JP6235761B2 - サービングネットワーク認証 - Google Patents
サービングネットワーク認証 Download PDFInfo
- Publication number
- JP6235761B2 JP6235761B2 JP2017515949A JP2017515949A JP6235761B2 JP 6235761 B2 JP6235761 B2 JP 6235761B2 JP 2017515949 A JP2017515949 A JP 2017515949A JP 2017515949 A JP2017515949 A JP 2017515949A JP 6235761 B2 JP6235761 B2 JP 6235761B2
- Authority
- JP
- Japan
- Prior art keywords
- network
- node
- serving network
- authentication
- encrypted
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0822—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0433—Key management protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/047—Key management, e.g. using generic bootstrapping architecture [GBA] without using a trusted network node as an anchor
- H04W12/0471—Key exchange
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/24—Key scheduling, i.e. generating round keys or sub-keys for block encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/062—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying encryption of the keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0892—Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Description
本出願は、2014年9月26日に米国特許商標庁に出願された仮特許出願第62/056,371号、および2015年3月31日に米国特許商標庁に出願された非仮特許出願第14/674,763号の優先権および利益を主張するものであり、その内容全体は、参照により本明細書に組み込まれる。
LTEネットワークにおける無線リンクセットアップでは、ネットワークへのアクセスを可能にするアクセスノードと通信デバイスとの間に1つまたは複数の無線ベアラが確立される場合がある。無線リンクセットアップは一般に、セキュリティアクティブ化交換を含む。その場合、論理ベアラである場合もあるいは論理チャネルである場合もあるセッションベラが、無線リンクを介して確立されてもよく、セッションベアラを介して1つまたは複数のサービスおよび/または通信が確立されてもよい。セッションベアラ、サービス、および/または通信は、1つまたは複数のセキュリティ鍵によってセキュアにされてもよい。
図5は、通常のLTEネットワーク内に実装される場合がある典型的なE-UTRAN鍵階層500を示す図である。通信デバイスでは、ネットワーク側におけるネットワークエンティティ内のユニバーサル加入者識別モジュール(USIM)および認証センター(AuC)がマスター鍵(K)502を使用して暗号鍵(CK)504および完全性鍵(IK)506を生成する。暗号解読鍵(CK)504および完全性鍵(IK)506は次いで、アクセスセキュリティ管理エンティティ鍵(KASME)508を生成するためにネットワークエンティティ内の通信デバイスおよびホーム加入者サーバ(HSS)によって使用されてもよい。LTEネットワーク内で動作する通信デバイスのセキュリティアクティブ化は、認証および鍵一致手順(AKA)、非アクセス層(NAS)セキュリティモード構成(NAS SMC)およびアクセス層(AS)セキュリティモード構成(AS SMC)によって遂行されてもよい。AKAは、KASME 508を導出するのに使われ、この鍵は次いで、NAS鍵510および512ならびにAS鍵514、516、518、および520の算出のためのベース鍵として使われる。ネットワーク側にある通信デバイスおよびMMEは、次いで、KASME 508を使用して、これらのセキュリティ鍵の1つまたは複数を生成してもよい。
図7は、LTEワイヤレスネットワークにおける認証の一例を示すメッセージ流れ図700である。UE 702は、ネットワーク事業者によって実施されるホームネットワーク706からサービスを取得するためにサービングネットワーク704を通してネットワークに接続する場合がある。ベアラセットアップの間、UE 702は、ホームネットワーク706のHSS 712とセキュアな接続を確立してもよい。UE 702は、HSS 712を信頼してもよく、一方、サービングネットワーク704のeNodeB 708は信頼されない場合がある。UE 702は、NAS接続要求720を国際モバイル加入者識別情報(IMSI)などの識別情報とともに送信してもよい。MME 710は、NAS接続要求720を受信し、要求720を認証情報要求メッセージ722においてHSS 712に転送する。認証情報要求メッセージ722は、UE 702のIMSIとサービングネットワーク識別子(SN_id)とを含んでもよい。HSS 712は、認証値(AUTN)と、期待結果値(XRES)と、乱数と、KASMEとを含む認証情報応答メッセージ724によって応答してもよい。AUTNは、AuCによって生成され、RANDとともに、HSS 712をUE 702に対して認証する。MME 710とHSS 712との間のメッセージ722、724は、リンク740上で伝達され、認証、許可、およびアカウンティングプロトコル(ダイアメータ)によって保護される。
