Authentication device, network device, communication system, authentication method, and non-transitory computer readable medium

US11902776B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11902776-B2
Application numberUS-202218078174-A
CountryUS
Kind codeB2
Filing dateDec 9, 2022
Priority dateMar 17, 2017
Publication dateFeb 13, 2024
Grant dateFeb 13, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is an authentication device capable of generating a master key suited to a UE in a 5GS. The authentication device (10) includes a communication unit (11) configured to, in registration processing of user equipment (UE), acquire UE key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE, a selection unit (12) configured to select a pseudo random function used for generation of a master key related to the UE by use of the UE KDF capabilities, and a key generation unit (13) configured to generate a master key related to the UE by use of the selected pseudo random function.

First claim

Opening claim text (preview).

The invention claimed is: 1. A communication system comprising: a non-3GPP access network (AN) connecting to user equipment (UE); a Non-3GPP Inter Working Function (N3IWF) node connecting to the non-3GPP AN; an Access and Mobility Function (AMF) node connecting to the N3IWF node; an Authentication Server Function (AUSF) node connecting to the AMF node via a Security Anchor Function (SEAF); and an Unified Data Management (UDM) node connecting to the AUSF node, wherein the N3IWF node receives a Registration Request message including a Key Set Identifier (KSI) and UE Security Capabilities from the UE via the non-3GPP AN, wherein the N3IWF node forwards the Registration Request message to the AMF node, wherein the AMF node sends, to the AUSF node, information for performing an authentication procedure for the UE, wherein the information is based on the received Registration Request message, wherein the AUSF node receives an Authentication Vector (AV) including an expected response (XRES) from the UDM node, wherein the AUSF node receives a response (RES) from the UE via the SEAF, and wherein the AUSF node authenticates the UE by comparing the RES with the XRES. 2. The communication system according to claim 1 , wherein if authentication is successful, the AUSF node sends a Success message to the UE via the SEAF. 3. The communication system of claim 1 , wherein the RES from the UE is based on the AV. 4. A method for authenticating user equipment (UE) comprising: sending, from the UE to a Non-3GPP Inter Working Function (N3IWF) node via a non-3GPP access network (AN), a Registration Request message including Key Set Identifier (KSI) and UE Security Capabilities; forwarding, from the N3IWF node to an Access and Mobility Function (AMF) node, the Registration Request message; sending, from the AMF node to an Authentication Server Function (AUSF) node, information for performing an authentication procedure for the UE, wherein the information is based on the received Registration Request message; receiving, by the AUSF node from a Unified Data Management (UDM) node, an Authentication Vector (AV) including an expected response (XRES); receiving, by the AUSF node, a response (RES) from the UE via a Security Anchor Function (SEAF); and authenticating, by the AUSF node, the UE by comparing the RES with the XRES. 5. The method according to claim 4 further comprising: if authentication is successful, sending, from the AUSF node to the UE via the SEAF, a Success message. 6. The method of claim 4 , wherein the RES from the UE is based on the AV. 7. A method for an Authentication Server Function (AUSF) node comprising: receiving information for performing an authentication procedure for user equipment (UE) from an Access and Mobility Function (AMF) node that received a Registration Request message sent from the UE via a non-3GPP access network (AN) and a Non-3GPP Inter Working Function (N3IWF) node; receiving an Authentication Vector (AV) including an expected response (XRES) from an Unified Data Management (UDM) node; receiving a response (RES) from the UE via a Security Anchor Function (SEAF); and authenticating the UE by comparing the RES with the XRES, wherein the Registration Request message includes a Key Set Identifier (KSI) and UE Security Capabilities. 8. The method according to claim 7 further comprising: if authentication is successful, sending a Success message to the UE via the SEAF. 9. An Authentication Server Function (AUSF) node comprising: a receiver configured to receive information for performing an authentication procedure for user equipment (UE) from an Access and Mobility Function (AMF) node that received a Registration Request message sent from the UE via a non-3GPP access network (AN) and a Non-3GPP Inter Working Function (N3IWF) node, receive an Authentication Vector (AV) including an expected response (XRES) from an Unified Data Management (UDM) node, and receive a response (RES) from the UE via a Security Anchor Function (SEAF); and a processor configured to authenticate the UE by comparing the RES with the XRES, wherein the Registration Request message includes a Key Set Identifier (KSI) and UE Security Capabilities. 10. The AUSF node according to claim 9 further comprising: a transmitter configured to send a Success message to the UE via the SEAF if authentication is successful.

Assignees

Inventors

Classifications

  • Key distribution or pre-distribution; Key agreement · CPC title

  • Pseudo-random number generators · CPC title

  • including means for verifying the identity or authority of a user of the system {or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials} · CPC title

  • Switchboards · CPC title

  • Answer-back mechanisms or circuits · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11902776B2 cover?
Provided is an authentication device capable of generating a master key suited to a UE in a 5GS. The authentication device (10) includes a communication unit (11) configured to, in registration processing of user equipment (UE), acquire UE key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE, a selection unit (12) configured to select a pseudo rando…
Who is the assignee on this patent?
Nec Corp
What technology area does this patent fall under?
Primary CPC classification H04W12/0431. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 13 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).