User identity privacy protection in public wireless local access network, WLAN, access
US-11212676-B2 · Dec 28, 2021 · US
US11540125B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11540125-B2 |
| Application number | US-201816494524-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 16, 2018 |
| Priority date | Mar 17, 2017 |
| Publication date | Dec 27, 2022 |
| Grant date | Dec 27, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Provided is an authentication device capable of generating a master key suited to a UE in a 5GS. The authentication device ( 10 ) includes a communication unit ( 11 ) configured to, in registration processing of user equipment (UE), acquire UE key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE, a selection unit ( 12 ) configured to select a pseudo random function used for generation of a master key related to the UE by use of the UE KDF capabilities, and a key generation unit ( 13 ) configured to generate a master key related to the UE by use of the selected pseudo random function.
Opening claim text (preview).
The invention claimed is: 1. An authentication device comprising: at least one memory storing instructions, and at least one processor configured to execute the instructions to: receive a registration request message including UE key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE transmitted from the UE; acquire the UE KDF capabilities; select a pseudo random function used for generation of a master key related to the UE by use of the UE KDF capabilities; and generate a master key related to the UE by use of the selected pseudo random function. 2. The authentication device according to claim 1 , wherein the at least one processor is further configured to execute the instructions to generate second authentication information by use of the master key, and send the second authentication information to a network device. 3. The authentication device according to claim 2 , wherein the second authentication information includes a session key used for communication with the UE connected to a non-3rd Generation Partnership Project (3GPP) access network or a 3GPP access network. 4. The authentication device according to claim 1 , wherein the at least one processor is further configured to execute the instructions to generate the master key by use of first authentication information generated in a subscriber information management device and the selected pseudo random function. 5. The authentication device according to claim 4 , wherein the at least one processor is further configured to execute the instructions to send a message requesting the first authentication information, the message being addressed to the subscriber information management device, and receives the first authentication information in response to the message. 6. A network device comprising: at least one memory storing instructions, and at least one processor configured to execute the instructions to: in registration processing of a UE, acquire authentication information generated based on a master key generated by use of a pseudo random function supported by a UE indicated in UE KDF capabilities included in a registration request message transmitted from the UE; store the authentication information; and in re-registration processing of the UE, send the stored authentication information in response to a message requesting authentication information. 7. The network device according to claim 6 , wherein the authentication information includes a session key used for communication with the UE connected to a non-3GPP access network or a 3GPP access network. 8. An authentication method comprising: receiving a registration request message including user equipment (UE) key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE transmitted from the UE; acquiring the UE KDF capabilities; selecting a pseudo random function used for generation of a master key related to the UE by use of the UE KDF capabilities; and generating a master key related to the UE by use of the selected pseudo random function. 9. The authentication device according to claim 1 , wherein the at least one processor is further configured to execute the instructions to: acquire a Subscriber Parameter Identifier (SUPI) in the registration processing of the UE, and generate the master key related to the UE by use of the selected pseudo random function and the SUPI. 10. The authentication device according to claim 5 , wherein the at least one processor is further configured to execute the instructions to: generate second authentication information by use of the master key, and send the second authentication information to a network device.
applying self-generating credentials, e.g. instead of receiving credentials from an authority or from another peer, the credentials are generated at the entity itself · CPC title
Key distribution or pre-distribution; Key agreement · CPC title
Switchboards · CPC title
involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title
Pre-authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.