4G、5G、およびその他のネットワーキング技術が開発されたことに起因して、いくつかのネットワーク機能がネットワークエッジに押しやられる場合がある。たとえば、MMEに関連するネットワーク機能は、小型セルにおいてeNodeBのネットワーク機能とコロケートされてもよい。いくつかの例では、1つまたは複数のネットワーク機能の再配置によって、セルラーコアネットワークに対する信頼が低下するかまたは無効になることがある。
本明細書において開示するいくつかの態様によれば、引き続き図8を参照するとわかるように、なりすまし攻撃は、HSS 818のみを信頼できるエンティティとして扱うことによって回避される場合がある。UE 802は、証明情報(すなわち、AV)を暗号化するのに使用することのできる鍵をHSS 818に供給してもよい。HSS 818は、供給される鍵を使用してUE 802に関する証明情報を暗号化してもよい。HSS 818は、対象とするMME 810のみが鍵を解読できるように鍵を暗号化してもよい。対象とするMME 810は、ネットワーク機能動作を介してHSS 818によって識別されならびに/あるいは登録されてもよい。MME 810は、鍵を解読し、次いでUE 802に関する信用情報を解読してもよい。したがって、MME 810は、UE 802に対して鍵の知識を証明してもよい。このようにして、UE 802は、ダイアメータプロトコルなどのさらなるセキュリティプロトコルに依存せずにサービングネットワーク804を直接的にかつ明示的に認証してもよい。
102 ユーザ機器
106 eNodeB
108 他のeNodeB
110 EPC
112 MME、モビリティ管理エンティティ(MME)
114 他のMME
116 サービングゲートウェイ
118 PDNゲートウェイ
122 事業者のIPアドレス
200 アクセスネットワーク
202 セル
204 eNodeB
206 UE
208 低電力クラスeNodeB
306 物理レイヤ
308 L2レイヤ
310 メディアアクセス制御(MAC)サブレイヤ
312 RLCサブレイヤ
314 PDCPサブレイヤ
316 RRCサブレイヤ
410 eNodeB
416 TXプロセッサ
420 アンテナ
452 アンテナ
456 RXプロセッサ
458 チャネル推定器
459 コントローラ/プロセッサ
460 メモリ
462 データシンク
467 データソース
468 TXプロセッサ
470 RXプロセッサ
474 チャネル推定器
475 コントローラ/プロセッサ
476 メモリ
500 E-UTRAN鍵階層
508 KASME
510 NASセキュリティキーKNAS-enc
516 セキュリティキーKUP-enc
518 キーKRRC-enc
600 プロトコルスタック
602 ASレイヤ
604 物理(PHY)レイヤ
606 メディアアクセス制御(MAC)レイヤ
608 無線リンク制御(RLC)レイヤ
610 論理チャネル
611 パケットデータコンバージェンスプロトコル(PDCP)レイヤ
612 無線リソース制御(RRC)レイヤ
613 セッション/無線ベアラ
614 非アクセス層(NAS)レイヤ
616 アプリケーション(APP)レイヤ
704 サービングネットワーク
706 ホームネットワーク
708 eNodeB
710 MME
712 HSS
720 NAS接続要求
722 認証情報要求メッセージ
724 認証情報応答メッセージ
726 NAS認証要求
728 NAS認証応答メッセージ
730 NAS SMC(機密性および完全性アルゴリズム)
732 NASセキュリティモード完了
734 S1AP初期コンテキストセットアップ
736 RRC SMC(機密性および完全性アルゴリズム)
738 RRCセキュリティモード完了
740 リンク
802 UE
804 サービングネットワーク
806 ホームネットワーク
808 eNodeB
810 MME
816 通信チャネル
818 HSS
820 攻撃者
824 認証ベクトル(AV)
906 不正なパブリックランドモバイルネットワーク(PLMN)
908 正規のPLMN
910 正規のPLMN
916 通信リンク
918 通信チャネル
920 通信チャネル
922 鍵情報
1002 NAS接続要求
1004 認証情報要求
1006 認証情報応答
1008 NAS認証要求
1010 NAS認証応答メッセージ
1012 セキュリティモードコマンドメッセージ
1014 NASセキュリティモード完了メッセージ
1016 S1AP初期コンテキストセットアップメッセージ
1018 RRC SMCメッセージ
1020 RRCセキュリティモード完了メッセージ
1102 処理ユニット
1104 プロセッサ
1106 ストレージ
1108 バスインターフェース
1110 バス
1112 トランシーバ
1114 ランタイムイメージ
1116 ソフトウェアモジュール
1118 ユーザインターフェース
1120 時分割プログラム
1300 装置、ワイヤレス通信用の装置
1302 処理回路
1304 モジュールおよび/または回路、ホームネットワークとの接続を確立するように構成されたモジュール/回路
1306 モジュールおよび/または回路、サービングネットワークとの通信において使用される暗号化および解読に対処するように構成されたモジュール/回路
1308 モジュールおよび/または回路、メッセージを送信しかつメッセージを受信するように構成されたモジュール/回路
