12 . The HSS of claim 11 , the instructions further to generate at least one authentication vector, wherein the authentication and data response message further includes the at least one authentication vector.
13 . The HSS of claim 11 , the instructions further to verify an integrity of the authentication and data request message.
14 . The HSS of claim 13 , wherein decrypting the encrypted portion further obtains at least one of a second IMSI or a third random number.
15 . The HSS of claim 14 , wherein the instructions to verify the integrity of the authentication and data request message comprises instructions to at least one of compare the second IMSI to the first IMSI or compare the third random number to the first random number.
16 . The HSS of claim 11 , wherein the encrypted portion is an encrypted inner portion.
17 . The HSS of claim 11 , wherein the second random number is generated by the UE.
18 . The HSS of claim 11 , wherein the second random number is generated by the UE.
19 . The HSS of claim 11 , wherein the second encryption key is generated by the HSS.
20 . The HSS of claim 11 , the instructions further to receive at least one of the first encryption key or the second encryption key from an authentication server.Join the waitlist — get patent alerts
Track US2021135878A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.