1312 ワイヤレストランシーバ回路
1314 アンテナ
1316 プロセッサ
1318 コンピュータ可読記憶媒体
1320 バス
1500 装置、ワイヤレス通信用の装置
1502 処理回路
1504 モジュールおよび/または回路、1つまたは複数のUEとの接続を確立するように構成されたモジュール/回路
1506 モジュールおよび/または回路、暗号化プロセスおよび解読プロセスの管理または対処を行うように構成されたモジュール/回路
1508 モジュールおよび/または回路、UEとの間でメッセージを送信しかつメッセージを受信するように構成されたモジュール/回路
1510 モジュールおよび/または回路、HSSとの間でメッセージを送信しかつメッセージを受信するように構成されたモジュール/回路
1512 ワイヤレストランシーバ回路
1514 アンテナ
1516 プロセッサ
1518 コンピュータ可読記憶媒体
1520 バス
1700 ワイヤレス通信用の装置
1702 処理回路
1704 ネットワーク機能に関連する暗号化鍵を管理するように構成されたモジュール/回路
1706 ホームネットワーク内で送信されるとともにホームネットワークとサービングネットワークとの間で送信されるメッセージに関する暗号化および解読を管理または実行するように構成されたモジュール/回路
1708 サービングネットワークとの間でメッセージを送信しかつメッセージを受信するように構成されたモジュール/回路
1712 ワイヤレストランシーバ
1714 アンテナ
1716 プロセッサ
1718 コンピュータ可読記憶媒体
1720 バス
Claims (30)
- ユーザ機器(UE)におけるワイヤレス通信のための方法であって、
前記UEによってサービングネットワークとのワイヤレス接続を確立するステップと、
前記UEによって、ランダムに選択された鍵暗号化鍵(KEK)およびサービングネットワーク識別子を含む認証証明情報を含む第1のメッセージを前記サービングネットワークに送信するステップであって、前記認証証明情報は、ホームネットワークに関連する暗号化鍵を使用して前記UEによって暗号化される、ステップと、
前記UEによって前記第1のメッセージに応答した第2のメッセージを受信するステップであって、前記第2のメッセージは、前記サービングネットワークからの認証要求と前記KEKを使用して前記サービングネットワークのノードによって生成されるシグネチャとを含む、ステップと、
前記UEによって前記シグネチャに基づいて前記サービングネットワークを認証するステップとを含む方法。 - 前記サービングネットワークを認証する前記ステップは、
前記シグネチャが前記KEKのコピーを使用して生成されたときに前記サービングネットワークを認証するステップであって、前記シグネチャは、前記サービングネットワークが前記第1のメッセージに応答して前記サービングネットワークのノードによって開始された前記ホームネットワークとの暗号化されたメッセージの交換が行われる間に前記KEKのコピーを受信したときに前記KEKのコピーを使用して生成される、請求項1に記載の方法。 - 前記シグネチャは、前記サービングネットワークのモビリティ管理エンティティ(MME)によって生成される、請求項1に記載の方法。
- 前記UEと前記ホームネットワークのノードとの間で共有される鍵に基づく対称暗号を使用して前記認証証明情報を暗号化するステップをさらに含む、請求項1に記載の方法。
- 前記ホームネットワークの前記ノードは、ホーム加入者サーバ(HSS)を備える、請求項4に記載の方法。
- 前記ホームネットワークの前記ノードは、認証、許可、およびアカウンティング(AAA)サーバを備える、請求項4に記載の方法。
- 前記ホームネットワークのノードの公開鍵に基づく非対称暗号を使用して前記認証証明情報を暗号化するステップをさらに含む、請求項1に記載の方法。
- 前記サービングネットワークとの前記接続を確立する前記ステップは、
前記ホームネットワークのホーム加入者サーバ(HSS)とのセキュアな接続を確立するステップを含む、請求項7に記載の方法。 - 前記ホームネットワークの前記ノードは、認証、許可、およびアカウンティング(AAA)サーバを備える、請求項7に記載の方法。
- 前記第2のメッセージは、前記KEKを使用して生成されるメッセージ認証コードを含む、請求項1に記載の方法。
- 前記第2のメッセージは、前記MMEが、HSSに送信された認証情報要求に対する応答を受信した後にMMEによって生成され、前記認証情報要求に対する前記応答は、前記HSSによって前記MMEに送信され、前記MMEの公開鍵を使用して暗号化される、請求項10に記載の方法。
- サービングネットワークにおけるワイヤレス通信のための方法であって、
前記サービングネットワークのノードによって、ユーザ機器(UE)と前記サービングネットワークとの間の接続を確立するために前記UEから第1の要求を受信するステップであって、前記第1の要求は、前記UEの一意の識別子と、前記サービングネットワークの識別子およびランダムに選択された鍵暗号化鍵(KEK)を含む暗号化された情報とを含む、ステップと、
前記サービングネットワークの前記ノードによって、前記UEに関連するホームネットワークに第2の要求を送信するステップと、前記第2の要求は、前記第1の要求において受信される前記暗号化された情報と前記サービングネットワークの前記ノードの公開鍵とを含む、ステップと、
前記サービングネットワークの前記ノードによって、前記ホームネットワークから前記第2の要求に対する応答を受信するステップと、前記第2の要求に対する前記応答は、前記サービングネットワークの前記ノードの公開鍵を使用して暗号化された前記KEKと、前記KEKを使用して暗号化された認証ベクトルとを含む、ステップと、
前記サービングネットワークの前記ノードによって、前記サービングネットワークの前記ノードの前記公開鍵に対応する公開鍵を使用して前記KEKを解読するステップと、
前記サービングネットワークの前記ノードによって、前記KEKを使用して前記認証ベクトルを解読するステップと、
前記サービングネットワークの前記ノードによって、前記UEに第3の要求を送信するステップであって、前記第3の要求は、前記KEKを使用して署名された認証要求を含む、ステップとを含む方法。 - 前記第1の要求において受信される前記暗号化された情報は、前記ホームネットワークの暗号化鍵を使用して前記UEによって暗号化される、請求項12に記載の方法。
- 前記UEから前記第3の要求に対する応答を受信するステップと、
前記第3の要求に対する前記応答を受信した後に前記UEと前記サービングネットワークとの間の接続を確立するステップとをさらに含む、請求項12に記載の方法。 - ユーザ機器(UE)のホームネットワークにおけるワイヤレス通信のための方法であって、
前記ホームネットワークのノードによってサービングネットワークのノードから認証情報要求を受信するステップであって、前記要求は、第1のサービングネットワーク識別子と、前記サービングネットワークの前記ノードの公開鍵と、前記UEによって暗号化された情報とを含み、前記UEによって暗号化された前記情報は、ランダムに選択された鍵暗号化鍵(KEK)および第2のサービングネットワーク識別子を含む、ステップと、
前記ホームネットワークの公開鍵を使用して、前記UEによって暗号化された前記情報から前記第2のサービングネットワーク識別子および前記KEKを解読するステップと、
前記第1のサービングネットワーク識別子が前記第2のサービングネットワーク識別子と一致するときに、暗号化されたKEKと暗号化された認証ベクトルとを含む前記認証情報要求に対する応答を送信するステップとを含む方法。 - 前記サービングネットワークの前記ノードは、モビリティ管理エンティティ(MME)を備える、請求項15に記載の方法。
- 前記UEによって暗号化された前記情報は、前記UEと前記ホームネットワークのノードとの間で共有される鍵に基づく対称暗号を使用して暗号化される、請求項15に記載の方法。
- 前記ホームネットワークの前記ノードは、ホーム加入者サーバ(HSS)を備える、請求項17に記載の方法。
- 前記ホームネットワークの前記ノードは、認証、許可、およびアカウンティング(AAA)サーバを備える、請求項17に記載の方法。
- 前記UEによって暗号化された前記情報は、前記ホームネットワークのノードの公開鍵に基づく非対称暗号を使用して暗号化される、請求項15に記載の方法。
- 前記ホームネットワークの前記ノードは、ホーム加入者サーバ(HSS)を備える、請求項20に記載の方法。
- 前記ホームネットワークの前記ノードは、認証、許可、およびアカウンティング(AAA)サーバを備える、請求項20に記載の方法。
- 前記サービングネットワークの前記ノードの前記公開鍵を使用して前記KEKを暗号化して前記暗号化されたKEKを取得するステップと、
前記KEKを使用して認証ベクトルを暗号化して前記暗号化された認証ベクトルを取得するステップとをさらに含む、請求項15に記載の方法。 - ユーザ機器(UE)とサービングネットワークとの間の接続を確立するための手段と、
前記UEに関連するホームネットワークに第1のメッセージを伝達するための手段であって、前記第1のメッセージは、前記ホームネットワークの暗号化鍵を使用して前記UEによって暗号化された認証証明情報を含む手段と、
前記サービングネットワークのノードによって供給される前記サービングネットワークの第1の識別情報と前記認証証明情報において供給される前記サービングネットワークの第2の識別情報との比較に基づいて前記サービングネットワークを認証するための手段とを備え、
前記ホームネットワークのノードは、前記認証証明情報を解読して前記第2の識別情報および前記UEによって供給された鍵暗号化鍵(KEK)を取得し、かつ前記サービングネットワークの前記ノードの公開鍵を使用して暗号化された前記KEKのバージョンを前記サービングネットワークの前記ノードに供給するように構成され、
前記サービングネットワークを認証するための前記手段は、前記サービングネットワークの前記ノードが前記KEKを使用して署名された認証要求を前記UEに送信した後に前記サービングネットワークを認証するように構成される装置。 - 前記サービングネットワークの前記ノードは、モビリティ管理エンティティ(MME)を備える、請求項24に記載の装置。
- 前記サービングネットワークを認証するための前記手段は、
前記ネットワークが、前記ホームネットワークの前記ノードによって供給された前記KEKの前記バージョンを使用してシグネチャを生成するときに、前記サービングネットワークの前記ノードを認証するように構成される、請求項24に記載の装置。 - 前記認証証明情報は、前記UEと前記ホームネットワークのノードとの間で共有される鍵に基づく対称暗号を使用して暗号化される、請求項24に記載の装置。
- 前記ホームネットワークの前記ノードは、ホーム加入者サーバ(HSS)または認証、許可、およびアカウンティング(AAA)サーバを備える、請求項27に記載の装置。
- 前記認証証明情報は、前記ホームネットワークのノードの公開鍵に基づく非対称暗号を使用して暗号化される、請求項24に記載の装置。
- 前記ホームネットワークの前記ノードは、ホーム加入者サーバ(HSS)または認証、許可、およびアカウンティング(AAA)サーバを備える、請求項29に記載の装置。
Applications Claiming Priority (5)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US201462056371P | 2014-09-26 | 2014-09-26 | |
| US62/056,371 | 2014-09-26 | ||
| US14/674,763 | 2015-03-31 | ||
| US14/674,763 US9491618B2 (en) | 2014-09-26 | 2015-03-31 | Serving network authentication |
| PCT/US2015/047295 WO2016048574A1 (en) | 2014-09-26 | 2015-08-27 | Serving network authentication |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JP2017529799A JP2017529799A (ja) | 2017-10-05 |
| JP6235761B2 true JP6235761B2 (ja) | 2017-11-22 |
Family
ID=54064611
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2017515949A Active JP6235761B2 (ja) | 2014-09-26 | 2015-08-27 | サービングネットワーク認証 |
Country Status (10)
| Country | Link |
|---|---|
| US (1) | US9491618B2 (ja) |
| EP (1) | EP3198906B1 (ja) |
| JP (1) | JP6235761B2 (ja) |
| KR (1) | KR101785249B1 (ja) |
| CN (1) | CN106717044B (ja) |
| AU (1) | AU2015321927B2 (ja) |
| CU (1) | CU24586B1 (ja) |
| PE (1) | PE20170656A1 (ja) |
| TW (1) | TWI695611B (ja) |
| WO (1) | WO2016048574A1 (ja) |
Families Citing this family (35)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9680816B2 (en) * | 2014-10-14 | 2017-06-13 | Cisco Technology, Inc. | Attesting authenticity of infrastructure modules |
| US10581703B2 (en) | 2014-12-24 | 2020-03-03 | Koninklijke Kpn N.V. | Method for controlling on-demand service provisioning |
| US9705752B2 (en) * | 2015-01-29 | 2017-07-11 | Blackrock Financial Management, Inc. | Reliably updating a messaging system |
| US11316934B2 (en) * | 2015-12-28 | 2022-04-26 | Koninklijke Kpn N.V. | Method for providing a service to a user equipment connected to a first operator network via a second operator network |
| US10771453B2 (en) * | 2017-01-04 | 2020-09-08 | Cisco Technology, Inc. | User-to-user information (UUI) carrying security token in pre-call authentication |
| US10433307B2 (en) * | 2017-04-20 | 2019-10-01 | Facebook Technologies, Llc | Diversity based relay for wireless communications between a head-mounted display and a console |
| EP3639542B1 (en) * | 2017-06-16 | 2023-01-04 | Telefonaktiebolaget LM Ericsson (Publ) | Network, network nodes, wireless communication devices and method therein for handling network slices in a wireless communication network |
| ES3015684T3 (en) | 2017-07-25 | 2025-05-07 | Ericsson Telefon Ab L M | Subscription concealed identifier |
| JP7028964B2 (ja) | 2017-10-02 | 2022-03-02 | テレフオンアクチーボラゲット エルエム エリクソン(パブル) | ネットワークステアリング情報のセキュア化 |
| EP3687207B1 (en) * | 2017-10-10 | 2023-12-13 | Ntt Docomo, Inc. | Security establishing method and terminal device |
| CN109688586B (zh) * | 2017-10-19 | 2021-12-07 | 中兴通讯股份有限公司 | 一种网络功能认证的方法、装置及计算机可读存储介质 |
| US10306578B2 (en) * | 2017-10-24 | 2019-05-28 | Verizon Patent And Licensing Inc. | Easy connectivity provisioning for cellular network |
| WO2019088599A1 (ko) * | 2017-10-31 | 2019-05-09 | 엘지전자 주식회사 | 무선 통신 시스템에서 홈 네트워크 키로 암호화된 데이터를 보호하기 위한 방법 및 이를 위한 장치 |
| EP3694245B1 (en) | 2017-11-08 | 2022-09-21 | Guangdong Oppo Mobile Telecommunications Corp., Ltd. | Integrity protection control method, network device and computer storage medium |
| WO2019138051A1 (en) | 2018-01-12 | 2019-07-18 | Telefonaktiebolaget Lm Ericsson (Publ) | Managing identifier privacy |
| KR102348078B1 (ko) * | 2018-01-12 | 2022-01-10 | 삼성전자주식회사 | 사용자 단말 장치, 전자 장치, 이를 포함하는 시스템 및 제어 방법 |
| FR3077175A1 (fr) * | 2018-01-19 | 2019-07-26 | Orange | Technique de determination d'une cle destinee a securiser une communication entre un equipement utilisateur et un serveur applicatif |
| AU2019249939B2 (en) | 2018-04-06 | 2021-09-30 | Telefonaktiebolaget Lm Ericsson (Publ) | UE controlled handling of the security policy for user plane protection in 5G systems |
| TWI717717B (zh) * | 2018-04-10 | 2021-02-01 | 新加坡商 聯發科技(新加坡)私人有限公司 | 行動通訊中錯誤ksi處理的改進方法 |
| WO2019226696A1 (en) * | 2018-05-22 | 2019-11-28 | Futurewei Technologies, Inc. | Access technology agnostic serving network authentication |
| US10499357B1 (en) * | 2018-08-09 | 2019-12-03 | Nec Corporation | Method and system for transmission of SUSI in the NAS procedure |
| WO2020060871A1 (en) * | 2018-09-19 | 2020-03-26 | Intel Corporation | Protection of initial non-access stratum protocol message in 5g systems |
| WO2020099148A1 (en) * | 2018-11-12 | 2020-05-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Authentication of a communications device |
| CN111669276B (zh) * | 2019-03-07 | 2022-04-22 | 华为技术有限公司 | 一种网络验证方法、装置及系统 |
| WO2020254302A1 (en) | 2019-06-17 | 2020-12-24 | Telefonaktiebolaget Lm Ericsson (Publ) | Home controlled network slice privacy |
| US12132732B2 (en) | 2019-06-24 | 2024-10-29 | Nokia Technologies Oy | Dynamic allocation of network slice-specific credentials |
| US11310661B2 (en) * | 2020-02-14 | 2022-04-19 | Mediatek Inc. | Security key synchronization method and associated communications apparatus |
| US11778463B2 (en) | 2020-03-31 | 2023-10-03 | Cisco Technology, Inc. | Techniques to generate wireless local area access network fast transition key material based on authentication to a private wireless wide area access network |
| US11706619B2 (en) * | 2020-03-31 | 2023-07-18 | Cisco Technology, Inc. | Techniques to facilitate fast roaming between a mobile network operator public wireless wide area access network and an enterprise private wireless wide area access network |
| US11012857B1 (en) | 2020-04-13 | 2021-05-18 | Sprint Communications Company L.P. | Fifth generation core (5GC) authentication for long term evolution (LTE) data service |
| CN111614496B (zh) * | 2020-05-13 | 2021-12-21 | 北京紫光展锐通信技术有限公司 | 路由访问方法、装置、电子设备及存储介质 |
| US12520137B2 (en) | 2020-07-31 | 2026-01-06 | Telefonaktiebolaget Lm Ericsson (Publ) | Authentication of a wireless device in a wireless communication network |
| CN114915966A (zh) * | 2021-02-10 | 2022-08-16 | 华为技术有限公司 | 配置演进分组系统非接入层安全算法的方法及相关装置 |
| US20230163974A1 (en) * | 2021-11-19 | 2023-05-25 | Packetfabric, Inc. | Systems and methods for message authentication using efficient signatures and secret sharing |
| US20250365316A1 (en) * | 2024-05-21 | 2025-11-27 | Honeywell International Inc. | Network transaction management |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8347090B2 (en) | 2006-10-16 | 2013-01-01 | Nokia Corporation | Encryption of identifiers in a communication system |
| WO2009006196A2 (en) * | 2007-07-05 | 2009-01-08 | Motorola, Inc. | Method and apparatus for determining capability of a serving system for anchoring a call using an intelligent network protocol |
| US8676251B2 (en) * | 2009-03-04 | 2014-03-18 | Lg Electronics Inc. | Dual modem device |
| CA2760522C (en) * | 2009-05-03 | 2015-07-14 | Kabushiki Kaisha Toshiba | Media independent handover protocol security |
| KR101683883B1 (ko) | 2009-12-31 | 2016-12-08 | 삼성전자주식회사 | 이동 통신 시스템에서 보안을 지원하는 방법 및 시스템 |
| US8296836B2 (en) * | 2010-01-06 | 2012-10-23 | Alcatel Lucent | Secure multi-user identity module key exchange |
| CN102196436B (zh) | 2010-03-11 | 2014-12-17 | 华为技术有限公司 | 安全认证方法、装置及系统 |
| US8839373B2 (en) * | 2010-06-18 | 2014-09-16 | Qualcomm Incorporated | Method and apparatus for relay node management and authorization |
| CN102131188B (zh) | 2010-09-01 | 2013-12-04 | 华为技术有限公司 | 用户身份信息传输的方法、用户设备、网络侧设备及系统 |
| US20120159151A1 (en) * | 2010-12-21 | 2012-06-21 | Tektronix, Inc. | Evolved Packet System Non Access Stratum Deciphering Using Real-Time LTE Monitoring |
| KR20140037276A (ko) * | 2011-03-23 | 2014-03-26 | 인터디지탈 패튼 홀딩스, 인크 | 네트워크 통신 보호 시스템 및 방법 |
| US8699709B2 (en) * | 2011-07-08 | 2014-04-15 | Motorola Solutions, Inc. | Methods for obtaining authentication credentials for attaching a wireless device to a foreign 3GPP wireless domain |
-
2015
- 2015-03-31 US US14/674,763 patent/US9491618B2/en active Active
- 2015-08-26 TW TW104127970A patent/TWI695611B/zh active
- 2015-08-27 CN CN201580051157.XA patent/CN106717044B/zh active Active
- 2015-08-27 EP EP15760028.9A patent/EP3198906B1/en active Active
- 2015-08-27 PE PE2017000494A patent/PE20170656A1/es unknown
- 2015-08-27 JP JP2017515949A patent/JP6235761B2/ja active Active
- 2015-08-27 AU AU2015321927A patent/AU2015321927B2/en not_active Ceased
- 2015-08-27 CU CU2017000033A patent/CU24586B1/es unknown
- 2015-08-27 WO PCT/US2015/047295 patent/WO2016048574A1/en not_active Ceased
- 2015-08-27 KR KR1020177008224A patent/KR101785249B1/ko active Active
Also Published As
| Publication number | Publication date |
|---|---|
| JP2017529799A (ja) | 2017-10-05 |
| CU24586B1 (es) | 2022-04-07 |
| US9491618B2 (en) | 2016-11-08 |
| BR112017006156A2 (pt) | 2018-02-06 |
| WO2016048574A1 (en) | 2016-03-31 |
| EP3198906A1 (en) | 2017-08-02 |
| US20160094988A1 (en) | 2016-03-31 |
| AU2015321927A1 (en) | 2017-03-16 |
| KR20170038096A (ko) | 2017-04-05 |
| PE20170656A1 (es) | 2017-05-17 |
| KR101785249B1 (ko) | 2017-10-12 |
| CN106717044A (zh) | 2017-05-24 |
| CU20170033A7 (es) | 2017-07-04 |
| TWI695611B (zh) | 2020-06-01 |
| TW201626751A (zh) | 2016-07-16 |
| CN106717044B (zh) | 2018-04-20 |
| EP3198906B1 (en) | 2020-07-15 |
| AU2015321927B2 (en) | 2018-11-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10491585B2 (en) | On-demand serving network authentication | |
| KR101785249B1 (ko) | 서빙 네트워크 인증 | |
| US12432559B2 (en) | Methods and apparatus for secure access control in wireless communications | |
| EP3453149B1 (en) | Secure signaling before performing an authentication and key agreement | |
| WO2018053271A1 (en) | Unified authentication framework | |
| EP3915290A1 (en) | Methods providing authentication using a request commit message and related user equipment and network nodes | |
| BR112017006156B1 (pt) | Método e aparelho para autenticação por um equipamento de usuário de uma rede servidora em um sistema de comunicação sem fio, método para comunicação sem fio em uma rede servidora, método para comunicação sem fio em uma rede doméstica de um equipamento de usuário e memória legível por computador |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20170322 |
|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20170322 |
|
| A871 | Explanation of circumstances concerning accelerated examination |
Free format text: JAPANESE INTERMEDIATE CODE: A871 Effective date: 20170322 |
|
| A975 | Report on accelerated examination |
Free format text: JAPANESE INTERMEDIATE CODE: A971005 Effective date: 20170814 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20171002 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20171026 |
|
| R150 | Certificate of patent or registration of utility model |
Ref document number: 6235761 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |